Cybersecurity · Networking · AI Agents

Automating the boring stuff,
securing the rest.

I build AI agents that take over the repetitive work: invoicing, quotes, follow-ups, data entry. They're built, deployed, and running in production, backed by 15 years inside regulated financial services and the certifications behind the work.

Certified
  • CISSP
  • CISM
  • CISA
  • GCIH
  • eCPPT
ProductionAI systems live and generating revenue
15+Years in regulated financial services
10+Certifications (CISSP, CISM, CISA)

About

Most of the work that eats your week isn't the work.

Invoices that need sending. Quotes that need following up. Emails that need answering. I build AI agents that handle all of it, so you and your team can focus on the work that actually moves the business.

My Approach

I start by watching how you actually work, not by pitching tools. I find the tasks eating your team's time and automate them with AI agents that work alongside your people, not instead of them — the machine handles the repetitive lift and hands off to a human the moment it matters. Only then do I think about security. Every engagement is practical: real workflows, real systems, deployed and running.

What Sets Me Apart

Deep technical expertise paired with a focus on the boring stuff. I've run security programs at a regulated financial institution and built production AI systems that generate revenue. I don't just talk about automation — I build it, deploy it, and it works.

Innovation

AI agents that do the work nobody wants to do.

If a task is repetitive, rule-based, or just plain tedious, it can be automated. I've built production systems that handle client outreach, bookings, and engagement — the same systems work for invoices, quotes, and follow-ups.

Automated Lead Generation Platform

In production

A production-deployed AI system that automates the entire outbound pipeline — from prospect discovery and qualification to personalized outreach and appointment scheduling. Built for service-based businesses, it replaces manual SDR workflows with intelligent agents that operate around the clock. Live, generating real client engagements.

AI Booking & Engagement System

In production

A conversational AI agent that picks up when your team can't — takes messages, generates quotes, schedules meetings, and handles routine client communication. When a conversation needs a human, it hands off automatically. Deployed in production with active users.

24/7Autonomous operation, no intervention
AI-NativeLarge language models, not rule-based bots
RevenueReal bookings, not vanity metrics

AI that works with your people, not instead of them.

An agent that picks up the phone when no one's available, takes the message, generates the quote, or schedules the meeting. The moment a real conversation matters, a human steps in. People don't like talking to machines, so I put machines where they save your people time — and keep humans where they matter.

  • Picks up when you can't

    Messages, quotes, and meetings covered when your team is busy or away

  • Hands off to a human

    The moment a real conversation matters, a person takes over

  • People-first by design

    Machines do the repetitive lift; people handle the relationships

Core Expertise

What Oto excels at.

Building AI agents that handle the boring work, and keeping the technical foundation secure underneath.

AI Agents & Business Automation

Custom AI agents that take over the repetitive work: invoicing, quoting, follow-up emails, data entry, scheduling. Built for your actual workflows, deployed in production, running 24/7.

Penetration Testing

Comprehensive offensive security assessments — external, internal, web app, and social engineering. Methodical, scoped, and actionable reporting aligned to PTES and OWASP standards.

Security Architecture

Defense-in-depth design and review across Cisco, pfSense, and Aruba environments. Firewall rule auditing, segmentation strategy, and zero-trust readiness assessments.

AI Governance & Compliance

NIST AI RMF and ISO 42001 implementation for regulated industries. Policy frameworks, risk assessments, and AI system lifecycle controls tailored to financial services.

Vulnerability Management

Continuous assessment programs — discovery, prioritization, validation, and remediation tracking. Triage that separates signal from noise and drives measurable risk reduction.

Brand Protection

External threat monitoring, domain/brand impersonation detection, and takedown coordination. Proactive defense of digital identity across the attack surface.

Network Infrastructure

Design, implementation, and hardening of enterprise networks — routing, switching, VPN, and segmentation. Cisco, Aruba, and pfSense expertise with operational excellence.

Credentials

Certified across the full stack.

The credentials behind the work. Fifteen years in a regulated financial institution, validated across offensive security, governance, and network engineering.

  • CISSPCertified Information Systems Security Professional
  • CISMCertified Information Security Manager
  • CISACertified Information Systems Auditor
  • GCIHGIAC Certified Incident Handler
  • eCPPTeLearnSecurity Certified Professional Penetration Tester
  • PenTest+CompTIA PenTest+
  • CCNPCisco Certified Network Professional
  • CCNACisco Certified Network Associate
  • Network+CompTIA Network+
  • A+CompTIA A+

Education

Academic foundation.

Formal education that bridges technical security and business management — the combination that makes security leadership effective.

  • M.S. Cybersecurity & Information AssuranceWestern Governors University
    Graduated 2025
  • B.S. Business Administration, ManagementWestern Governors University
    Graduated 2024

What I do

What I work on.

If it's repetitive, I can automate it. If it's technical, I can secure it.

Business Process Automation

  • Phone agents that take messages, quote jobs, and book meetings after hours
  • Invoice generation and payment chasing — built and running
  • Quote drafting and client follow-up, handled before anyone opens the inbox
  • Email triage that sorts routine client mail from the rest
  • Data entry, reporting, and document workflows running unattended

AI Governance Programs

  • NIST AI RMF implementation
  • ISO 42001 readiness assessments
  • AI risk assessment frameworks
  • Regulatory compliance mapping

Security Audits & Gap Assessments

  • Full-scope security posture evaluation
  • Control framework mapping (NIST, ISO, CIS)
  • Prioritized remediation roadmap
  • Executive-ready reporting

Penetration Testing

  • External & internal network testing
  • Web application security testing
  • Social engineering simulations
  • PTES-aligned methodology & reporting

Vulnerability Management

  • Continuous assessment programs
  • Discovery, prioritization & validation
  • Remediation tracking
  • Signal vs. noise triage

Firewall & Network Review

  • pfSense, Cisco, and Aruba audits
  • Rulebase analysis & optimization
  • Segmentation strategy design
  • Zero-trust readiness evaluation

Career

From IT support to security leadership.

Fifteen years in a regulated financial institution, from IT support to Director of Information Security and Cyber Risk. I've built the security programs that protect member data, run the networks that keep operations alive, and earned credentials spanning offensive security and infrastructure. I write about AI and security from inside the work, not from the sidelines.

Newsletter

Twice a month, whatever I'm thinking about.

AI, cybersecurity, and the business side of both. No pitch, no spam.

Two emails a month
give or take
Never sold
your email stays with me
One click out
unsubscribe anytime

How I handle your information: Privacy

Want to talk shop?Find me on LinkedIn