Long-term · Living Journal

The Journey

A living journal of continuous growth toward executive security leadership. Not a résumé. Not a highlight reel. The actual work, documented as it happens.

Current Focus

Working in a senior security operations leadership role at a healthcare organization. Building toward broader security leadership responsibility and executive security leadership.

Current operational priorities: Zero Trust architecture rollout, healthcare threat intelligence program, GenAI risk governance, and executive-level security reporting.

Immediate

CISM exam preparation · Board reporting framework · Security architecture documentation · GenAI policy development

This Quarter

First conference CFP submission · HCISPP certification planning · Security leadership development · Publication growth

Certifications

CISSP

Active

Certified Information Systems Security Professional. Maintained with active CPE currency through publishing, research, and operational work.

OSCP

Active

Offensive Security Certified Professional. Forms the foundation of offensive methodology applied across red team work and detection strategy.

CEH

Active

Certified Ethical Hacker. Maintained with CEU credits through operational work, published research, and security community contributions.

CISM

In progress

Certified Information Security Manager. Next priority — bridges the gap between technical security operations and security governance.

HCISPP

Planned

Healthcare Information Security and Privacy Practitioner. Deepens healthcare-specific security and regulatory expertise for CISO-track positioning.

CRISC

Planned

Certified in Risk and Information Systems Control. Rounds out the governance and risk quantification skills needed for the CISO seat.

Books

Reading across three tracks simultaneously: technical depth, business strategy, and leadership development. Full reviews added as each is completed.

Currently reading

The CISO Evolution · Turn the Ship Around! · Extreme Ownership

Technical

The Hacker Playbook 3 · Red Team Development and Operations · The Practice of Network Security Monitoring

Leadership

CISO Desk Reference Guide · The Five Dysfunctions of a Team · Leaders Eat Last

Strategy

Good Strategy / Bad Strategy · Thinking in Systems · The Art of War (applied to security strategy)

Conferences

Targeting RSA Conference (CISO Executive Security Action Forum), HIMSS, Health-ISAC Annual Summit, and regional CISO roundtables for 2026–2027. First CFP submissions planned for HIMSS Healthcare Security Forum and RSA CISO track.

Leadership Lessons

The hardest part of moving from practitioner to director wasn't technical — it was identity. You stop being the person who finds the vulnerability and become the person responsible for the program that doesn't have them.

The lesson I keep returning to: a security leader's job is to make the organization's risk tolerance visible and defensible — not to eliminate all risk. That difference sounds semantic. In practice, it changes every decision.

Building trust with non-technical executives requires translating technical problems into business language before they're asked. The question isn't "what's the CVSS score" — it's "what's the impact if this goes wrong and how long do we have to fix it."

Technical Experiments

TAP Verification System

Built a production-ready Temporary Access Pass verification system on Entra ID with risk-based routing, Teams escalation, and full RBAC admin panel.

CVE Validation Tooling

Safe, non-exploitative detection scripts for CVE-2024-21762 and CVE-2025-47981. Published with methodology for safe internal use.

DLP Architecture

Designed and implemented enterprise DLP policies for PHI protection at clinical scale, including sanctioned app controls and GenAI inline inspection.

This Publication

SecretSquirrel.cloud is itself a technical experiment — a static publication platform built on Cloudflare Pages with a custom design system.

AI Exploration

Actively exploring AI adoption in security operations: using LLMs for threat intelligence summarization, detection rule generation, and security policy drafting. Also researching the threat side — prompt injection, data exfiltration through LLM context, and the PHI risk of unsanctioned AI tool use in healthcare environments.

Building a risk-based GenAI enablement framework for healthcare that balances productivity with HIPAA compliance.

Career Reflections

The path from federal security work (NIST 800-53, government ATO processes) → health system threat and vulnerability operations → red team leadership at a security vendor → senior security leadership in healthcare has been faster than expected and harder than anticipated.

Each move was motivated by one question: does this role make me a better security leader? The answer was always about scope — more responsibility, harder problems, bigger programs.

Future Goals

2027

Security leadership development milestone · CISM certification · First conference talk · Board-level security communication framework published

2028–2029

Broader executive security leadership · CRISC certification · Advisory board seat · Continue building this publication

Long-term

World-class security program · Mentoring practitioner-leaders · Private pilot license and experimental aircraft build (CH-750 SD)

This publication

100+ articles · 20+ series · Named authorship when timing is right · A reference for practitioners navigating the same path