Sr. Lead, Cybersecurity Risk · Citgo Petroleum
Cyber Risk Quantification · IT/OT Risk Programs · Industrial Control Systems
8+ years securing critical infrastructure at enterprise scale — now leading cybersecurity risk across IT and OT at a major refiner, translating SCADA-level technical exposure into business impact executives can act on.
// Background
I'm a cybersecurity risk leader with deep specialization in Operational Technology (OT), SCADA, and Industrial Control System (ICS) environments. My career has been built at the intersection of engineering and security — where protecting critical infrastructure demands both technical depth and strategic thinking.
Today I lead cybersecurity risk at Citgo Petroleum, running risk assessments across IT and OT estates, driving vulnerability management, and using FAIR-based quantification to put a dollar figure on exposure so leadership can prioritize with real numbers instead of heat maps.
Before that, I spent 8 years at Chevron progressing from vulnerability analyst to program leadership, designing and deploying security solutions that protected some of the most critical systems in the energy sector. I bridge the gap between engineering teams and executive leadership, translating technical risk into business decisions.
Bilingual (English/Spanish), and equally comfortable in a field deployment or a boardroom briefing.
// Expertise
Run enterprise risk assessments across IT and OT estates under the NIST RMF, quantify exposure with FAIR, and report risk posture to stakeholders through KPIs and dashboards.
Deep hands-on experience securing SCADA, HMI, PLC, and process control networks in energy sector environments.
Built NIST- and CIS-aligned compliance programs from the ground up, driving audits, control evidence, and risk remediation at enterprise scale.
Researched and tracked threat actor groups, produced executive intelligence products, and led proactive threat hunting on corporate infrastructure.
Executed pen tests, full attack chain demonstrations, and remediated critical vulnerabilities across 500+ systems and multiple business units.
Led enterprise AIP deployments and elevated DLP capabilities using hash matching, document fingerprinting, and custom regex markers.
Managed full project lifecycles, cross-functional teams, and national-scale deployment programs across critical infrastructure sites.
// Career History
// Credentials
// Let's Connect
Always glad to talk shop with people working on ICS/OT security, cyber risk quantification, and critical infrastructure defense.