Technology executive (CIO/CISO) working in technology since 2011, from technician to the senior seat across healthcare and wholesale distribution. Owns strategy through hands-on delivery: EMR consolidations, network and security overhauls, HIPAA/NIST compliance programs, and a revived managed-services revenue line — while shipping production software solo through disciplined AI-assisted workflows.
Experience
Howland Pump & Supply Co., Inc.
Aug. 2025 – Present Chief Information Officer & Chief Information Security Officer
- Recruited by ownership as a change agent to modernize technology and operations for a 17-location, ~$75M wholesale plumbing, heating & pump distributor spanning New York & Vermont; own IT and security strategy end-to-end.
- Built the company's first governance, risk, and compliance (GRC) program — from no formal program to a CMMC Status of Final Level 1 (Self) in SPRS, now operationalizing NIST SP 800-171 controls toward Level 2 readiness and protecting eligibility for a $14.3M defense and government contract line.
- Identified the company's unaddressed PCI-DSS obligations and reduced compliance scope to SAQ B-IP by architecture: standalone payment terminals with no ERP interaction, and no cardholder data keyed into any other system.
- Segmented a flat network across 17 locations by device class: corporate, voice, printing, cameras, IoT, guest, and payment terminals each on their own VLAN with per-segment group policies. Held the site-to-site VPN to corporate and print traffic, so camera, IoT and payment devices have no path between branches.
- Introduced the company's first production use of artificial intelligence — automated vendor pricing updates — under an existing maker-checker approval framework extended to cover model output, so no AI-generated price takes effect without human approval.
- Regained administrative control of all critical technology platforms: Microsoft 365, Meraki SD-WAN across 17 branches, VoIP, and public DNS consolidated out of multiple registrars into Cloudflare. Stood up three segregated Global Administrator identities, eliminating key-person dependency and privileged daily-use access.
- Re-architected infrastructure management off Kaseya/Datto onto a self-managed toolchain (Action1, ScreenConnect, Icinga 2, Veeam, Synology, Cloudflare Tunnels). Cut recurring platform spend ~70% (~$37.6K to ~$11.4K annually) after a one-time $5.5K investment, trading a bundled suite for individually replaceable components.
- Replaced ~120 of 158 endpoints across all 17 branches in the first three months — an 8-to-10-year-old fleet with no Windows 11 upgrade path — at $550/desktop and $675/laptop negotiated with Dell, and established the company's first asset-replacement standard: five years for desktops, three for laptops and dust-exposed warehouse machines.
General Manager, C4 Technologies — Managed Services Division Aug. 2025 – Present
- Rebuilt the MSP practice into a managed-services division serving outside SMB and healthcare clients — tripling the client base from 12 to 37, 11 on managed Microsoft 365 tenants, and growing managed endpoints 3.5x, from 170 to 600+, within the first year; own P&L, pricing, strategy, business development, operations, and delivery end-to-end.
- Built a hosted UCaaS practice on a multi-company 3CX platform with redundant SIP carriers (Telnyx, Commio), scaling to 14 organizations and ~200 extensions; AWS primary with an on-site Debian failover node, cutover by DNS, failover tested quarterly.
- Standardized 100% of managed endpoints on RMM integrated into an in-house ITSM/PSA platform, and reached a ~50% attach rate across ~300 endpoints for Huntress Managed EDR and Managed SIEM — priced and sold as a single package, never one without the other.
River Hospital
Dec. 2020 – Aug. 2025 Chief Information Security Officer May 2024 – Aug. 2025
- Owned the organization's information and data security strategy — policies, programs, and procedures protecting PHI and digital assets; overhauled 30+ policies with KPIs measuring framework effectiveness, and validated recoverability through quarterly full restorations.
- Took independently assessed conformance from 0% fully conforming to 87% on the HIPAA Security Rule and 94% on NIST security controls over four annual assessment cycles; set the remediation standard at six weeks for critical and high findings, with exceptions formally documented against a compensating control.
- Drove vulnerability management to a 95%+ reduction in critical and high vulnerabilities leveraging NIST CSF, OpenSCAP, and Action1. Partnered with BlueOrange Compliance for annual security risk assessments.
- Reduced the internal attack surface — expanded segmentation from 3 VLANs to 25+, enforced host firewalls on all capable endpoints, and secured all privileged accounts with MFA (AuthLite), just-in-time access, and least-privilege gMSAs to limit lateral movement.
- Cut annual Microsoft licensing spend 16% ($28.4K to $23.9K) while upgrading 350 users from primarily Business Basic to Business Premium with EMS E5 through nonprofit pricing.
- Launched migration from Wazuh/Huntress to Microsoft Sentinel and negotiated a three-year StratusIP agreement for SilverSky MDR/SOC services, establishing a managed detection-and-response roadmap.
- Created and formalized vendor risk assessment, scored and tiered by data sensitivity, gated at contract and reviewed on a cadence. Required ISO 27001 over SOC 2 for financial-data vendors; rejected one whose attestation had no continuity plan behind it, the cash-flow risk outweighing the commercial case.
Director of Information Technology Jun. 2022 – Aug. 2025
- Directed a six-month consolidation of five legacy EMRs into MEDITECH Expanse with implementation partner CereCore — a 17% EMR cost reduction — aligning seven senior stakeholders (CNO, Medical Directors, Revenue Cycle) and standing up the EHR Governance Committee.
- Held primary responsibility for MIPS Promoting Interoperability — ran the Security Risk Analysis with BlueOrange Compliance, formed the group that completed the ONC SAFER Guides self-assessments, and filed the annual attestations.
- Designed and built behavioral health clinical documentation from the ground up as part of the EHR consolidation — authored the templates, workflows, and billing logic for one of the North Country's largest behavioral health programs, partnering with clinical leadership on clinical content.
- Called the move off Change Healthcare on day three, evaluated Waystar and Quadax, and negotiated a three-year contract cutting clearinghouse spend 72% ($10K to $2.8K monthly) with medical-necessity files bundled free — holding the billing outage on ~$25M of annual claims to about two weeks.
- Built the IT department from the ground up, insourcing the entire technology function from the larger organization that had previously supported it — service desk through clinical application support, plus IT management and line-item ownership of a $1M+ annual IT budget (excluding labor). Presented to the board of directors.
- Grew and personally trained that department to a peak of six over 18 months, spanning technical support, network administration, clinical applications, and data analytics; the department still runs on those hires.
- Migrated the analog phone system to VoIP and fax lines to WestFax eFaxing — cutting telephony spend 49% ($43.8K to $22.3K annually) while retaining four POTS lines as failover for an internet or cell outage.
- Established ITIL-aligned change management across ~400 workstations and servers: staged patch rings validated on redundant systems, bi-weekly windows for non-critical servers, monthly for uptime-critical, and a criteria-gated emergency path under two-person approval.
- Built the organization's security monitoring capability — Wazuh SIEM for long-term log retention with Health-ISAC threat intelligence, alongside Huntress MDR.
- Implemented a comprehensive legacy archival and downtime strategy (IPeople Offline Views) providing complete local access to patient records for long-term retention and clinical/financial downtime requirements.
- Eliminated single points of failure across the network core — a standalone firewall replaced with a redundant high-availability pair, HA core switching, and end-of-life hardware retired across ~40 switches — with infrastructure-as-code configuration driven from NetBox through Ansible rather than device-by-device CLI.
- Built every import for the hospital's Charge Description Master, the pricing and coding foundation of the revenue cycle.
IT Manager/Programmer Analyst Dec. 2020 – Jun. 2022
- Consolidated 89 facility data feeds — 31 HL7, 36 flat file, and 22 API including FHIR — into a single integration layer leveraging Mirth Connect.
- Migrated 40 virtual machines — including three EMRs — to a hyper-converged Hyper-V/StarWind VSAN environment over six months, cutting latency and hardening ACLs; moved the primary EMR (MEDITECH Magic) to CloudWave's OpSus cloud, with Azure carrying long-term backup retention and a cloud-hosted domain controller.
- Established data governance and BI from nothing — hundreds of SSRS reports and 20 operational, clinical, and financial dashboards on MEDITECH Business & Clinical Analytics, under a chartered committee.
- Built the majority of the billing and claim matrix — 100+ rule sets across the charge master and claims, including burst-charge logic — turning captured charges into submitted claims under Rural Health Clinic split-billing rules.
PCN Technologies
2011 – 2025 Principal — Healthcare IT Consulting
- Retained by Kaleida Health to rebuild its cost report data extraction — MEDITECH Data Repository SQL producing the charge, allowance, payment, and inpatient-day detail behind Worksheet S-10, DSH, and New York's Institutional Cost Report, across the system's Upper Allegheny facilities.
- Built a primary care practice's first clinical interface layer (2011) — HL7 feeds delivering inbound lab results and radiology reports from two separate regional hospital systems into the practice's EHR.
Claxton-Hepburn Medical Center
Apr. 2007 – Dec. 2020 Lead Programmer/Systems Analyst Aug. 2016 – Dec. 2020
- Implemented the payer transaction sets — 837 claims, 835 remittance, 270/271 real-time eligibility, and 278 prior authorization — through Change Healthcare.
Systems Analyst Apr. 2015 – Aug. 2016
- Ran the project portfolio for an 18-person IT team, including Masimo and Philips patient-monitoring implementations.
IT Technician Jul. 2013 – Apr. 2015
- Cut workstation deployment from days to hours with FOG imaging; achieved 100% endpoint inventory and patch-compliance visibility via PDQ.
Environmental Service Worker Apr. 2007 – Jul. 2013
SELECTED SOFTWARE PRODUCTS
Architected and shipped four production applications solo using a disciplined, multi-model AI-assisted workflow for architecture review, implementation, testing, and validation.
- Just the Facts:
Public, strictly neutral civic-data explorer for St. Lawrence County, NY — 82 municipal and school entities across 50+ finance, tax, enrollment, and staffing metrics; preserves source-verbatim values and derives all ratios at query time; Astro SSR on Cloudflare D1.
- FairwayBook (app.fairwaybook.com):
Golf tee-sheet management SaaS on Cloudflare Workers, D1, and Durable Objects; live in production at Partridge Run Golf Course, Canton, NY.
Skills & Technologies
- Leadership & Governance
- IT & security strategy; IT governance & policy development; board reporting; GRC program development; HIPAA, NIST CSF & NIST SP 800-171 / CMMC; budgeting, ROI & vendor management; digital transformation & change management; team building & development; data governance & business intelligence; incident response, disaster recovery & business continuity
- Technologies
- Microsoft 365; Entra ID; Azure; AWS; Microsoft Sentinel; Meraki; UniFi; Huntress Managed EDR; Huntress Managed ITDR; Microsoft Defender for Office; Wazuh; 3CX; MEDITECH Expanse; SQL/SSRS; Python; TypeScript / React; Cloudflare Workers; Action1; Veeam; ScreenConnect; Icinga 2; Synology; Cloudflare Tunnels
- Interests
- Linux & open-source software; home labbing; automation; camping
Education
SUNY Canton
2009 – 2013 Bachelor of Technology in Information Technology