Long-term · Living Journal
The Journey
A living journal of continuous growth toward executive security leadership. Not a résumé. Not a highlight reel. The actual work, documented as it happens.
Current Focus
Working in a senior security operations leadership role at a healthcare organization. Building toward broader security leadership responsibility and executive security leadership.
Current operational priorities: Zero Trust architecture rollout, healthcare threat intelligence program, GenAI risk governance, and executive-level security reporting.
Immediate
CISM exam preparation · Board reporting framework · Security architecture documentation · GenAI policy development
This Quarter
First conference CFP submission · HCISPP certification planning · Security leadership development · Publication growth
Certifications
CISSP
ActiveCertified Information Systems Security Professional. Maintained with active CPE currency through publishing, research, and operational work.
OSCP
ActiveOffensive Security Certified Professional. Forms the foundation of offensive methodology applied across red team work and detection strategy.
CEH
ActiveCertified Ethical Hacker. Maintained with CEU credits through operational work, published research, and security community contributions.
CISM
In progressCertified Information Security Manager. Next priority — bridges the gap between technical security operations and security governance.
HCISPP
PlannedHealthcare Information Security and Privacy Practitioner. Deepens healthcare-specific security and regulatory expertise for CISO-track positioning.
CRISC
PlannedCertified in Risk and Information Systems Control. Rounds out the governance and risk quantification skills needed for the CISO seat.
Books
Reading across three tracks simultaneously: technical depth, business strategy, and leadership development. Full reviews added as each is completed.
Currently reading
The CISO Evolution · Turn the Ship Around! · Extreme Ownership
Technical
The Hacker Playbook 3 · Red Team Development and Operations · The Practice of Network Security Monitoring
Leadership
CISO Desk Reference Guide · The Five Dysfunctions of a Team · Leaders Eat Last
Strategy
Good Strategy / Bad Strategy · Thinking in Systems · The Art of War (applied to security strategy)
Conferences
Targeting RSA Conference (CISO Executive Security Action Forum), HIMSS, Health-ISAC Annual Summit, and regional CISO roundtables for 2026–2027. First CFP submissions planned for HIMSS Healthcare Security Forum and RSA CISO track.
Leadership Lessons
The hardest part of moving from practitioner to director wasn't technical — it was identity. You stop being the person who finds the vulnerability and become the person responsible for the program that doesn't have them.
The lesson I keep returning to: a security leader's job is to make the organization's risk tolerance visible and defensible — not to eliminate all risk. That difference sounds semantic. In practice, it changes every decision.
Building trust with non-technical executives requires translating technical problems into business language before they're asked. The question isn't "what's the CVSS score" — it's "what's the impact if this goes wrong and how long do we have to fix it."
Technical Experiments
TAP Verification System
Built a production-ready Temporary Access Pass verification system on Entra ID with risk-based routing, Teams escalation, and full RBAC admin panel.
CVE Validation Tooling
Safe, non-exploitative detection scripts for CVE-2024-21762 and CVE-2025-47981. Published with methodology for safe internal use.
DLP Architecture
Designed and implemented enterprise DLP policies for PHI protection at clinical scale, including sanctioned app controls and GenAI inline inspection.
This Publication
SecretSquirrel.cloud is itself a technical experiment — a static publication platform built on Cloudflare Pages with a custom design system.
AI Exploration
Actively exploring AI adoption in security operations: using LLMs for threat intelligence summarization, detection rule generation, and security policy drafting. Also researching the threat side — prompt injection, data exfiltration through LLM context, and the PHI risk of unsanctioned AI tool use in healthcare environments.
Building a risk-based GenAI enablement framework for healthcare that balances productivity with HIPAA compliance.
Career Reflections
The path from federal security work (NIST 800-53, government ATO processes) → health system threat and vulnerability operations → red team leadership at a security vendor → senior security leadership in healthcare has been faster than expected and harder than anticipated.
Each move was motivated by one question: does this role make me a better security leader? The answer was always about scope — more responsibility, harder problems, bigger programs.
Future Goals
2027
Security leadership development milestone · CISM certification · First conference talk · Board-level security communication framework published
2028–2029
Broader executive security leadership · CRISC certification · Advisory board seat · Continue building this publication
Long-term
World-class security program · Mentoring practitioner-leaders · Private pilot license and experimental aircraft build (CH-750 SD)
This publication
100+ articles · 20+ series · Named authorship when timing is right · A reference for practitioners navigating the same path