01

Summary

Cybersecurity Leader in the defence market at Thales, supporting Department of National Defence and Canadian Forces projects. 20+ years leading cybersecurity teams with 7+ years in senior leadership. Background as a digital forensics practitioner, sales engineer, and in consulting. Experienced in turning complex engineering projects into practical capabilities, and leading the teams that deliver them.

02

Experience

  1. Jun 2024 - Present
    Ottawa, Ontario

    Principal of Cyber Security (Acting Head of Discipline)

    Thales
    • Grew the Defence Cyber team, building the discipline's delivery capacity from a part-time function into a full Cyber team.
    • Stood up the NDEC's (National Digital Excellence Centre) first centralized cyber lab, creating in-house network threat hunting (RSA NetWitness & Zeek), threat intelligence (MISP & OpenCTI), forensics (Encase and X-Ways) and detection-engineering capabilities that previously did not exist.
    • Designed and launched a cyber range training environment (DIATeam), used today to train hundreds of personnel, improving operational readiness and threat response skills.
    • Owned the vision and multi-PI roadmap (SAFe Agile) for LC5ISRT cybersecurity, sequencing delivery across Thales teams, defence-industry partners and government stakeholders to align with Canadian Forces mission requirements.
    • Translated DND/CAF operational requirements into a prioritized program board, owning ship/no-ship decisions and resolving cross-team dependencies to keep delivery aligned to timelines.
  2. Dec 2020 - Jan 2024
    Santa Clara, California

    Director of Engineering (CXtr 3rd Party Integrations)

    Cisco
    • Led the SecureX integration ecosystem supporting thousands of enterprise SOC users, enabling cross-platform detection and response workflows.
    • Grew ecosystem from 10 to 75+ vendors over 3.5 years, expanding coverage across security tools and data sources.
    • Transformed integration onboarding from 3-4 months down to 1 week by shifting from partner-built AWS/Python solutions to a fully managed platform model.
    • Enabled scalable, partner-driven integrations, reducing dependency on custom engineering and accelerating ecosystem growth.
    • Built containerized pipelines (Docker, Kubernetes) to streamline integration development and improve delivery speed.
    • Managed a $5M integration program, improving adoption through workflow automation and developer enablement.
  3. Sep 2015 - Dec 2020
    Toronto, Ontario

    Principal Consultant

    RSA
    • Designed and delivered threat hunting programs for executive stakeholders, improving understanding of detection and response workflows.
    • Built sandboxed cyber range environments simulating real attack scenarios, enabling hands-on training for enterprise customers.
    • Translated real-world threat patterns into actionable product insights, aligning platform capabilities with customer needs.
    • Developed investigative playbooks used by incident response and SOC teams.
  4. Aug 2014 - Sep 2015
    Toronto, Ontario

    Specialist / Forensics Investigator

    KPMG
    • Conducted forensic investigations across enterprise environments using X-Ways and F-Response, including malware analysis, insider threats, and incident response.
    • Built custom forensic tools (Automated FTK Imager bootable CD) to support regulatory and legal investigations.
  5. Sep 2012 - Aug 2014
    Toronto, Ontario

    Senior Consultant

    Deloitte
    • Built a Cyber Threat Management Portal (CTMP) product and service delivering real-time, actionable intelligence feeds to enterprise customers.
  6. Feb 2011 - Sep 2012
    Waterloo, Ontario

    Forensics Investigator

    Research in Motion
    • Led incident triage and malware reverse-engineering for global breaches.
    • Pinpointed gaps in RIM's security posture and built incident-response playbooks, streamlining tooling and cutting response times.
  7. Feb 2006 - Mar 2010
    Scarborough, Ontario

    Network Security Analyst

    Scotiabank
    • Performed forensic investigations on insider-threat, fraud, and malware incidents.
03

Education

  • Jun 2025 - Jun 2026 Product Management, MIT (Professional Education)
  • 2003 - 2006 Advanced Diploma, Computer Security and Investigations, Sir Sandford Fleming College
04

Certifications & Coursework

  • Aug 2022 - Apr 2030GCTI - Cyber Threat Intelligence - GIAC
  • Oct 2020 - Nov 2028GCFA - Certified Forensics Analyst - GIAC
  • Oct 2017 - PresentOSCP - Certified Professional - Offensive Security
  • Aug 2015 - Aug 2027GREM - Reverse Engineering Malware - GIAC
  • Jun 2025 - Sep 2025Designing High Impact Solutions (MITdesignX) - MIT
  • Sep 2025 - Dec 2025Designing Product Families: From Strategy to Implementation - MIT
  • Dec 2025 - Mar 2026Digital Platforms: Designing Two-Sided Markets - MIT
  • Mar 2026 - Jun 2026Forecasting Technology Innovation: Using Data for Strategic Advantage - MIT
05

Skills

Product & Strategy

AI Product Management · Product Roadmapping · Strategic Planning · User-Centric Design · SaaS Platforms

Cybersecurity

Digital Forensics & Incident Response · Threat Detection & Response · Threat Intelligence · Computer Security · Networking Protocols

Forensics Tooling

FTK · X-Ways · Encase

Technical

OpenAI API · Anthropic API · Model Context Protocol (MCP) · LLM Technologies · AWS · Docker · Kubernetes · Python · Secure Architecture

Execution

Cross-Functional Leadership · Stakeholder Management · Agile (SAFe) · Process Optimization

06

Projects

44Net PoP

connect.44net.cloud ->

VPN infrastructure points of presence for the 44Net cloud network, serving the amateur radio community.

HashLookup.org

coming soon

Next-generation AI-powered cyber search engine utilizing MCP and a custom backend.

07

Also

Outside the day job: licensed amateur radio operator (VA3IAN), homelab tinkerer (Proxmox, Docker Swarm, MikroTik, SDR), and persistent builder of things that probably didn't need to exist but were fun to make anyway.