//About

My story.

Most security work produces more artifacts than clarity. Executives don't need frameworks. They need decisions they can stand behind. That is the work I do.

I translate complex cybersecurity, vendor, and enterprise risk into concise, executive-ready briefs that support fast, defensible decisions. After more than two decades in the field, that is the thing I have learned matters most. Not another dashboard. A clear call someone can stand behind.

Recent work

Right now I am building out a global cybersecurity team, putting in place the people, the structure, and the standards a security function needs to work across regions. I also recently led security due diligence on a $1B acquisition.

For an $850M organization I built a three-year security transformation roadmap representing a $3.6M investment. The hybrid build-and-buy strategy achieved $5.8M in cost savings while closing 65% of a CMMC Level 2 compliance gap and protecting a $320M defense contract pipeline.

Innovation

I am a co-inventor on two US AI patents in 3D medical image analysis, bridging cybersecurity and healthcare through privacy-preserving diagnostic systems. The first, now issued as U.S. Patent No. 12,665,073, was granted by the USPTO in 2026. The second, Application No. 19/199,034, is in examination. There is more on the Patents page.

Background

My career spans enterprise, government, healthcare, finance, and technology, including CISO-level roles overseeing global security programs, regulatory compliance, incident response, and high-risk transformation. My work covers cloud security on AWS and Azure, Zero Trust, DevSecOps, IAM, and MDR/XDR, with regulatory programs aligned to SOC 2, PCI-DSS, HIPAA, GDPR, NIST, and CMMC.

Increasingly my focus is rapid risk interpretation: reviewing vendor documentation, security assessments, and complex inputs to surface what actually matters, what does not, and what leaders should do next.

Writing

I am the author of Sarah and the Malware Fairy, a children's cybersecurity book that teaches online safety through story rather than fear, and CyberSecurity Metaverse. More in the articles.

Beyond the work

Outside of cybersecurity I cook (you will find me as @cookwithsaj), invest in real estate, support the Blanquita Foundation's work on clean water and women's empowerment, and spend my best hours raising my kids.

//Career

Two decades, eight chapters.

2025-Present

CECO Environmental Corporation

Director, Cybersecurity & Risk · Dallas, TX. Building out a global cybersecurity team. Recently led security due diligence on a $1B acquisition.

2021-2025

American Heart Association

Sr. Director / Director, Cyber Security & Risk · Dallas, TX. Led enterprise-wide cybersecurity strategy and risk management for a $1B global organization.

2019-2020

City of Carrollton

Technology Officer · Carrollton, TX. Directed enterprise cybersecurity and IT risk, and collaborated with the FBI on cyber incidents.

2017-2019

FBMC Benefits Management

Chief Operating Officer · Tallahassee, FL. Led operations, technology, and cybersecurity across a team of 55+ during a pivotal period.

2016-2017

United Solutions Company

SVP / Chief Information Officer · Tallahassee, FL. Led enterprise technology strategy and operations for a national FinTech organization.

2014-2016

Omnicom Media Group

Director of Technology · Toronto, Canada. IT operations and digital transformation for clients including Honda, Apple, McDonald's, and Microsoft. Cut application development cycles by over 50%.

2013-2014

Cook County Sheriff's Department

Chief Technology Officer · Chicago, IL. Reduced infrastructure costs by 46% while improving resilience and uptime.

2001-2012

Ogilvy

Chief Technology Officer / IT Technical Manager · Chicago & Toronto. More than 11 years leading technology at one of the world's best-known agencies.

//Education

Where it started.

2015-2017

University of Miami

Master of Business Administration (MBA)

1996-2000

York University

B.S., Computer Science