All work
Global Payments

Threat and vulnerability management for a top payment processor

Led the threat and vulnerability management program for one of the largest payment processors in the world, cutting time to remediate by 87% and time to detect by 91%.

CISO2013 to 2014
87%
Reduction in time to remediate
91%
Reduction in time to detect
PCI-DSS, SOC 2
Regulatory scope

Context

A payment processor lives inside PCI-DSS and SOC 2, with a vulnerability backlog that scales with the size of the estate. The program had the data but not the decisions.

Approach

We turned scan output into ranked, owner-assigned risk: exploitability, exposure, and business criticality rather than raw CVSS counts.

Built the team to match the work: vulnerability analysts, application security assessors, penetration testers, and data loss prevention specialists, with governance documented as policies, standards, and procedures.

Embedded security into the development lifecycle so findings stopped arriving after release.

More work

Cinch: a production collaboration platform built on evidence, not demos

Independent · 2025 to present

A multi-tenant Slack alternative in production at cinchme.app, with tenant isolation proven in the database, a browser suite run against the production image, and a release gate that refuses to promote traffic without evidence.

2,566
Unit and integration tests
92
Browser scenarios against the production image

Five certifications, first audit, zero critical findings

North Highland · 2014 to 2026

A risk and compliance program aligned to ISO 27001, HITRUST, HIPAA, GDPR, and UK Cyber Essentials that certified on the first pass and opened more than a billion dollars of revenue.

5
Standards certified on the first audit
0
Critical findings