From the boardroom to the build pipeline.
Security leadership built for the AI era.
I build security programs that work — ones that pass audits, enable growth, and actually get adopted by the teams they’re meant to protect. 25+ years spanning network engineering, cloud infrastructure, application security, DevSecOps, compliance, and executive leadership.
I build security programs that work — ones that pass audits, enable growth, and actually get adopted by the teams they’re meant to protect.
With 25+ years of experience spanning network engineering, cloud infrastructure, application security, DevSecOps, compliance, and executive leadership, I bring a full-stack perspective that lets me engage credibly from the boardroom to the build pipeline. I’m equally comfortable presenting risk posture to a board as I am architecting a cloud security control or building an AI-powered security workflow.
Today I lead SideChannel’s vCISO delivery practice — overseeing a team of consultants delivering fractional CISO services to 40+ clients across a broad range of industries — while also advising clients directly, working hands-on to build and mature security programs across technology, manufacturing, hospitality, and higher education.
A consistent theme across my career: I show up where organizations need to build something. Whether that’s founding a security program at Wayfair, building Scout Exchange’s SOC 2-compliant security practice from scratch, or guiding a national manufacturer to completely remediate repeated failed penetration tests showing full-domain compromise — I build things that last.
I’m now focused on helping organizations navigate the AI era — both governing AI risk responsibly and deploying AI to make security programs smarter and more efficient. I've completed ISO 42001 (AI Management Systems) and ISO 31000 (Risk Management) training and actively build AI-powered tooling to enhance security delivery. I also contribute to the ISC² CISSP exam development process and co-authored “The Six Pillars of DevSecOps” for the Cloud Security Alliance.
“The brakes on a car are what allow it to go fast — without them, you drive fast but recklessly, endangering yourself and everyone around you. The right security program works like the brake pedal: invisible in daily use, instinctual for the people who rely on it, yet hiding vast complexity behind something deceptively simple.”— Eric Gauthier
End-to-end builds grounded in NIST CSF and ISO 27001 that pass audits and get adopted.
Embedding security throughout the SDLC with DAST/SAST/SCA scanning and CI/CD hardening.
ISO 42001-based programs and frameworks for responsible, secure AI adoption.
SOC 1/2, PCI-DSS, GDPR, ISO 27001 — audit-ready programs that drive revenue.
Infrastructure-as-code, container and serverless hardening, AWS cost governance.
Led major IR efforts — reduced median resolution from 1 week to 1 day at Lightcast.
A couple of pieces worth a read — one on rethinking phishing defense, one a foundational contribution to DevSecOps practice.
Why user-blaming falls short as a phishing defense — and how DMARC, email gateway controls, and rethinking internal email entirely stop attacks at the source.
Co-authored for the Cloud Security Alliance — a framework-agnostic model for implementing DevSecOps in practice, covering team structure, culture, and the technologies that underpin it.
That means embedding it into the culture, the pipeline, and the default — not bolting it on at the end and hoping it sticks.
Building programs from the ground up or maturing existing ones — policy, governance, and operations that pass audits and actually get adopted by the teams they protect.
NIST CSF/SSDF, ISO 27001, SOC 1/2, PCI-DSS, GDPR. Translating audit requirements into prioritized, business-aligned roadmaps rather than checkbox exercises.
ISO 42001-based governance frameworks for organizations adopting AI — balancing responsible risk management with practical, secure deployment.
Infrastructure-as-code, container and serverless hardening, and Zero Trust design for cloud-native environments with no legacy perimeter to fall back on.
Embedding security throughout the SDLC — automated DAST/SAST/SCA scanning, secure design checklists, and CI/CD pipeline integration that engineering teams actually use.
Leading response efforts across endpoint compromise, BEC, and targeted attacks — then translating risk posture clearly for boards and executive leadership.
Equally at home in a board meeting, a risk assessment workshop, and a CI/CD pipeline review.
A track record built at some of the web’s largest platforms and SaaS companies. Scroll to explore.
Lead SideChannel’s vCISO delivery practice — overseeing a team of 10 consultants serving 40+ active clients — while serving as the firm’s named CISO. Promoted to VP in January 2024 after joining as Principal Consultant in January 2023.
Led global IT, infrastructure, and security for a labor market analytics SaaS company, with an explicit mandate to build the organization’s holistic security program from the ground up.
Built and led the security program for a cloud-based SaaS recruiting marketplace, operating at the intersection of security governance, DevOps, and compliance.
Built ShoeBuy’s security program from scratch, directing the full scope of infrastructure and information security for the e-commerce platform.
Founded Wayfair’s Information Security and compliance program while leading systems engineering for the company’s rapidly scaling e-commerce infrastructure.
Served as network representative on BU’s IT security team across a ten-year tenure spanning individual contributor and management roles in network engineering and operations.
“The best conversations I’ve had with other practitioners weren’t about finding a job or filling a role — they were just two people comparing notes.”
I’m always happy to connect with other security and technology leaders — whether that’s a question about AI governance, navigating compliance in a SaaS or technology environment, or just talking through where the field is headed. No agenda required.
I’m also open to board and advisory roles, and to mentorship or volunteer opportunities where 25+ years of program-building experience is useful.
Book Time →