Fractional GRC Leadership for Healthcare & Technology

Turning Security from a
Department of No into
a Revenue Enabler.

Most mid-market security teams are technically capable but organizationally overwhelmed. Audits pile up. Vendor processes create friction. New regulations land on legal’s desk with no clear owner. Enterprise deals stall while security questionnaires sit unanswered.

I come in as a fractional GRC leader — embedded enough to understand the business, experienced enough to build what is missing, and structured enough to hand it to the internal team to run.

15+
Years in enterprise cybersecurity
CISSP
HITRUST Certified Practitioner
Ex-
Deloitte, Take-Two & MultiPlan
NYC
Serving clients nationally

Senior GRC Leadership Without the Full-Time Overhead

I work with CISOs, CIOs, CTOs and General Counsel at mid-market healthcare and technology companies — especially when an audit is looming, a deal is stalling, or a new regulation just landed on legal’s desk with no clear owner.

My background spans Deloitte, Take-Two Interactive, and MultiPlan — where I built GRC programs from scratch, led HITRUST certifications, implemented vendor oversight at scale, and turned security from a bottleneck into a business enabler.

  • HIPAA
  • HITRUST
  • SOC 2 Type I & II
  • ISO 27001
  • PCI DSS
  • Vendor Risk Management
  • GRC Program Build
  • Regulatory Readiness

Ways I Work Together With You

Structured engagements for mid-market healthcare and technology companies that need senior GRC leadership — without the full-time cost.

Start Here

GRC Diagnostic

3–4 Weeks Fixed Fee

A structured gap assessment that surfaces your highest-priority risks, maps them to the regulations that matter most to your business, and produces a board-ready findings report with a prioritized roadmap.

What You Get
  • Full GRC gap assessment against your regulatory landscape
  • Prioritized risk and control roadmap
  • Board-ready findings presentation
  • Clear starting point — so nothing gets missed
Build & Sustain

Pilot Project & Advisory Retainer

2–3 Months Ongoing

Following the diagnostic, I build the GRC or vendor oversight program your organization is missing — then stay on as your fractional GRC leader to course-correct, support audits, and advise on new regulatory requirements as they emerge.

What You Get
  • GRC or TPRM program built and handed to your team
  • Ongoing audit support and regulatory guidance
  • A senior GRC presence without a full-time headcount
  • Defensible answers for your legal and compliance team

Ready to Move Security Forward?

Tell me where you are and what’s blocking you. I’ll respond within one business day.