All work
TRX

Standing up a first security program for a global SaaS provider

Established the first information security program at a SaaS travel-technology company, including PCI-DSS and NIST SP 800-53 compliance and an enterprise threat and vulnerability management program.

CISO2008 to 2012
From zero
Security program established
PCI-DSS, NIST 800-53
Compliance maintained

Context

A hosting and SaaS provider handling travel and payment data for large customers had grown faster than its security function. Customers were starting to ask questions the company could not answer.

Approach

Built the program from policy up: governance, PCI-DSS and NIST 800-53 compliance, and a threat and vulnerability management practice, then hired the team to run it.

Served as the security face to customers, answering assessments and running vendor security reviews so security became a sales asset rather than a blocker.

More work

Cinch: a production collaboration platform built on evidence, not demos

Independent · 2025 to present

A multi-tenant Slack alternative in production at cinchme.app, with tenant isolation proven in the database, a browser suite run against the production image, and a release gate that refuses to promote traffic without evidence.

2,566
Unit and integration tests
92
Browser scenarios against the production image

Five certifications, first audit, zero critical findings

North Highland · 2014 to 2026

A risk and compliance program aligned to ISO 27001, HITRUST, HIPAA, GDPR, and UK Cyber Essentials that certified on the first pass and opened more than a billion dollars of revenue.

5
Standards certified on the first audit
0
Critical findings