Security architect and GRC leader with 15 years of experience in industries where failure has real consequences: medical devices, law enforcement, aviation, banking, insurance, telecom, and manufacturing. My current focus is AI security, data security and privacy, and GRC. I assess enterprise AI systems for data governance, data security, model risk, and LLM supply chain exposure, and I build the security strategy and roadmap that lets an organization adopt AI without betting the company on it.