Principal Cybersecurity Architect
Los Angeles County Employees Retirement Association (LACERA) | August 2023 – June 2024
Role Summary
Senior-most technical authority for a dedicated cybersecurity engineering team reporting under the CISO. The public evidence centers on privileged-access elimination, continuous red-team / blue-team operations, phishing containment, compliance automation, change-management integration, and visible risk reduction in a regulated public retirement environment.
- Led a five-person dedicated cybersecurity engineering team as the senior-most technical authority under the CISO, shifting the team from reactive whack-a-mole on user reports and Netskope alerts to consistent daily workflows focused on fundamentals and holistic remediation; user-submitted incidents and business disruptions fell from dozens per day to a handful per week, while GRC moved from constant chasing of IT staff to dashboard-driven work, reducing audit compliance effort from a dedicated full-time auditor to a monthly inter-team checkpoint with largely automated report generation.
- Implemented Entra Privileged Identity Management with Just-in-Time access, eliminating 45 standing privileged accounts and all persistent admin access except a monitored break-glass account, while unifying a single audit trail and introducing M-of-N controls integrated with change management.
- Stopped a successful phishing compromise of a high-value, high-privilege executive account with zero data extraction, zero lateral movement, and no impact to business systems, validating the effectiveness of the new privileged access and monitoring controls.
- Deployed Pentera as a continuous red-team capability that initially surfaced hundreds of findings (thousands when correlated with Defender), consolidated after MITRE-aligned triage to approximately 360 actionable items; Critical and High severity issues (roughly 10–15 percent of the total) were closed within the first month’s change cycles, and the residual backlog was driven down to an average of 10–12 active findings, with zero-day exposures typically detected within 1–24 hours of CVE assignment and more than 80 percent remediated inside a single change cycle.
- Paired Pentera (red team) with the Microsoft Defender / Purview suite (blue team) to institutionalize regular red-team / blue-team war-game exercises, producing a two-order-of-magnitude drop in Defender events (from hundreds of thousands to thousands per week across the enterprise) and closing nearly all historical vulnerabilities within one quarter of joint operation.
- Integrated security tooling and processes into existing fire-drill and disaster-recovery exercises, creating a unified operational cadence that enabled full business continuity during a real high-privilege account lockdown with zero impact to internal users, external consumers, or public-facing services.
- Led RFP, demonstration, and proof-of-concept processes for SIEM, SOAR, and SASE platforms while simultaneously advancing the organization’s compliance maturity more than 30 percent across key frameworks through prioritized controls and programmatic governance.
- Drove ServiceNow-based GRC and change-management integration that increased legitimate change tickets from a handful per month to dozens per week, established a weekly Change Review Board with security as an equal participant, and reduced change delivery cycles from weeks to days or hours with almost no post-change security regressions.
- Delivered real-time security dashboards and live monitoring that compressed project charter and board-approval cycles from multi-quarter processes to a standard monthly cadence, unlocking faster budget and resource decisions and organization-wide visibility into posture and progress.