Bio
My Career
I’ve been doing this for a bit over two decades now. It started with an unhealthy interest in computers and *nix systems at Purdue (see the history degree for how that went) and turned into an actual career almost by accident: one tech-support job during my last semester, and one thing led to another.
Since then I’ve worked in small startups, one very large corporation, and growth-phase companies in between. I’ve done embedded systems, web applications, a state medicaid system, an encryption product, and now security compliance. The common thread is that I’ve had a seat in nearly every part of a technology company at some point (development, project management, operations, security), which mostly means I’ve collected a lot of examples of what makes projects succeed, and rather more examples of what makes them fail.
I hold the CISSP (Certified Information Systems Security Professional), PMP (Project Management Professional), and CSM (Certified ScrumMaster). The certificates are useful shorthand, but honestly the more valuable education came from the mistakes (mine and other people’s). My approach keeps changing because I keep learning, and one of my hobbies is just learning for the sake of it.
If you’re here to see whether we should work together, or just poking around: welcome. The projects section is the portfolio, the blog is where the stories go.
Experience
Founder, Principal Consultant
SC2 · Apr 2024 – Present
I started Star City Security Consulting to bring my knowledge and experience to the small and medium-sized businesses of Lafayette. I am responsible for everything as of this writing. Our chief aim is to provide data security guidance for where you are, what you want to do, and what you have on hand.
Compliance Manager
OnBoard · Aug 2018 – Present
I am currently working as a compliance manager at OnBoard taking our InfoSec compliance posture to the next level; maintaining compliance with SOC 2 Type 2, ISO 27001, ISO 27701, and emerging privacy regulations around the globe. I am leveraging prior technical experience for a holistic and knowledge-led approach to security compliance.
- Completed external audits of ISO 27001/27701 and SOC 2 Type 2 with zero non-conformities two years in a row
- Created GRC tracking and management solutions focused on objective risk assessment and greater non-compliance visibility
- Led business and product compliance efforts on AI, requiring rapid learning of LLMs and transformers, vendors, architecture approaches, public concern, and reinterpreting privacy regulations in light of how LLMs function.
- Instituted an organization-wide rollout of ISO 27701
Scrum Master
Arxan · May 2016 – Feb 2018
As a Scrum Master for our encryption product team, I was responsible for transitioning the team to more agile work methods, adapting to new standards and initiatives, identifying and mitigating risks, advocating for the team with internal management, and assisting the team in meeting feature goals and objectives.
- Guided team to more consistent agile development with 2 week sprints utilizing JIRA
- Assisted product owner in maintaining product and sprint backlog in accordance with product road-map
Technical Functional Area Lead
Hewlett Packard Enterprise · Feb 2008 – April 2016
While also being a developer, I was responsible for managing the prior authorization subsystem and Atlantes subsystem of the medicaid account. I was also responsible for the coordinated efforts of a small team of developers to maintain and build onto the eligibility system as well as communicating with account management regarding improvements, problem mitigation, and policy.
- Architected the flow of data along with interfaces and standards between subsystems
- Rearchitected full letter generation engine
- Rearchitected testing environment refresh process
- Worked with client to define business rules
- Performed project management duties on behalf of PMO for the prior authorization subsystem team
Education
Bachelor of Arts in History of Science and Technology
Purdue University · 2002 – 2006
My path through Purdue was a winding one, starting out in NROTC and Nuclear Engineering. The timing was not right for me, and I took a year of computer science in an attempt to transfer colleges. Long story short, I ended up in the History department with a minor in the history of science and technology.
Extracurricular Activities:
- NROTC
- Pre-law Society
- Japanese Club
- Purdue Anime Club
Certifications
Click through for the Credly verifications.
Contact
If you have any questions or would like to work together, please feel free to reach out to me at [email protected]. For sensitive requests, my GPG key fingerprint is E48B 9BA1 3823 B0D8 D065 C110 7467 B453 13F5 5526
Some Frequently Asked Questions
What’s with the name “Tsunami.No.Ai”?
In high-school (c. 2000) I was big into this new thing I’d been exposed to called “anime.” Around the time our family got our first hosted domain with our ISP, I got to choose a subdomain for myself. Having just watched the original Tenchi Muyo OVA, I wanted “tsunami” in the name. It was taken, of course, so being a romantic, I added “noai” to the end. It was a play on words, “tsunami no ai” meaning (incorrectly) “tsunami of love” in Japanese. I was a teenager, what can I say? Not too long after, I found out that the correct phrase would be “ai no tsunami” and that “tsunami no ai” would mean “love of tsunamis.” It must have been a sign of not wanting to fool with DNS records that I kept it ever since.
What’s up with that Profile Picture?
It’s Cirno.
A History Degree?
Yes, a history degree.

