Senior GRC & Information Security · Florida

Security and compliance
your auditors accept
and your board understands.

Independent consultant for Florida organizations working through the FTC Safeguards Rule, HIPAA and AI governance. Twenty years in technology, now focused on turning requirements into controls, owners and evidence.

Book a scoping call → See how I work →
Remote-first across Florida and the U.S. · +1 786 664 1200
Focus
FTC Safeguards · GLBA HIPAA · HITECH AI Governance FIPA · Florida NIST CSF 2.0 ISO 42001

Why me

Senior work, without the firm.
And AI governance most consultants cannot cover yet.

Senior-level, independent rates

You get the consultant who does the work, not a partner who sells it and a junior who delivers it. One point of contact from assessment through evidence.

AI governance, in practice

AI tools are already inside your workflows. I inventory them, classify their risk and build the policy, review and monitoring structure around them using ISO 42001 and the NIST AI RMF.

Bilingual, both markets

English and Spanish, and equal fluency in U.S. and European frameworks. Useful if your business spans Florida and Latin America or Europe.


Frameworks

What applies to a Florida business.
And what to do about it.

U.S. compliance is sectoral: your obligations depend on the data you hold and the customers you serve. I map which of these actually applies to you before recommending any work.

Regulation

FTC Safeguards Rule
Applies to a far wider set of businesses than the name suggests: lenders, dealers, tax preparers, mortgage and title operations. Written program, qualified individual, vendor oversight.
HIPAA · HITECH
Protected health information. Security Rule risk analysis, safeguards, business associate agreements and breach notification for providers, plans and their vendors.
FIPA · Florida
Florida Information Protection Act. Reasonable measures to protect personal information, plus notification to affected individuals and the Attorney General within 30 days.
Sector overlays
Contractual and state-level obligations that stack on top: customer security addenda, insurance questionnaires, and privacy laws applying to your out-of-state customers.

Frameworks & standards

NIST CSF 2.0
The common language for U.S. security programs. I use it to structure every engagement: current-to-target profile, prioritized roadmap, and a governance function your leadership can own.
NIST AI RMF
Reference model for identifying and managing AI risk by use case. The basis for risk-tiering the AI systems already running in your business.
ISO/IEC 42001
Management system for responsible AI. Structure for AI inventory, risk classification, human oversight and lifecycle controls.

Services

Three engagements.
Each one ends in something you can show.

Financial services

FTC Safeguards Rule Compliance

Written program, qualified individual, vendor oversight and the documentation that proves it runs.

Details →
Healthcare

HIPAA Security Readiness

Risk analysis, safeguards, business associate oversight and a breach playbook that works.

Details →
AI

AI Governance Program

Inventory, risk tiers, policy and oversight for the AI already in use across your business.

Details →

Start here

Thirty minutes, no pitch.
You will know what applies to you.

Tell me your industry, your data and what triggered the question — a customer questionnaire, an insurer, an audit, a new AI tool. I respond within one business day.

Book a scoping call

+1 786 664 1200