Chief Information Security & Transformation Officer at Lee Enterprises
Founded and led Lee Enterprises’ first security division as CISO, building governance and regulatory teams to achieve SOX and PCI-DSS compliance within six months. Directed work across GRC, incident response, vendor risk management, and security operations while implementing automated tools and playbooks that reduced incident response times. Developed enterprise security awareness and phishing programs, and advised leadership and compliance teams on security incidents, regulatory exposure, and third-party risks. • Produced and maintained risk registers, risk mitigations, and compliance procedures • Managed third-party security compliance through vendor risk assessments and remediation tracking • Used incident guidance and post-incident analysis to inform operational improvements • Led security training outputs intended to change workforce behavior toward phishing