Security Leader · USAF Veteran · CISSP & GCPN

I don't inherit security programs
I build them

Then I translate them for the people who pay for them.

Director of Information Security at an MDR provider running 24/7 SOC operations worldwide. Nine security domains, built from zero, with a lean team through 174% company growth. SOC 2 Type II, HIPAA, and NIST 800-171 with zero major findings.

Founder of Security Translated: the newsletter for the people who build security and the people who fund it.

Priscilla Lopez

Before you read further.

Who I am

A security leader who builds programs from zero and won't build them any way but right. Nearly two decades across the Air Force, three university classrooms, my own consultancy, and now an MDR provider. Budget conversations and bash terminals, same day.

Who I'm not

Not a vendor. Not a consultant selling you a maturity model you'll never staff. Not a GRC director who can't open a terminal, and not a pentester who can't write an executive summary. I don't do security theater, and I won't sell you shelfware.

What I bring

Nine security domains built from zero. SOC 2 Type II, HIPAA, and NIST 800-171 with zero major findings. CMMC Level 2 to 95% on first assessment. A lean team through 174% growth with minimal consultant support. Audit pass rate 82% to 100%. 96% of standing privileged access eliminated. 37 policies written, not inherited.

Why that's different

Most security leaders inherit a program and patch it. I've built from zero as the only security person in the room, with no senior to escalate to. Then I taught it for a decade, which is why I can explain it to an executive, an engineer, and an auditor in the same afternoon.


Why 'Ciber Cazadora' and why Security Translated.

It started with a Commodore 64. I didn't play games on it. I took it apart, figured out how it worked, and put it back together. That instinct never left.

Six years in the Air Force taught me to lead when the situation is unclear. A decade teaching cybersecurity at three universities taught me to make risk make sense for any audience. Running my own consultancy in Hawai'i taught me that every engagement is personal when your name is on the door.

Today I'm Director of Information Security at Lumifi Cyber, where I built the program from zero. The numbers are above; the part that matters is that none of it existed before, and it holds up under audit.

The handle "Ciber Cazadora" means cyber huntress. I don't wait for threats to find me.

Security done right gives companies permission to grow. A mature program isn't overhead, it's a competitive advantage. Built right. Passed clean. People first.

Security Translated is the other side of that. After years of turning risk into budget language, then going back to the terminal to actually fix things, I started writing it down. Most security content serves one audience. Mine serves two.

I mentor through WiCyS and (ISC)². I still play on TryHackMe, Hack The Box, and CTFs. When I'm not doing either, I'm baking or binging Netflix with the family.

0
Major findings across SOC 2 Type II, HIPAA, NIST 800-171
9
Security domains built from zero
95%
CMMC Level 2 alignment on first assessment
6 yrs
USAF, Secret clearance, zero safety or compliance failures

Security Translated.

Every issue does two jobs: a framework the people funding security will understand, and something the people building it can actually ship. No vendor pitches. No rehashed press releases.

Twelve pillars: translating cyber to the executive, GRC, GRC engineering, AI in security, DevSecOps, container and cloud-native security, penetration testing and red teaming, code review and application security, vulnerability management, security architecture and strategy, incident response and threat detection, and security operations and team building.

Free to subscribe. Read it on Substack.

Free for subscribers · Security Translated

Get the Executive Briefing Template

The one-pager I use to turn a security risk into a five-minute executive update. Threat data into budget language: no buzzwords, no slide bloat.

Subscribe free

Takes 10 seconds. No vendor pitches. Unsubscribe any time.


Publishing this since 2013.

The newsletter is the current form, not the start.


What I bring.

Not a list of technologies I've touched. These are the tools I've used to close audit findings, cut standing privileged access, and defend production.

Identity & Access Management

Entra ID SAML OIDC SCIM SSO MFA PAM RBAC JIT Provisioning Identity Lifecycle Least Privilege

Security Operations

Microsoft Sentinel Defender XDR EDR DLP Microsoft Purview KQL Incident Response Vuln Management (Tenable)

Compliance & Frameworks

SOC 2 Type II NIST 800-171 HIPAA CMMC Level 2 GDPR FERPA COPPA CIS Controls

Device & Endpoint Security

Microsoft Intune Jamf Pro Sophos Conditional Access Device Posture

Zero Trust & Network Security

Cloudflare Tailscale ZTNA Firewalls

Cloud Platforms

Microsoft Azure AWS Microsoft 365 Google Workspace

Scripting & Automation

Python Bash PowerShell CI/CD

Penetration Testing

Kali Linux Metasploit Burp Suite Nmap Nessus OWASP ZAP Wireshark
M.S. Information Security & Assurance · Western Governors University B.S. Computer & Information Technology · University of Maryland

What I've built.

Proof of work. Not slide decks.

AI Security

Agentic LLM Threat Model & Security Architecture

Threat model covering 23 attack vectors across 4 layers. Mitigations for all 10 OWASP LLM risks. MCP security layer with identity propagation, context isolation, and tiered sandboxing. Circuit breakers and scoped execution tokens for the agentic loop.

Threat Modeling OWASP LLM Top 10 MCP Agentic AI
Identity Engineering

Identity Lifecycle & Access Automation

JML automation with Python and Microsoft Graph. Okta and OIDC federation lab in Gitea. Conditional access and device posture policies in Entra ID and Intune. Automated access reviews via Graph API.

Python Microsoft Graph Okta Entra ID Intune
Compliance Automation

Continuous Compliance Pipeline

Automated evidence collection from cloud, IdP, CI/CD, and runtime, mapped directly to control frameworks. No more screenshot-driven audits.

CI/CD Cloud IdP Evidence Automation
AI Governance

NIST AI RMF & Prompt Injection Defenses

Full NIST AI RMF implementation: Govern, Map, Measure, Manage across 12 documented activities. Prompt injection defenses using canary tokens, instruction hierarchy, and dual-LLM sanitization. Human-in-the-loop guardrails with fail-closed timeouts.

NIST AI RMF Prompt Injection Guardrails HITL
Zero Trust

Tailscale ZTNA Home Network Lab

Zero trust network access using Tailscale. Identity-based access control, no VPNs, no exposed ports.

Tailscale ZTNA Network Segmentation

Where I've been.

I've been the only security person in the room. I've also been the one explaining the risk to leadership while the team builds. Selected roles below: the military years and the last decade. Earlier work was in other fields.

Download resume (PDF)

April 2024 – Present

Director of Information Security

Lumifi Cyber · Scottsdale, AZ

Built the security program from zero across nine domains: GRC, vulnerability management, IAM, endpoint security, product security, infrastructure security, third-party risk, incident response, and disaster recovery. SOC 2 Type II, HIPAA, and NIST 800-171 with zero major findings. Drove CMMC Level 2 to 95% alignment on first assessment after a mid-cycle revision, with minimal consultant support. Led a lean team through 174% company growth while developing a junior hire. Audit pass rate went from 82% to 100%. Eliminated 96% of standing privileged access. Zero data breaches in three years. Built the Trust Center answering 100+ client security questionnaires a year.

April 2023 – April 2024

Senior IT Security Engineer

Lumifi Cyber

Walked into a security program that existed on paper but barely held up under scrutiny. Rebuilt vulnerability management, risk operations, and compliance readiness into workflows that survived the first SOC 2 Type II and NIST 800-171 audits with zero major findings. Authored 37 framework-mapped policies. Embedded SAST and DAST into CI/CD and cut critical production vulnerabilities by 38%. Promoted to Director in under a year, skipping Manager.

2013 – 2023, concurrent

Adjunct Professor & Lecturer

UH Maui College · Liberty University · Excelsior College

Taught cybersecurity, digital forensics, ethical hacking, Python, and networking across three universities for ten concurrent years, alongside full-time work. Designed hands-on labs with AWS Workspaces, VMware, and SEED Labs. Earned the 2015 Instructor Excellence Award at Liberty University and led NSF grant-funded cybersecurity cohorts at the University of Hawai'i. This decade is why I explain risk differently than most leaders in this field.

2018 – 2023

Computer Systems Engineer

Hawaii Preparatory Academy

Sole IT owner for a K-12 campus of 600 students and 150 staff: infrastructure, security, endpoints, budget, vendors, compliance, and automation. Completed a school-wide LMS and SIS rollout in six months against a twelve-month industry average. Led GDPR readiness in 2018 for an international parent community. Cut malware incidents in half, raised phishing reporting 60%, and secured roughly $50K in infrastructure grant funding. Compliance across PCI, GDPR, COPPA, CIPA, and HIPAA.

2013 – 2018

Founding Owner & Lead Technologist

Lana'i Computers LLC

Founded and ran a solo IT and security consultancy for five years. Delivered seven external and web application penetration tests for healthcare, legal, and retail clients using Nessus, Kali Linux, and Burp Suite. Designed a HIPAA-compliant Windows Server and Office 365 environment for a nonprofit healthcare organization. Scoping, delivery, reporting, and running the business: all of it mine.

2000 – 2006

Staff Sergeant (E-5), Munitions Systems Specialist

U.S. Air Force, Active Duty

Six years active duty with a Secret clearance. Directed 30+ munitions operations involving missile systems valued at $100K+, with zero safety or compliance failures. Received audit commendations for documentation accuracy and operational excellence. Managed scheduling and mission readiness for a shop of 10+ personnel. Two Air Force Achievement Medals with Oak Leaf Cluster, an Outstanding Unit Award, a Humanitarian Service Medal, and a National Defense Service Medal. The accountability standard here is the one I still run security programs by.


I'd rather build with you than talk at you.

Phoenix, Arizona.

Open to: security leadership roles, advisory work, and speaking.
Building: Security Translated — newsletter, templates, and practitioner toolkits.
Not open to: unsolicited vendor pitches.