Testimonials

  • I received great tips and tricks to maximize my resume and job hunting. Very helpful, I learned so much in such a short period! I am glad I reached out for assistance.
    Christopher Whitlock
  • Extremely helpful and knowledgeable! Sal gave me invaluable advice and helped me develop a roadmap to help me get where I want to be and where I should put my time. I am glad I got a meeting!
    Christopher Whitlock
  • Sallie is a well-spoken leader. She possesses a charismatic energy that has you hanging off of every word. She provided me with the guidance I needed to build my brand and encouraged me to conduct myself as a vCISO, and I will be treated as one. I can’t wait to book my next call.
    Jennifer Smith

Services

Ratings and feedback

5/5
3 ratings
3
Testimonials

About me

Hi! I'm Sal, As a cyber security professional, I prioritize making data driven decisions to reduce enterprise security risks and increase product security assurance. One of my primary areas of expertise lies in the Secure Development Lifecycle (SDL). Within this framework, my focus revolves around establishing baseline metrics that effectively mitigate risk, enhance security assurance, and ensure compliance with regulatory requirements. I'm a Certified Information Systems Security Professional #CISSP and a Certified Secure Software Lifecycle Professional #CSSLP, both of which demonstrate my expertise in product security. I possess an infectious growth mindset and prioritize amplifying the value developers and technologists bring to the secure product development lifecycle. I have experience in compliance, business continuity, IT security program development, Security Education, Training, and Awareness (SETA) program development, and program management. I have served in technical education roles for industry leaders, such as ISC2 as a CISSP exam question writer and SANS Institute as a facilitator. My extensive background in information security, consulting, audit experience, and business degree with a concentration in finance makes me an ideal candidate for understanding and assessing risk, defining and tracking relevant metrics, and developing strategic security programs. When I'm not working, I enjoy spending time with family and friends, reading, oil painting, restoring mid century modern furniture, and listening to audiobooks. CYBERSECURITY DOMAINS - Information Security - Incident Response - Table Top Exercises - Threat Modeling - Secure Software Development Lifecycle - Product Security - PSIRT - SSDL Requirements Writing - Risk Assessments - Gap Assessment - Report Writing - Project Management - Product Management - Program Management - Policy, Procedures - Security Training, Awareness, & Education TECHNICAL SKILL - SQL - Linux - GitHub - Python - PostgreSQL - Data Analysis - Database Queries - Data Visualization - Dashboards - Reports - Spreadsheets - Confluence - JIRA - ServiceNow - Advanced Excel FRAMEWORKS and REGULATIONS - NIST 800-53, 171, + - ISO 27001 - 02 - PCI DSS - HIPAA - GDPR - Agile - CVSS CERTIFICATION - CISSP - CSSLP - GISP - PCI QSA (inactive) - PCIP