Security & Compliance Executive · Fractional CISO · Infrastructure Architect
Three decades building and securing production systems — a senior Linux and Windows administrator currently leading Information Security & Compliance at an enterprise AI company. I design compliance programs (SOC 2 Type II, HIPAA, GDPR) and personally deliver the infrastructure and automation that satisfy them: replaced commercial tooling quoted at up to $152K/yr with a platform built in-house under my direction, ran individual production VMs past 1,450 days of continuous uptime, took security programs from placeholder policies to full certification — and took Trustivum (trustivum.com), a multi-tenant SOC 2/HIPAA compliance SaaS, from PRD to production as its own product. Own a private-suite AI co-location buildout (~$5M of GPU/CPU compute — ~2,900 CPU cores, ~34 TB RAM, A100/B300-class GPUs, 48 VMs across 35 hosts; six racks growing toward eleven), Zero Trust architecture, and incident response; co-architecting a second hot-hot facility connected over dark fiber. Career spans nearly three decades co-founding and running Indigo Productions, a five-person IT consultancy ($70M+ in managed IT budgets; started at the physical layer, personally installing and pulling CAT-6 and fiber for client offices and data-center suites; delivered early software including InfoExchange, a CAD-file exchange CRM for construction firms), co-founding a seven-brand creative-tech LLC as CEO/CTO/CISO, and cybersecurity mentorship. Known for combining board-level strategy with the ability to ship the systems that implement the controls.
Compliance SaaS taken from PRD to production — sole architect and product owner, directing an AI-accelerated build end-to-end. Compliance-mapping engine spanning SOC 2 and HIPAA, weekly compliance calendar with answers stored as audit evidence, AI compliance assistant, and multi-tenant isolation with SSO and RBAC. Go · GraphQL · PostgreSQL · React · Relay · TypeScript · Docker.
Multi-tenant penetration-testing platform taken from concept to production — product owner and architect directing an AI-accelerated build. Runs audit-credible external pentests (automated scanning + manual analyst verification) and generates branded PDF reports with SOC 2 and HIPAA control mapping on every finding, plus a free 30-day retest. Its Sentry tier extends the same platform to continuous coverage: drop-in appliances that join a private mesh and run scheduled internal-network scans, streaming findings to a customer portal. Three tiers (External · Sentry Standard · Sentry Pro); OpenVAS/Greenbone · ZAP · Docker · private-mesh appliances.
Multi-year data-center buildout (half a rack → six racks; ~2,900 cores, ~34 TB RAM, 48 VMs / 35 hosts) plus a suite of internal software built from scratch: a federated CMDB, live inventory and network dashboards with daily auto-generated reports, rack-PDU power monitoring (pysnmp/InfluxDB/FastAPI/React), an AI infrastructure assistant, and a self-healing event-log pipeline. Mostly open-source/custom-coded.
Self-hosted ITSM replacing commercial tools quoted at up to $152K/year. 10-container Docker stack, 41 ticket types, autonomous self-healing AI remediation agent (Claude API), Active Directory sync, Slack interactive approvals. Python/FastAPI · React/TypeScript · PostgreSQL · Redis · Celery.
Complete data center fabric design for AI company GPU fleet. Dell S5232F-ON / OS10, eBGP underlay, VLT pairs, ECMP across 3 spines, Anycast Gateway, all-100G links, Fortinet NGFW. Replaces flat Layer 2 network; implementation in progress.
Full-stack SaaS product — sole architect and product owner, PRD to production. Backward-planning scheduler with appliance lanes, human bandwidth constraints, allergen safety, PWA push notifications, and pluggable AI assistance. Next.js 14 · Fastify/TypeScript · PostgreSQL · Redis · BullMQ · Drizzle · Lucia Auth.
Self-healing applications built with scripting and AI — autonomous remediation, container auto-healing, and a log-analysis pipeline that opens its own tickets. Plus a multi-agent orchestration layer coordinating specialized agents across my own applications and brands: durable session memory, vault-based handoff, cross-host execution, scheduled routines, browser automation, and a custom skill library. Claude Agent SDK foundation with custom orchestration on top.
Owned the multi-year infrastructure scale-up for an AI technology company: half a rack → six full colocation racks → migration into a private suite (built for up to eleven racks) housing ~$5M of AI infrastructure. Co-architecting a second, geographically separate facility connected to the primary suite over dark fiber for active-active hot-hot workload distribution, failover, and DR at AI-compute scale.