Award Recognition
Nominated for Chief Information Security Officer of the Year
Cybersecurity Excellence Awards 2026
View NominationProfessional Summary
Chief Information Security Officer who leads with vision and impact, specializing in translating complex security frameworks into practical, business-focused outcomes. Known for a calm, consultative approach that empowers business leaders to focus on growth with confidence that their data and systems are protected. Expertise spans regulatory compliance, cloud security architecture, and risk management for organizations across FinTech, legal services, healthcare (HIPAA), payment processing (PCI DSS), and defense contracting (CMMC) sectors. Core philosophy: turning compliance from a burden into a strategic advantage that drives trust, growth, and recurring revenue.
Core Expertise
Regulatory Compliance
- HIPAA Security & Privacy Rules
- PCI DSS Requirements
- CMMC Level 2 Compliance
- GDPR Implementation
- FTC Safeguards Rule
Cloud Security
- Microsoft 365 Security
- AWS Security Architecture
- Azure Security Solutions
- Cloud Access Controls
- Identity Management
Security Operations
- Incident Response Planning
- Business Continuity
- Disaster Recovery
- Security Auditing
- Vulnerability Management
Risk Management
- Vendor Risk Assessment
- Third-Party Risk Management
- Business Impact Analysis
- Security Policy Development
- Compliance Gap Analysis
Professional Services
Chief Information Security Officer - MSP
Serving as full-time CISO for a Managed Service Provider, overseeing security operations, compliance programs, and risk management for the organization and its diverse client base. Developing scalable frameworks that help businesses not only meet regulatory requirements but also leverage security as a driver of trust and competitive advantage. Focus on creating standardized baseline configurations, guiding policy enforcement, and mentoring MSPs across the country to ensure security is proactive, measurable, and sustainable.
Virtual CISO Services
Providing fractional CISO services to organizations across multiple regulated industries requiring executive-level security leadership. Consultative approach that empowers business leaders to make informed decisions while maintaining robust security posture. Services include strategic security planning, board-level reporting, security program development, and regulatory compliance management tailored to FinTech, legal, healthcare, payment processing, and defense contracting sectors. Trusted advisor focused on practical outcomes over checkbox compliance.
Compliance Program Development
Comprehensive compliance program design and implementation for HIPAA, PCI DSS, CMMC, GDPR, and other regulatory frameworks. Development of policy suites, security controls implementation, staff training programs, and ongoing compliance monitoring.
Cloud Security Architecture
Expert guidance on securing cloud infrastructure across Microsoft 365, AWS, and Azure platforms. Implementation of identity and access management, data protection strategies, security monitoring, and compliance configurations for cloud-native organizations.
Incident Response & Business Continuity
Development of incident response plans, disaster recovery strategies, and business continuity programs that measurably increase organizational resilience. Creation of tabletop exercises, crisis communication protocols, and recovery procedures tailored to cloud-based operations. Focus on continuous risk assessments and proactive vulnerability reduction to minimize business disruption and accelerate recovery when incidents occur.
Vendor Risk Management
Comprehensive vendor security assessments, third-party risk evaluations, and supply chain security analysis. Specialized expertise in healthcare technology vendors, cloud service providers, and critical infrastructure suppliers.
Recent Project Experience
Compliance-as-a-Service Framework Development
National MSP Program
Architected and deployed scalable Compliance-as-a-Service frameworks providing organizations with the tools to achieve and maintain compliance with HIPAA, PCI DSS, NIST, and FTC Safeguards Rule. Created standardized baseline configurations adopted across multiple organizations, reducing implementation time by 60% while ensuring consistent security postures. Mentored IT leaders and MSPs nationwide on effective compliance program delivery, raising industry standards for security service providers.
CMMC Level 2 Compliance Implementation
Defense Contractor Compliance Program
Developed comprehensive 18-policy compliance suite covering all CMMC Level 2 domains. Created detailed implementation procedures, remediation timelines, compliance metrics, and audit preparation materials. Successfully prepared organization for CMMC assessment with full documentation and technical control implementation.
Cloud-Native Business Continuity
Managed Service Provider Resilience Program
Designed and implemented business impact analysis and disaster recovery strategies for MSP operating entirely on cloud infrastructure. Developed incident response plans for third-party cloud service failures, executive communication protocols, and detailed recovery procedures. Implemented continuous risk assessment processes that measurably reduced vulnerabilities and increased organizational resilience, with documented improvements in recovery time objectives and business continuity readiness.
Healthcare Compliance Modernization
HIPAA Security Rule Update Implementation
Analyzed proposed 2025 HIPAA Security Rule updates and developed implementation roadmaps for multiple healthcare clients. Created comprehensive GDPR and HIPAA compliance policies tailored for Microsoft cloud environments, including Entra ID and Intune security configurations.
Multi-Entity AWS Cost Attribution
Cloud Financial Management & Security
Implemented AWS Cost and Usage Report configurations with resource tagging strategies for accurate cost attribution across multiple client entities. Developed automated inventory scripts and security control implementations for AWS environments.
Industry Specializations
FinTech & Payment Processing
Specialized expertise in financial technology security, PCI DSS compliance for payment processing environments, and secure payment system architecture. Experience with payment gateway security, tokenization, encryption standards, and financial data protection requirements. Understanding of banking regulations and fintech compliance frameworks.
Legal Sector
Deep knowledge of law firm security requirements, attorney-client privilege protection, and confidential document management. Expertise in legal practice management system security, client portal configurations, and compliance with legal industry security standards. Experience with data retention policies and e-discovery preparation.
Healthcare
Comprehensive expertise in HIPAA compliance, patient data protection, healthcare technology vendor assessments, and patient portal security. Experience with electronic health record systems, telemedicine platforms, and healthcare business associate agreements.
Defense Contracting
Extensive experience with CMMC framework implementation, controlled unclassified information (CUI) protection, and defense contractor security requirements. Expertise in preparing organizations for CMMC assessments and maintaining ongoing compliance with defense industry standards.
Technical Skills & Platforms
Recognition & Awards
Chief Information Security Officer of the Year Nominee
Cybersecurity Excellence Awards 2026
Recognized for leading cybersecurity strategy and compliance initiatives with vision and impact across multiple regulated industries. Nomination highlights include developing scalable compliance frameworks, mentoring IT leaders nationwide, and transforming security from operational cost into strategic business advantage. The Cybersecurity Excellence Awards honor companies, products, and professionals advancing cybersecurity worldwide, backed by a community of over 600,000 security professionals.
Connect
For cybersecurity consulting, vCISO services, or compliance project inquiries, please connect via LinkedIn or visit dickietechnologies.com for more information.