Biography

A journey from technology to military service to law enforcement to security incident command and program leadership

I started in IT. Through school and after it I managed the networks and servers for the Rutherford school district, six buildings, and ran the upgrades across them. That is where I learned how systems are actually put together, and how they break.

Then I joined the Marine Corps, and the job stopped being about machines. Three tours in Iraq, leading teams that grew from a squad to a full platoon, with a promotion each deployment cycle. I made Staff Sergeant. Somewhere in there I developed more than fifty junior Marines and Naval officers, and ten of them were promoted under me. That is still the part I am proudest of.

Law enforcement came next. I came in through corrections and patrol, but the cases that pulled me in were the digital ones: fraud, identity theft, cybercrime, people being stalked and harassed online. I made detective, and then I spent ten years there. The department had no digital forensics capability and no budget for one, so I built it: the procedures, the tooling, the training, so other detectives could work digital evidence themselves instead of shipping it out and waiting. I went and secured grant access to cryptocurrency-tracing tools and taught the team to use them.

Every one of those cases could end with me on a witness stand, being questioned by someone paid to take my work apart. You learn to handle evidence so it survives that, and to never claim more than you can actually prove.

In 2025 I moved to Thrive as their Security Incident Commander. Same instinct, different clock. I built the incident command function from nothing, the methodology, the playbooks, the escalation model, and then ran the critical incidents through it, from routine outages through full-scale ransomware, for clients from the West Coast to Hong Kong, some of them with a team of up to twenty working it. On a bad day that meant holding a room together while breach counsel, an outside forensics firm, an insurance carrier, and sometimes the FBI or the UK's NCSC all needed something different out of the same event, and the client needed someone to tell them the truth about what was happening.

Alongside that I run ADS Risk Solutions, an independent risk assessment practice, and I write three newsletters about what I keep seeing.

The thread through all of it is pretty simple. Figure out what is actually true, take charge of it, and protect the people on the other end.

The details

Dates, roles, certifications, and the full training record are on the resume.

View Full Resume