Principal Role

Principal Architect &
AI Platform Builder

End-to-end platform architecture across distributed systems, data, security, and AI layers. I shape the vision, define the architecture, and when the engagement calls for it, I build it. Multi-cloud, regulated environments, agentic systems - simultaneously.

Security

Virtual CISO

CISO-level governance without the full-time hire. Security architecture, compliance frameworks (HIPAA, PCI, SOC 2, ISO 27001/42001), threat modeling, and board-level risk reporting.

30+
years in the trenches
IBM · PwC · Fortune 500
3 companies founded
Leadership

Fractional CTO · CIO

Engineering strategy, roadmap, team design, and the architecture decisions that compound over years - without the full-time cost. For startups scaling past founder architecture and mid-market companies modernizing.

AI Strategy

AI Strategy, Mentorship & Blueprint Execution

From "we need an AI strategy" to a governed, production-grade AI platform - with a published methodology, not improvisation. Agent orchestration, compliance-native design, AI readiness assessment, and hands-on execution when the blueprint needs to be built. The 80/20 methodology: 80% architectural specification, 20% delegated execution.

Mentorship

Executive Mentorship

For CTOs, VPs, and senior architects navigating the transition to executive leadership. I've been in the room. I can prepare you for it.

Diligence

Technical Due Diligence

For investors and acquirers: architecture, compliance posture, and execution risk. Honest and detailed - not the report you want, the one you need.

DevOps

Managed DevOps & Cloud Ops

Architecture, deployment, and ongoing operation - AWS, Azure, GCP. A lean, vetted bench runs 24/7 coverage under my direct architectural oversight, built for one goal: boring. Nothing paging anyone because nothing broke. Onboarded through grant-access: MFA-enforced, zero standing access, full audit trail.

Audit & Certification

Audit, Certification & Pentest

vCISO-led delivery, not just advice: SOC 2, HIPAA, PCI, ISO 27001/42001 readiness, internal audits, and coordinated third-party penetration testing - through to certification, not just a findings report. Tracked in Attestia, our documentation and risk planning system.

Not a fit - and I'll tell you directly

Generic software development with no architectural complexity.

Frontend or UI/UX design work.

"We need an AI strategy" with no actual engineering problem underneath it.

Headcount handed off to run unsupervised, with no architectural authority attached. DevOps and audit delivery here always run under my direct oversight - that's the difference from staff aug.

How we work together

Available now

I'm actively taking on contract and part-time work. Below are the engagement models that work best.

Engagements are scoped around outcomes, not hours. Every conversation starts with the same question: what does the organization actually need?

All engagements begin with a conversation. No pitch deck required. If there's a fit, you'll know by the end of it.

Explore a fit.
No pitch required.

Send a message