Security Leader · USAF Veteran · CISSP & GCPN


I build security programs

from scratch with lean teams, pass audits quickly, and personally defend the work to clients.

Then I translate them for the people who pay for them.

Director of Information Security at an MDR provider running 24/7 SOC operations worldwide. Nine security domains, built from zero, with a lean team through 174% company growth. SOC 2 Type II, HIPAA, and NIST 800-171 with zero major findings.

Founder of Security Translated: the newsletter for the people who build security and the people who fund it.

Priscilla Lopez

Before you read further.

Who I am

A security leader who builds programs from zero and won't build them any way but right. Nearly two decades across the Air Force, system administration, IT, three university classrooms, my own consultancy, and now an MDR provider. Budget conversations and bash terminals, same day.

Who I'm not

Not a vendor. Not a consultant selling you a maturity model you'll never staff. Not a GRC director who can't open a terminal, and not a pentester who can't write an executive summary. I don't do security theater, and I won't sell you shelfware.

What I bring

Nine security domains built from zero. SOC 2 Type II, HIPAA, and NIST 800-171 with zero major findings. CMMC Level 2 to 95% on first assessment. A lean team through 174% growth with zero consultant support. Audit passes on first try. 96% of standing privileged access eliminated. 37 policies written and used, not inherited.

Why that's different

Most security leaders inherit a program and patch it. I've built from zero as the main security person in the room. Also taught it for a decade, which is why I can explain it to an executive, an engineer, and an auditor in the same afternoon.


Why 'Ciber Cazadora' and why Security Translated.

It started with a Commodore 64. I didn't play games on it. I took it apart, figured out how it worked, and put it back together. That instinct never left.

Six years in the Air Force taught me to lead when the situation is unclear. A decade teaching cybersecurity at three universities taught me to make risk make sense for any audience. Running my own consultancy and break/fix company in Hawai'i taught me that every engagement is personal when your name is on the door.

Today I'm Director of Information Security at Lumifi Cyber, where I built the program from bare bones. The numbers are above; the part that matters is that none of it existed before, and it held up under audit.

The handle "Ciber Cazadora" means cyber huntress. I proactively look for security gaps caused by people, in poor processes, and found in technology.

Security done right gives companies permission to grow. A mature program isn't overhead, it's a competitive advantage.

Security Translated is the other side of that. After years of turning risk into budget language, then going back to the terminal to actually fix things, I started writing it down. Most security content serves one audience. Mine serves two.

I mentor through WiCyS. I work on projects in my home lab, help my husband with his business, participate in CTFs, or sharpen my skills in HTB or THM. When I need a break from technology, I'm baking, painting, drawing, maintaining my health, or binging Netflix with the family.

0
Major findings across SOC 2 Type II, HIPAA, NIST 800-171
9
Security domains built from zero
95%
CMMC Level 2 alignment on first assessment
6 yrs
USAF, Secret clearance, zero safety or compliance failures

Security Translated.

Every issue does two jobs: a framework the people funding security will understand, and something the people building it can actually ship. No vendor pitches. No rehashed press releases.

Twelve pillars: translating cyber to the executive, GRC, GRC engineering, AI in security, DevSecOps, container and cloud-native security, penetration testing and red teaming, code review and application security, vulnerability management, security architecture and strategy, incident response and threat detection, and security operations and team building.

Free to subscribe. Read it on Substack.

Free for subscribers · Security Translated

Get the Executive Briefing Template

The one-pager I use to turn a security risk into a five-minute executive update. Threat data into budget language: no buzzwords, no slide bloat.

Subscribe free

Takes 10 seconds. No vendor pitches. Unsubscribe any time.


Publishing this since 2013.

The newsletter is the current form, not the start.


What I bring.

Not a list of technologies I've touched. These are the tools I've used to close audit findings, cut standing privileged access, and defend production.

Identity & Access Management

Entra ID SAML OIDC SCIM SSO MFA PAM RBAC JIT Provisioning Identity Lifecycle Least Privilege

Security Operations

Microsoft Sentinel Defender XDR EDR DLP Microsoft Purview KQL Incident Response Vuln Management (Tenable)

Compliance & Frameworks

SOC 2 Type II NIST 800-171 HIPAA CMMC Level 2 GDPR FERPA COPPA CIS Controls

Device & Endpoint Security

Microsoft Intune Jamf Pro Sophos Conditional Access Device Posture

Zero Trust & Network Security

Cloudflare Tailscale ZTNA Firewalls

Cloud Platforms

Microsoft Azure AWS Microsoft 365 Google Workspace

Scripting & Automation

Python Bash PowerShell CI/CD

Penetration Testing

Kali Linux Metasploit Burp Suite Nmap Nessus OWASP ZAP Wireshark
M.S. Information Security & Assurance · Western Governors University B.S. Computer & Information Technology · University of Maryland

What I've built.

Proof of work. Not slide decks.

AI Security

Agentic LLM Threat Model & Security Architecture

Threat model covering 23 attack vectors across 4 layers. Mitigations for all 10 OWASP LLM risks. MCP security layer with identity propagation, context isolation, and tiered sandboxing. Circuit breakers and scoped execution tokens for the agentic loop.

Threat Modeling OWASP LLM Top 10 MCP Agentic AI
Identity Engineering

Identity Lifecycle & Access Automation

JML automation with Python and Microsoft Graph. Okta and OIDC federation lab in Gitea. Conditional access and device posture policies in Entra ID and Intune. Automated access reviews via Graph API.

Python Microsoft Graph Okta Entra ID Intune
Compliance Automation

Continuous Compliance Pipeline

Automated evidence collection from cloud, IdP, CI/CD, and runtime, mapped directly to control frameworks. No more screenshot-driven audits.

CI/CD Cloud IdP Evidence Automation
AI Governance

NIST AI RMF & Prompt Injection Defenses

Full NIST AI RMF implementation: Govern, Map, Measure, Manage across 12 documented activities. Prompt injection defenses using canary tokens, instruction hierarchy, and dual-LLM sanitization. Human-in-the-loop guardrails with fail-closed timeouts.

NIST AI RMF Prompt Injection Guardrails HITL
Zero Trust

Tailscale ZTNA Home Network Lab

Zero trust network access using Tailscale. Identity-based access control, no VPNs, no exposed ports.

Tailscale ZTNA Network Segmentation

Where I've been.

I've been the only security person in the room. I've also been the one explaining the risk to leadership while the team builds. Selected roles below: the military years and the last decade. Earlier work was in other fields.

Download resume (PDF)

April 2024 – Present

Director of Information Security

Lumifi Cyber · Scottsdale, AZ

Built the security program from zero across nine domains: GRC, vulnerability management, IAM, endpoint security, product security, infrastructure security, third-party risk, incident response, and disaster recovery. SOC 2 Type II, HIPAA, and NIST 800-171 with zero major findings. Drove CMMC Level 2 to 95% alignment on first assessment after a mid-cycle revision, with minimal consultant support. Led a lean team through 174% company growth while developing a junior hire. Audit pass rate went from 82% to 100%. Eliminated 96% of standing privileged access. Zero data breaches in three years. Built the Trust Center answering 100+ client security questionnaires a year.

April 2023 – April 2024

Senior IT Security Engineer

Lumifi Cyber

Walked into a security program that existed on paper but barely held up under scrutiny. Rebuilt vulnerability management, risk operations, and compliance readiness into workflows that survived the first SOC 2 Type II and NIST 800-171 audits with zero major findings. Authored 37 framework-mapped policies. Catalyzed SAST and DAST into CI/CD. Promoted to Director in under a year, skipping Manager.

2013 – 2023, concurrent

Adjunct Professor & Lecturer

UH Maui College · Liberty University · Excelsior College

Taught cybersecurity, digital forensics, ethical hacking, Python, e-commerce, and networking across three universities for ten concurrent years, alongside full-time work. Designed hands-on labs with AWS Workspaces, VMware, and SEED Labs. Earned the 2015 Instructor Excellence Award at Liberty University and led NSF grant-funded cybersecurity cohorts at the University of Hawai'i. This decade is why I explain risk differently than most leaders in this field.

2018 – 2023

Computer Systems Engineer

Hawaii Preparatory Academy

Main IT modernization driver for a K-12 campus of 600 students and 150 staff: infrastructure, security, endpoints, budget, vendors, compliance, and automation. Completed a school-wide LMS and SIS rollout in six months against a twelve-month industry average. Led GDPR readiness in 2018 for an international parent community. Cut malware incidents in half, raised phishing reporting and awareness. Compliance across PCI SAQ, GDPR, COPPA, CIPA, and HIPAA.

2013 – 2018

Founding Owner & Lead Technologist

Lana'i Computers LLC

Founded and ran a solo IT and security consultancy for five years. Delivered seven external and web application penetration tests for healthcare, legal, and retail clients using Nessus, Kali Linux, and Burp Suite. Designed a HIPAA-compliant Windows Server and Office 365 environment for nonprofit healthcare organization and stood up networking for local bank. Scoping, delivery, reporting, and running the business: all of it me.

2000 – 2006

Staff Sergeant (E-5), Munitions Systems Specialist

U.S. Air Force, Active Duty

Six years active duty with a Secret clearance. Directed 30+ munitions operations involving missile systems valued at $100K+, with zero safety or compliance failures. Received audit commendations for documentation accuracy and operational excellence. Managed scheduling and mission readiness for a shop of 10+ personnel. Two Air Force Achievement Medals with Oak Leaf Cluster, an Outstanding Unit Award, a Humanitarian Service Medal, and a National Defense Service Medal. The accountability and integrity standard here is the one I still run security programs by.

Prior Work to make ends meet

Served in healthcare, utilities, and part-time primary school teaching

Lāna'i Community Hospital, Pacificorp, Waikoloa School

Prior to building my career I had make ends meet for my family. I've worked as a Ward Clerk wearing multiple hats, administrative work for large utilities contract department, and Waikoloa School helping teachers with their young students. Each role contributed to the specialized and unique skillset I bring.


I'd rather build with you than talk at you.

Phoenix, Arizona.

Open to: security leadership roles, advisory work, and speaking.
Building: Security Translated — newsletter, templates, and practitioner toolkits.
Not open to: unsolicited vendor pitches.