Head of IT & Enterprise Security — Aeva
Leading IT and Enterprise Security as a single function. Just getting started — more here as the work takes shape.
I run IT and security organizations through scale: hiring teams, standing up programs, choosing tools, and quietly removing the friction that slows everyone else down. Most of my career has been spent inside companies as they grew from a few hundred people to several thousand.
CISSP, CISSP-ISSMP, and CCSP. Comfortable working onsite or hybrid. Based in the San Francisco Bay Area.
I've run IT and Security as one function for most of my career, and I think that's the right model — the two disciplines under one roof, with a direct line to the business and a real seat at the table. That's the role I'm in at Aeva as Head of IT & Enterprise Security: technology treated as strategic, and problems worth modernizing. I run toward the messes — legacy estates, struggling teams, post-acquisition integration — because that's where the work matters most.
Operational excellence without blame: when something breaks, we find the root cause, fix it, and make sure it can't recur — no finger-pointing. And I stay invested in people even when the path is hard. When we wound down our Seattle office, I told the team straight, negotiated packages, and helped place the people who couldn't relocate; the director I most needed through the transition is still a friend today. You can do something hard to people without breaking the relationship — if you do it honestly.
Leading IT and Enterprise Security as a single function. Just getting started — more here as the work takes shape.
Led IT strategy and operations for a global workforce, setting the IT vision, mission, and roadmap and turning them into a prioritized investment plan for security, AI, and operational improvement. Raised management-confidence scores from 77% to 93% in a single year through career development, leveling-matrix redesign, and team-engagement work.
Stood up a SaaS-governance program — replacing Bettercloud with Trelica, classifying all 150+ applications against policy, and adding shadow-IT detection over a single software source-of-truth. Drove device trust and phishing-resistant authentication to 100% compliance with Kolide Device Trust and Okta Fastpass, modernized the service desk with automated routing and AI-assisted self-service, and championed AI adoption across IT and workplace teams.
Owned the Employee Experience product, engineering, and operations teams plus the Secure Identity Engineering team (Okta, Azure AD, and bespoke applications) — the bridge between IT and Security for a frictionless, secure employee experience at enterprise scale, alongside day-to-day service desk and core-application operations.
Led engineering for a passwordless, phishing-resistant authentication initiative using FIDO2/WebAuthn across platforms and applications; ran identity and directory integrations for multiple acquisitions, including a Google Workspace migration that had failed twice before; migrated operations to a new managed-service partner at lower cost and improved SLAs; and delivered early GenAI tooling, including an in-house Azure/OpenAI assistant integrated with Slack. Managed a team of roughly 35 staff plus 65 contractors.
Hired as VP of IT to modernize aging infrastructure and rebuild a struggling team; promoted to also lead Customer Care and DevOps/Global Hosting. Owned the systems, security, and support that touched every employee, player, and office across studios in San Francisco and Hyderabad.
Drove an enterprise-application overhaul — Oracle ERP Cloud (delivered in five months, on time and on budget), Workday HRIS, and a rebuilt order-management system — and restored daily sales-reporting reliability across dozens of interfaces. Rebuilt the security program and anti-phishing training after leading the company through a major incident, managed a multi-cloud (AWS/GCP) environment, and scaled the Hyderabad customer-care team from 15 to 50 while holding cost per ticket flat.
Provided executive leadership for IT and Real Estate as a member of the executive management team at a newly public Rackable Systems, which acquired Silicon Graphics in 2009 to form Silicon Graphics International. Built the IT function from 5 to 17 people, then grew the combined post-acquisition team to 48 across eight global sites, running a $33M combined budget.
Implemented Oracle E-Business Suite across finance, order management, manufacturing, and supply chain within seven months of the IPO; led a clean first year of SOX compliance with no significant deficiencies; and consolidated the merged company onto a single global Oracle ERP instance, including a SAP-to-Oracle migration in Japan. Delivered steady cybersecurity and infrastructure improvements with corporate-wide security education.
Joined during a period of hypergrowth and progressed from senior systems administrator through IT manager to Director of IT Infrastructure, ultimately responsible for a global network spanning five data centers and forty offices and a team that grew from 20 to 54 — largely through M&A.
Integrated IT teams and environments from eleven acquisitions, designed and built highly available environments for Oracle Financials, Exchange, and engineering workloads, and cut telecom cost while improving voice quality with a global MPLS network. This is where most of how I think about IT was formed — uptime is a feature, and the network is never the problem until it is.
Leading IT as companies grow from a few hundred employees into the thousands. Hiring, operating model, tool consolidation, on-call, and the operating relationship between IT, security, and the business.
Building security programs that work with the business, not against it — identity and SSO consolidation, phishing-resistant authentication, endpoint and device-trust strategy, and SOX-grade compliance from a clean first-year audit onward. Real incident response, led under pressure, and the anti-phishing programs that follow.
Helping organizations decide what AI tooling to allow, how to review it, and where the line sits between productive use and data exposure. Acceptable-use policy, vendor review, model and data inventory, governance committee work that keeps policy honest.
Treating the employee's day-one-to-offboarding journey as a product — role-based access (RBAC) granted automatically on day one and revoked the moment someone leaves, onboarding that's secure by default, and the service desk, devices, and workplace tech that make the secure path the easy one rather than the obstacle.
Folding acquired companies' IT and identity in fast and cleanly — 20 acquisitions integrated across a career, plus carve-outs and spin-offs. Directory and SaaS consolidation, application and ERP migration, and the IT and security due diligence that decides what you're actually inheriting.