I don't inherit security programs
I build them
Then I translate them for the people who pay for them.
Director of Information Security at an MDR provider running 24/7 SOC operations worldwide.
Nine security domains, built from zero, with a lean team through 174% company growth.
SOC 2 Type II, HIPAA, and NIST 800-171 with zero major findings.
Founder of Security Translated: the newsletter for the people who build security
and the people who fund it.
Before you read further.
Who I am
A security leader who builds programs from zero and won't build them any way but right. Nearly two decades across the Air Force, three university classrooms, my own consultancy, and now an MDR provider. Budget conversations and bash terminals, same day.
Who I'm not
Not a vendor. Not a consultant selling you a maturity model you'll never staff. Not a GRC director who can't open a terminal, and not a pentester who can't write an executive summary. I don't do security theater, and I won't sell you shelfware.
What I bring
Nine security domains built from zero. SOC 2 Type II, HIPAA, and NIST 800-171 with zero major findings. CMMC Level 2 to 95% on first assessment. A lean team through 174% growth with minimal consultant support. Audit pass rate 82% to 100%. 96% of standing privileged access eliminated. 37 policies written, not inherited.
Why that's different
Most security leaders inherit a program and patch it. I've built from zero as the only security person in the room, with no senior to escalate to. Then I taught it for a decade, which is why I can explain it to an executive, an engineer, and an auditor in the same afternoon.
Why 'Ciber Cazadora' and why Security Translated.
It started with a Commodore 64. I didn't play games on it. I took it apart, figured out how it worked, and put it back together. That instinct never left.
Six years in the Air Force taught me to lead when the situation is unclear. A decade teaching cybersecurity at three universities taught me to make risk make sense for any audience. Running my own consultancy in Hawai'i taught me that every engagement is personal when your name is on the door.
Today I'm Director of Information Security at Lumifi Cyber, where I built the program from zero. The numbers are above; the part that matters is that none of it existed before, and it holds up under audit.
The handle "Ciber Cazadora" means cyber huntress. I don't wait for threats to find me.
Security done right gives companies permission to grow. A mature program isn't overhead, it's a competitive advantage. Built right. Passed clean. People first.
Security Translated is the other side of that. After years of turning risk into budget language, then going back to the terminal to actually fix things, I started writing it down. Most security content serves one audience. Mine serves two.
I mentor through WiCyS and (ISC)². I still play on TryHackMe, Hack The Box, and CTFs. When I'm not doing either, I'm baking or binging Netflix with the family.
Security Translated.
Every issue does two jobs: a framework the people funding security will understand, and something the people building it can actually ship. No vendor pitches. No rehashed press releases.
Twelve pillars: translating cyber to the executive, GRC, GRC engineering, AI in security, DevSecOps, container and cloud-native security, penetration testing and red teaming, code review and application security, vulnerability management, security architecture and strategy, incident response and threat detection, and security operations and team building.
Free to subscribe. Read it on Substack.
Free for subscribers · Security Translated
Get the Executive Briefing Template
The one-pager I use to turn a security risk into a five-minute executive update. Threat data into budget language: no buzzwords, no slide bloat.
Subscribe freeTakes 10 seconds. No vendor pitches. Unsubscribe any time.
Publishing this since 2013.
The newsletter is the current form, not the start.
A Day in the Life: Cybersecurity
CyberJitsu. What the work actually looks like, minus the keynote gloss.
WatchMSP / Customer Security Summit
Compliance panel in 2024. CMMC compliance talk in 2025. Two years running.
Enterprise Cyber Resilience Strategy
Presented to a peer cohort of security leaders, (ISC)² Cyber Leadership Program.
Creating an Effective Incident Response Plan
The plan people actually run, not the one that sits in a binder.
Watch 2013 · PublishedSteganography: The Art of Hidden Data in Plain Sight
Feature article, eForensics Magazine.
eForensics Magazine 2013 · Published12 Open-Source Linux Forensic Tools
Feature article, eForensics Magazine.
eForensics MagazineWhat I bring.
Not a list of technologies I've touched. These are the tools I've used to close audit findings, cut standing privileged access, and defend production.
Identity & Access Management
Security Operations
Compliance & Frameworks
Device & Endpoint Security
Zero Trust & Network Security
Cloud Platforms
Scripting & Automation
Penetration Testing
What I've built.
Proof of work. Not slide decks.
Agentic LLM Threat Model & Security Architecture
Threat model covering 23 attack vectors across 4 layers. Mitigations for all 10 OWASP LLM risks. MCP security layer with identity propagation, context isolation, and tiered sandboxing. Circuit breakers and scoped execution tokens for the agentic loop.
Identity Lifecycle & Access Automation
JML automation with Python and Microsoft Graph. Okta and OIDC federation lab in Gitea. Conditional access and device posture policies in Entra ID and Intune. Automated access reviews via Graph API.
Continuous Compliance Pipeline
Automated evidence collection from cloud, IdP, CI/CD, and runtime, mapped directly to control frameworks. No more screenshot-driven audits.
NIST AI RMF & Prompt Injection Defenses
Full NIST AI RMF implementation: Govern, Map, Measure, Manage across 12 documented activities. Prompt injection defenses using canary tokens, instruction hierarchy, and dual-LLM sanitization. Human-in-the-loop guardrails with fail-closed timeouts.
Tailscale ZTNA Home Network Lab
Zero trust network access using Tailscale. Identity-based access control, no VPNs, no exposed ports.
Where I've been.
I've been the only security person in the room. I've also been the one explaining the risk to leadership while the team builds. Selected roles below: the military years and the last decade. Earlier work was in other fields.
Director of Information Security
Built the security program from zero across nine domains: GRC, vulnerability management, IAM, endpoint security, product security, infrastructure security, third-party risk, incident response, and disaster recovery. SOC 2 Type II, HIPAA, and NIST 800-171 with zero major findings. Drove CMMC Level 2 to 95% alignment on first assessment after a mid-cycle revision, with minimal consultant support. Led a lean team through 174% company growth while developing a junior hire. Audit pass rate went from 82% to 100%. Eliminated 96% of standing privileged access. Zero data breaches in three years. Built the Trust Center answering 100+ client security questionnaires a year.
Senior IT Security Engineer
Walked into a security program that existed on paper but barely held up under scrutiny. Rebuilt vulnerability management, risk operations, and compliance readiness into workflows that survived the first SOC 2 Type II and NIST 800-171 audits with zero major findings. Authored 37 framework-mapped policies. Embedded SAST and DAST into CI/CD and cut critical production vulnerabilities by 38%. Promoted to Director in under a year, skipping Manager.
Adjunct Professor & Lecturer
Taught cybersecurity, digital forensics, ethical hacking, Python, and networking across three universities for ten concurrent years, alongside full-time work. Designed hands-on labs with AWS Workspaces, VMware, and SEED Labs. Earned the 2015 Instructor Excellence Award at Liberty University and led NSF grant-funded cybersecurity cohorts at the University of Hawai'i. This decade is why I explain risk differently than most leaders in this field.
Computer Systems Engineer
Sole IT owner for a K-12 campus of 600 students and 150 staff: infrastructure, security, endpoints, budget, vendors, compliance, and automation. Completed a school-wide LMS and SIS rollout in six months against a twelve-month industry average. Led GDPR readiness in 2018 for an international parent community. Cut malware incidents in half, raised phishing reporting 60%, and secured roughly $50K in infrastructure grant funding. Compliance across PCI, GDPR, COPPA, CIPA, and HIPAA.
Founding Owner & Lead Technologist
Founded and ran a solo IT and security consultancy for five years. Delivered seven external and web application penetration tests for healthcare, legal, and retail clients using Nessus, Kali Linux, and Burp Suite. Designed a HIPAA-compliant Windows Server and Office 365 environment for a nonprofit healthcare organization. Scoping, delivery, reporting, and running the business: all of it mine.
Staff Sergeant (E-5), Munitions Systems Specialist
Six years active duty with a Secret clearance. Directed 30+ munitions operations involving missile systems valued at $100K+, with zero safety or compliance failures. Received audit commendations for documentation accuracy and operational excellence. Managed scheduling and mission readiness for a shop of 10+ personnel. Two Air Force Achievement Medals with Oak Leaf Cluster, an Outstanding Unit Award, a Humanitarian Service Medal, and a National Defense Service Medal. The accountability standard here is the one I still run security programs by.
I'd rather build with you than talk at you.
Phoenix, Arizona.
Open to: security leadership roles, advisory work, and speaking.
Building: Security Translated — newsletter, templates, and
practitioner toolkits.
Not open to: unsolicited vendor pitches.