About
I translate for a living.
Most security failures I've seen weren't sophisticated. They were ordinary: a process nobody
owned, an exception nobody revisited, a warning nobody understood well enough to act on.
Technology rarely fails alone; it fails alongside a sentence somebody didn't say out loud.
So that's the work. I take the thing the engineers are worried about and tell it as a story
the finance team, the board, and the person in the warehouse can all follow. Then I make
sure the story ends with a decision instead of a slide.
In practice that means putting the risk and the tradeoffs on the table together. Executives
are not asking me to make the call for them. They are asking me to make the call makeable,
which means naming what we accept if we do nothing and what each option actually costs us.
I came to security sideways: programmer, architect, web development manager, then senior
manager over network, cloud, and web operations. I earned the CISSP on my own initiative and
used it to start a conversation that eventually became a formal enterprise security program.
Before all of that, I was a Military Police Sergeant and a communications specialist in the
U.S. Army, which is where I learned that a plan nobody has rehearsed isn't a plan.
The programs I'm proud of are the ones still standing after I leave. People follow them
without being chased, because they understand them. They report bad news early, because the
program earned it. And none of it falls over when priorities shift and the org chart gets
redrawn.
“If I can't explain the risk in one breath, I don't understand it yet.”