I help agencies and enterprises govern and secure their AI — standing up oversight under NIST's AI Risk Management Framework, and controlling the fastest-growing risk in security: AI agents and machine identity. Move fast, without it blowing up.
Agencies and companies are pushing AI and autonomous agents into production while their oversight, risk, and identity controls lag years behind. Regulators and boards have raised the bar — and most organizations have no working answer.
The hardest part is identity. AI agents are non-human actors operating inside your trust boundary with credentials you issued them — and almost no one can see, count, or govern them.
A fixed-scope, NIST AI RMF-based gap assessment of your AI use and oversight — with an AI inventory, risk register, and a prioritized roadmap.
Ongoing senior guidance to stand up and run your AI governance program — policy, oversight, and the frameworks that keep you defensible.
Discover, control, and monitor non-human and AI-agent identities — the spearpoint of modern identity security.
Bring AI-enabled systems through the Risk Management Framework and authorization — NIST 800-53 and the GenAI profile, done right.
Clear, credible briefings that translate AI risk into decisions leadership can act on — boardroom to program office.
Prepare your AI management system for ISO/IEC 42001 and the mandates your customers and regulators require.
A fixed-scope readiness assessment maps your AI landscape, risks, and gaps against NIST AI RMF and the rules that apply to you.
You get a prioritized, executable plan — and a clear picture of what governing your AI actually requires.
Retained advisory to execute the roadmap, brief leadership, and keep your program current as AI and the rules evolve.
I spent 30 years inside federal cybersecurity and law enforcement — including as Deputy Director and Technical Program Manager of DHS's HART biometric program, leading 300+ personnel on one of the nation's most sensitive identity systems. I bring that same rigor to how agencies and companies govern and secure AI.

A Leader’s Playbook to Stand Up, Run, and Defend AI Governance — and Adopt AI With Confidence.
Adopt AI fast, leadership says. Stay defensible, oversight demands. Between those two pressures stands the security and governance leader — with no proven playbook. This is the operational field manual for that job: a four-phase lifecycle — Stand Up, Operate, Mature, Defend — one unified control set that reconciles NIST AI RMF, ISO/IEC 42001, the EU AI Act, and OMB M-25-21 into 28 controls you can actually run, and a 90-day stand-up sequence that survives first contact with oversight.
A veteran-owned small business, registered and ready to contract — as a prime or on your team — and equally at home advising a corporate boardroom.
A 30-minute conversation on where you are and what governing your AI actually takes.
Book a Consultation