Security architecture for cloud, identity & AI.
Senior Principal Information Security Architect
I architect cloud, identity, and AI security solutions for regulated environments — transforming complex risk into secure, scalable capabilities that enable business innovation.
"It's all in the logs…" — syslogfather, handle held for 20 years
AZ-305 · SC-100 · AZ-500
Security domains
Built for regulated, fast-moving environments.
I've spent 19 years in information security, most of that time in financial services — where security controls have to stand up to both attackers and auditors.
I'm a Senior Principal Information Security Architect specializing in cloud, identity, and AI security for regulated fintech. I design secure cloud environments, advise executive leadership, and build security programs that align with Zero Trust, regulatory requirements, and enterprise risk.
My career began in public-sector cybersecurity before moving into enterprise security engineering and architecture, ultimately leading security strategy for cloud-native platforms, SaaS, data, and AI systems. Today, my focus is helping organizations securely adopt AI through governance, risk management, and modern security architecture.
I've gone by syslogfather for nearly two decades — a reminder that the best security decisions start with evidence. That mindset continues to shape how I approach architecture, incident response, and security leadership.
Extreme ownership
Takes accountability from strategy through execution, building internal capabilities — such as eDiscovery and identity automation solutions — when they deliver greater long-term value than third-party alternatives.
Simplifying Complexity
Transforms complex or evolving security initiatives — including AI governance, MFA modernization, and SIEM operations — into clear, repeatable processes that enable teams to execute with confidence.
Evidence-Based Decision Making
Leads structured evaluations, proof-of-concepts, and technology assessments with measurable success criteria, ensuring recommendations are objective, defensible, and aligned with business goals.
Transparent Leadership
Builds trust through proactive communication, keeping executives, stakeholders, and cross-functional teams informed of risks, decisions, and progress to enable timely, confident action.
Enterprise Security Leadership & Program Execution
Nineteen years of security programs led across cloud, identity, AI, and detection engineering.
AI Governance & Shadow AI Oversight
- Built an AI governance program from the ground up, giving real-time visibility into GenAI tool usage across the workforce.
- Led data-loss-prevention strategy for generative AI and large language model tooling.
- Piloted next-generation gateway controls for agentic AI and developer tool-chains.
Impact: Cut AI tool vetting time from roughly a week of manual review to near real-time coverage.
Identity Modernization Program
- Led a multi-factor authentication platform migration, including conditional access policy design and phased rollout.
- Architected security controls for major workplace-suite and collaboration platform transitions.
- Directed the evaluation and rollout of secure access service edge (SASE) architecture.
Impact: Consolidated three concurrent identity migrations under one architecture roadmap.
Cloud Security Posture Management
- Ran structured, multi-vendor evaluations of cloud security posture tooling with data-driven selection criteria.
- Built cloud policy, key vault architecture, and access baselines across production environments.
- Delivered a full cloud security architecture assessment and posture dashboarding.
Impact: Data-driven vendor selection process backed by a full architecture assessment.
SIEM: Foundation to Modernization
- Built the original detection platform foundation and scaled it to full production delivery within a year.
- Currently leading a detection platform modernization evaluation.
- Owns log pipeline architecture and data onboarding across cloud and SaaS sources.
Impact: Foundation-to-production detection platform delivery in 12 months.
In-House Security Tooling
- Designed and built an in-house eDiscovery application, eliminating a third-party vendor.
- Delivered eDiscovery process design, build, and operationalization for a major workplace-suite migration.
- Built an internal testing framework to speed evaluation of new AI tools.
Impact: $30K saved annually by building in-house instead of buying.
Vendor Strategy & Program Governance
- Led 25+ security vendor proof-of-concepts since 2022 with documented, data-driven selection criteria.
- Built and maintains the security program's roadmap, lifecycle management, and metrics reporting cadence.
- Mentors team members and leads the team's recurring senior technical review.
Impact: A structured evaluation process now used across every major program.
In the news.
Advisor360 Gets a Handle on Shadow AI via Automation
Dark Reading profiled how Advisor360°'s security team, led by Michael Janielis, tackled shadow AI adoption across its workforce. With a five-person SOC previously vetting new AI tools manually over roughly a week, the team automated detection and policy enforcement with Harmonic Security — cutting response time from days to near real time and giving instant visibility into fast-moving situations like the DeepSeek AI launch.
"It's literally hours to seconds. If we deploy a tool and it's covered by Harmonic, we have insight right away."
Mercedes Cardona, Dark Reading · January 2026 · Read the full article →
Nineteen years in information security.
Senior Principal Information Security Architect (promoted)
· Serve as a trusted advisor to executive leadership and the CISO, translating strategic security objectives into enterprise architecture roadmaps, reference architectures, and measurable outcomes that strengthen cloud, AI, and data security programs.
· Architect secure public, private, and hybrid cloud environments across AWS and Azure, aligning enterprise solutions with Zero Trust principles, regulatory requirements, and risk management frameworks.
· Design and implement enterprise security architectures that protect cloud-native applications, SaaS platforms, data ecosystems, AI/ML workloads, and distributed infrastructure through scalable, resilient, and secure-by-design solutions.
· Lead enterprise security initiatives spanning architecture, engineering, cloud operations, and secure data lifecycle management, establishing consistent security standards and driving operational excellence across the organization.
· Deliver strategic consulting and technical leadership to executives, architects, engineers, and development teams on security architecture, technology strategy, control implementation, and modernization initiatives that enhance resilience and accelerate secure transformation.
Information Security Architect
Designed public, private, and hybrid cloud architecture; stood up log management infrastructure, an encryption key management platform, and the organization's initial secure access rollout.
Information Security Architect (promoted)
· Advised on security controls across network, endpoint, application, and cloud environments; consulted on security architecture and incident management.
· Collaborate with cross-functional IT teams to identify functional requirements and drive the implementation of security technologies that enable and enhance business operations.
Information Security Engineer
Defined security system requirements across cloud, datacenter, and branch office; served as in-house consultant between the security team and business units.
Network Security Engineer
Secured and monitored core network infrastructure and 600+ branch office sites. Ran the full network security monitoring lifecycle across enterprise firewalls, SIEM, IDS/IPS, PKI, and VPN systems.
Helpdesk Support
Monitored and maintained the Massachusetts Criminal Justice Information Network and CHSB's LAN, following 24x7 troubleshooting and escalation procedures.
Associate's Degree, Web Page, Digital/Multimedia & Information Resources Design
Current Microsoft, Cloud & AI credentials.
Azure Solutions Architect Expert · Issued Feb 2023 · Exp. Feb 2027
Microsoft Cybersecurity Architect Expert · Issued Jun 2022 · Exp. Jun 2027
Azure Security Engineer Associate · Issued Nov 2019 · Exp. Nov 2026
Azure Administrator Associate · Issued Jul 2021 · Exp. Jul 2027
Certificate of Cloud Security Knowledge · Cloud Security Alliance · Issued Aug 2017
Build a NLP Solution with Azure AI Language · Microsoft · Issued Oct 2024
Introduction to Model Context Protocol · Anthropic · Issued Jun 2026
Certificate of Completion · Anthropic · Issued Jun 2026
Let's talk security.
Open to conversations about cloud security architecture, identity modernization, and AI governance.
The fastest way to reach me is LinkedIn. For direct inquiries, use the email link below.