Risk-based governance, compliance, and roadmapping for organizations building a security function that can prove it works.
A sample of recent engagements, not a full client list. Names withheld — happy to talk through any of these in detail on a call.
PCI-DSS compliance program for a regional nonprofit — cardholder data scope narrowed to keep the burden off their technology and business teams, with compliance achieved against the acquirer's requirements
FAIR-based security risk management program and roadmap for a large regional healthcare organization, integrated with their existing asset inventory and incident response systems
vCISO for a mid-sized investment firm — building the governance framework and lifecycle, driving third-party risk management, and maturing the program toward RIA compliance
CMMC program advisory for a defense industry startup — ensuring the compliance investment produces durable security value rather than an audit artifact
Strategic planning lifecycle for a regional nonprofit's technology organization — aligning quarterly prioritization, resource capacity, and measurable outcomes that surface in monthly business reviews
Most clients begin with an assessment and continue into program work. Scope is set in the first call.
Build your security roadmap from the ground up, using risk-based approaches to resource allocation. Together, we'll define the right scope and structure for your security function, ensuring decisions are grounded in business reality rather than checkbox compliance.
Navigate PCI-DSS compliance and other regulatory requirements with frameworks that guide rather than constrain. Implement NIST, ISO, and CIS standards, and create governance structures that let your team make smart, consistent security decisions.
Evaluate your current security maturity and develop practical improvement plans. Understand where you are, define where you need to be, and build sustainable programs that grow with you.
Stellaria Labs is an independent security consultancy working with executives and security leaders on governance, risk, and compliance. Engagements are hands-on: scoping, framework implementation, roadmap design, and the ongoing decisions in between.
The GRC discipline transfers beyond security. Risk-based prioritization, resource capacity, and measurable outcomes are the same machinery whether the subject is a controls program or a technology portfolio — which is why some engagements reach into strategic planning for technology organizations.
Remote-first, on-site for key meetings and strategic sessions. Based in West Lafayette, Indiana, working with clients across the United States.
I spent fifteen years building security programs inside Fortune 500 companies before starting Stellaria Labs. Most recently I served as Interim CISO at Nordstrom, leading a 100-plus person security organization and reporting to the Board of Directors on posture, maturity and strategic investment. Before that I built the company's GRC function from scratch — a thirty-person organization running PCI, SOX, SOC 2 and HIPAA certification on a single common control framework, alongside the enterprise risk methodology and third-party assurance programs. Earlier, at Microsoft, I owned security policy and risk management for the cloud infrastructure behind Microsoft's online services.
I started Stellaria Labs in 2026 to bring that experience to organizations building a security program for the first time — designing and standing up a program mature enough that their own team can run it once I step back.
A scoping call runs about thirty minutes: where you are, what's driving the timeline, and whether this is a fit.
I'm currently booked, with capacity opening in roughly two to four months. Scoping conversations typically happen well ahead of a start date, so if you're planning a program for later this year it's worth talking now.
Send a note with your timeline and current state, and I'll reply within one business day.
Email stellaria@stellaria.io