
I started Antares Security after spending years working inside organizations where security problems were rarely as simple as the technology suggested. The difficult part was often figuring out what actually mattered, who needed to be involved, what the organization was prepared to do, and how to turn all of that into something people could act on.
Over time, I kept seeing the same gap from different angles. Organizations could have capable people, good technology, and plenty of security activity, yet still struggle to turn all of it into a coherent program. That experience is what led me to start Antares.
How the practice operates.
Antares is deliberately small and senior. Engagements are led directly, recommendations are independent of technology vendors, and the work stays focused on decisions, ownership, and outcomes.
Independent
Advice is based on what the organization actually needs, not a technology platform or vendor relationship.
Senior
Engagements are led directly, without layers of junior staffing.
Accountable
Recommendations are tied to decisions, ownership, and what happens next.
Direct
I’ll tell you what I see, what I don’t know, and where the organization needs to focus.
Experience, applied.
My career has taken me through security, risk, governance, and program development across financial services, healthcare, technology, professional services, and the public sector. I've worked on security assessments, third-party risk, compliance, incident response, governance, and security leadership.
The work has changed over the years, and so have the environments I've worked in. What has remained consistent is being close to the problem: understanding what is happening, figuring out what matters, and helping the people responsible for the outcome decide what to do next.
I've seen the same thing in different forms over and over: the hardest security problems are usually not purely technical. They're questions of judgment, priorities, ownership, incomplete information, and sometimes competing ideas about what should happen next.
A framework can provide structure. Technology can provide capability. Neither one removes the need to understand the situation and make a decision. That is usually where the real work begins.
I prefer to work close to the people responsible for the outcome. That means understanding the situation before prescribing an answer, bringing the right people into the conversation, working through the uncertainty, and being clear about what needs to happen next.
The goal is something practical: a security program people understand, decisions they can explain, and work that can actually be operated once the engagement is over.
The work behind the practice.
- Education & practice base
- I hold a degree in Information Assurance and Security Engineering from DePaul University and operate Antares from Chicago, Illinois. My work is grounded in security practice rather than a single technology, framework, or industry, with an emphasis on understanding how security actually works inside an organization.
- Operational & governance experience
- My career spans security, risk, and governance leadership across regulated and enterprise environments, including financial services work at Northern Trust focused on operational risk, third-party risk, and enterprise risk governance; advisory and assurance engagements at Baker Tilly; and information and operational security roles at Wolters Kluwer.
- Enterprise & public-sector program work
- I have also supported security program development across complex operational environments, including enterprise security initiatives at Cushman & Wakefield, public sector program work with the City of Chicago in collaboration with Unisys, and regulated healthcare and research environments through University of Chicago Medicine and Biosciences.
- Federal-aligned & program leadership experience
- My additional experience includes federal compliance–aligned security work through Easterseals under a VA-funded grant program, as well as security operations and program development at Verisys, where my role evolved into Head of Security / CISO-level responsibility following my tenure.
- Practice area
- Cybersecurity advisory
- Practice area
- Risk & assessment
- Practice area
- Compliance & governance
Start with the decision the program needs to support.
A direct conversation about your operating context, current risk posture, and the decisions forcing the work. No sales process.