The
Playbook
All good things
start with an offer.
Here is mine. It is priced below your floor, bounded by a term, and built so that the only person carrying risk past month six is me.
The terms
- You pay 10% under your own floor for twelve months, in exchange for a candidate without hyperscale data center experience. The discount is priced to exactly the gap you identified.
- You carry no downside risk past month six. The off-ramp is yours alone to exercise, on evidence I defined in advance and cannot move later.
- I carry the burden of proof. Every commitment produces an artifact you can hold, or it does not count. “Improved posture” is not a deliverable. A signed post order is.
- I fund my own gap closure. Four of six items out of my pocket, an estimated $5,500 to $16,000. With the salary discount, that is $26,500 to $37,000 of my own money behind the claim.
- Equity on your standard terms. No premium sought anywhere else.
- No competing commitments. I am closing my construction business on completion of my current build. It does not come with me.
- Or make it interim. Run me until you find the right person. I am not precious about the title — I am confident you already found the right person, you just do not know it yet.
The ten commitments
| # | Commitment | How you verify it | By |
|---|---|---|---|
| 01 | Baseline physical security assessment complete at every site in the region, findings ranked by risk and consequence, with a costed remediation plan | The document, in your hands | Day 90 |
| 02 | Post orders written to the threat and in force at every site, signed by site leadership | Signed post orders on file, per site | Day 90 |
| 03 | 100% access control entitlement audit — every credential mapped to a named owner, an approval record and a current justification; every orphan closed | Audit record, with the count of credentials closed | Day 90 |
| 04 | One regional SOP set in force: access management, visitor and vendor control, incident response, guard post standards | The SOP set, adopted | Day 180 |
| 05 | Guard vendor performance framework live — measurable post standards, QA at a published cadence, monthly scorecard | Three consecutive months of scorecards | Day 180 |
| 06 | Every critical finding from the Day 90 baseline either closed, or funded-and-scheduled with an interim mitigation in force | The baseline document, line by line | Day 180 |
| 07 | Incident response tabletop run at every site, with documented after-action | After-action reports, one per site | Day 180 |
| 08 | My operational deficiencies closed — hyperscale immersion documented, enterprise ACS/VMS certification held, NIST control mapping delivered, PIDS commissioning participated in, joint physical/cyber tabletop run | Certificates and artifacts, five items | Day 180 |
| 09 | Customer-facing security package ready: audit-ready documentation, evidence artifacts, standard site tour | You put a real customer through it | Day 270 |
| 10 | Regional metrics published monthly from month one: incidents, response times, access anomalies, post compliance, open findings, by site | Twelve consecutive months of published metrics | Monthly |
How the year is shaped
Phase I, Day 1–90 — Establish. Find out what is actually true at every site, write it down, and price the fix.
Phase II, Day 91–180 — Standardize. One region, one standard. And every operational gap I have is closed and evidenced by the end of it.
Phase III, Day 181–270 — Prove. Put the program in front of a real customer and let it be tested by someone who is not me.
Phase IV, Day 271–365 — Institutionalize. Make it survive me.
Establish
the baseline.
You cannot standardize a region you have not walked. The first ninety days are spent finding out what is actually true at every site, writing it down in a form you can act on, and putting a price on the fix. Nothing in this phase is assessed from a desk.
What I do
- Walk every site in the region, including nights and weekends. The posture you have at 2 a.m. on a Sunday is your real posture, and it is never the one in the daytime briefing.
- Map what is not mapped. At Snowmass I hand-drew a property that had no maps and then digitized it, because you cannot reference a door that has no name. I would do the same here for anything missing.
- Meet the site personnel and the contract guard force on their post, on their shift — not in a conference room.
- Sit with site operations, facilities and the build teams. Ask what security does that gets in their way, and write the answers down.
- Run a single physical security assessment methodology at every site so the results are comparable. Deter, detect, delay, respond — with delay budgeted explicitly against real response time.
- Rank every finding by risk and consequence rather than by which site complains loudest.
- Verify devices against design intent, not against an install checklist. A camera that is online is not a camera that covers what the drawing said it would cover.
- Run a 100% access control entitlement audit: every credential mapped to a named owner, an approval record and a current business justification. Close every orphan. This audit finds something in every environment it has ever been run in.
- Post orders written to the threat at each site — not inherited from the last contract — and signed by site leadership. A guard force that cannot tell you why a post exists will not hold it at 3 a.m.
- A costed remediation plan in your hands: every finding, what it costs to fix, and what it costs not to.
- The first monthly regional metric publication goes out at Day 30, with whatever is knowable then. The baseline starts on day one or it never exists at all.
What closes in this phase
| Commitment | Artifact you receive | By |
|---|---|---|
| 01 — Baseline assessment at every site | The document, ranked and costed | Day 90 |
| 02 — Post orders in force | Signed post orders, per site | Day 90 |
| 03 — 100% entitlement audit | Audit record with orphans closed | Day 90 |
| 10 — Regional metrics | First issue published | Day 30, then monthly |
D1 — hyperscale immersion begins in week one. I shadow the build and critical facilities teams at every site and document the power, cooling and hall architecture myself rather than being briefed on it. By Day 90 I can read your estate; by Day 180 it is documented and evidenced.
D2 — enterprise ACS/VMS. I find out which platform is actually in your estate and enrol in vendor-led administrator training on it. Console-level, not overview-level, at my cost.
Why this order
Every instinct in a new job says to start fixing things. That is the wrong move in a region, because the fixes you can see in week one are the ones the site already knows about — they are visible precisely because somebody already flagged them.
The findings that matter are the ones nobody has looked for. Those only surface from a methodology applied uniformly, at every site, by someone who does not yet have a reason to look away from any of them. That window closes about ninety days in, and it does not reopen.
Standardize
the region.
One region, one standard, with site-specific annexes rather than site-specific reinventions. This is also the phase where every operational deficiency I have is closed and evidenced — because month six is your off-ramp, and I am not going to arrive at it still owing you something.
What I do
- Access management, visitor and vendor control, incident response, guard post standards — written once for the region, annexed per site.
- A RACI across the regional security tasks, so no responsibility lives in the gap between two people who each assumed the other had it. I run about forty of these at my current property.
- Vendor staging and dock-only routing written as standard, so contractor access is a defined path rather than a courtesy.
- Measurable post standards, QA inspections at a published cadence, and a monthly vendor scorecard reviewed face to face.
- I write that scorecard as someone who spent ten years as the vendor being inspected. I know which metrics a guard vendor can quietly game and which ones they cannot.
- Guard performance becomes a number you see before it becomes an incident you have to explain to a customer.
- One incident response process across the region, tested by tabletop at every site, with a documented after-action for each. A process that has never been run is a document, not a capability.
- I write, host and present these myself — I already do it for executive leadership and an emergency response team at my current property.
- One of those exercises is a joint physical/cyber tabletop with your security engineering team. I own the physical leg and I am the junior voice on the logical side until I have earned otherwise.
- Every critical finding from the Day 90 assessment either closed, or funded-and-scheduled with an interim mitigation in force and written down.
- Nothing sits open and unexplained. If it is not fixed, you know why, what it costs, and what is holding the line in the meantime.
What closes in this phase
| Item | What it is | Verified by | By |
|---|---|---|---|
| C-04 | One regional SOP set in force | The SOP set, adopted | Day 180 |
| C-05 | Guard vendor performance framework live | Three consecutive monthly scorecards | Day 180 |
| C-06 | Every critical Day 90 finding closed or funded-and-mitigated | The baseline document, line by line | Day 180 |
| C-07 | Incident response tabletop at every site | After-action reports, one per site | Day 180 |
| C-08 | My operational deficiencies closed | Certificates and artifacts, five items | Day 180 |
| D-1 | Hyperscale immersion — power, cooling and hall architecture at every site, documented by me | The document | Day 180 |
| D-2 | Enterprise ACS/VMS administrator certification on the platform in your estate, console-level. My cost: $0–4,000 | The certificate | Day 180 |
| D-3 | Regional physical control set mapped to the relevant NIST control families | The mapping | Day 180 |
| D-5 | Perimeter intrusion detection commissioned at device level against design intent | Commissioning record | Day 180 |
| D-6 | Joint physical/cyber tabletop built and run with your security engineering team | After-action report | Day 180 |
The checkpoint
At the end of this phase you hold a unilateral off-ramp. If commitments 01 through 08 are not delivered and verifiable against the artifacts named above, you end it. No severance, no notice period, no argument.
I have deliberately front-loaded the hardest work and all of my own gap closure into the first six months, so that the decision you make at that checkpoint is made on evidence rather than on optimism.
Prove it to
somebody who
isn’t me.
A security program that has only ever been graded by the person who built it has not been graded. This phase puts the region in front of a real enterprise customer and lets it be tested.
What I do
- Audit-ready documentation: the control set, the evidence behind each control, and the artifacts that prove it operating rather than existing.
- A standard site tour — the same at every site in the region, so a customer visiting two sites sees one company.
- When a customer asks how you control access to the hall their weights are training in, the answer is already written, already evidenced, and identical everywhere.
- Not a rehearsal. A real customer, a real visit or audit cycle, with me as the accountable name on the physical security evidence package end to end.
- This is the part of the job I have done longest under real consequence. At my current property the department is measured against three concurrent audit regimes — brand standard, ownership, and Marriott corporate — each with its own control set. Before that, federal facility security standards across four VA hospital sites.
- Whatever the customer finds goes into the same ranked, costed format as the Day 90 baseline, and gets closed or funded on the same discipline.
- An audit finding you argue with is a finding you will see again.
What closes in this phase
| Item | What it is | Verified by | By |
|---|---|---|---|
| C-09 | Customer-facing security package: audit-ready documentation, evidence artifacts, standard site tour | You put a real customer through it | Day 270 |
| D-3 | Implementer-level information security management training, plus ownership of one real customer audit evidence package end to end. My cost: $1,500–3,500 | Certificate and the audit record | Day 270 |
| D-1 | A recognised data centre infrastructure or tier design credential, or a demonstrable equivalent. My cost: $3,000–7,000 | The credential | Day 270 |
A year of deliberate work does not make me equivalent to someone who has run hyperscale physical security for a decade, and anyone who tells you otherwise is selling. What it does is make the gap documented, dated and closed against evidence you can inspect — so it stops being a reason to worry about me.
Make it
survive me.
A program that depends on the person who built it is a liability, not an asset. The last quarter is about making the standard hold whether or not I am the one enforcing it — and about the one credential I deliberately left until last.
What I do
- Twelve consecutive months of published regional metrics — incidents, response times, access anomalies, post compliance, open findings, by site. A region that cannot be read cannot be managed.
- The annual entitlement review scheduled and running on its own cadence, not because I remembered.
- Audit cadence set and calendared. QA inspections happening on a published schedule that does not depend on my attention.
- Every new site brought online in the region enters operations with security integrated from the construction phase — nothing retrofitted — verified by a turnover checklist per activation.
- This is the part I am most confident about. I own a construction company, I hold an ICC Plans Examiner certification, and I currently run the security profile of a live eighteen-month, nine-figure renovation with hundreds of vendors credentialed daily inside an operating property.
- The cheapest security fix available at any site is a redline before pour.
- Develop site-level leadership to the point where a site runs its standard without me on it. I am deliberately not making this a numbered commitment — it depends on who you hire, and I will not ask you to score me on someone else's appointment. But it is the work, and you will see it or you will not.
- ASIS CPP board exam, sat inside the contract year. Deliberately last: I am not going to miss nine dated operational commitments while studying for an exam. PSP to follow, after the term.
What closes in this phase
| Item | What it is | Verified by | By |
|---|---|---|---|
| C-10 | Regional metrics published monthly from month one | Twelve consecutive months, published | Day 365 |
| D-4 | ASIS CPP board exam, sat inside the contract year. My cost: $1,000–1,500 | The result | Day 365 |
What you are
actually buying.
Not a hire. A regional security program that exists, is documented, has been tested by somebody outside the company, and can be read from a dashboard — plus a person who is no longer the candidate you turned down.
The operation
- One SOP set in force across the cluster — access management, visitor and vendor control, incident response, guard post standards — with site-specific annexes rather than site-specific inventions.
- Post orders at every site, written to the threat, signed, and audited against.
- A guard force measured monthly against a scorecard the vendor cannot game, with QA inspections on a published cadence.
- Every badge in the region maps to a named owner, an approval record and a current business justification.
- Least-privilege provisioning with written approval for restricted areas, two-person authorization to issue, immediate deactivation on separation, and an annual entitlement review running on its own schedule.
- One incident response process across the region, run at every site, with after-action reports on file.
- At least one joint physical/cyber exercise completed with security engineering.
- Twelve consecutive months of published metrics: incidents, response times, access anomalies, post compliance, open findings, by site. A baseline that did not exist before, and now cannot be argued with.
- If a site is drifting, you do not need me to tell you. You can read it.
- An audit-ready documentation and evidence package that a real enterprise customer has been through — not a rehearsal.
- A standard site tour, identical everywhere, so a customer visiting two sites sees one company.
- Every site activated during the year entered operations with security integrated from the construction phase, verified by a turnover checklist. Nothing retrofitted.
- Security enters at the drawing set, which is the only place it is cheap.
Who is at the helm
The same person, with the gap closed. Everything I brought on day one is still there — seventeen and a half years across law enforcement, federal-standard contract security, multi-site portfolios, construction ownership, and a live nine-figure build. What is added is the part you were right to worry about.
| What I lacked on day one | Status at Day 365 |
|---|---|
| Hyperscale / data center security experience | Documented immersion across every site in the region, written by me, plus a recognised infrastructure credential |
| Hands-on enterprise ACS/VMS | Administrator-certified on the platform in your estate |
| SOC 2 / ISO 27001 / NIST cycle owned | Implementer-trained, NIST control mapping delivered, one real customer audit cycle owned end to end |
| PIDS commissioning | Commissioned at device level against design intent |
| Joint physical/cyber incident response | Built and ran the physical leg of a joint exercise with your security engineering team |
| ASIS board certification | CPP |
What my résumé says in August 2027
This is the entry I intend to have earned. I am printing it now so that in twelve months you can hold it against what actually happened.
Own physical security across every site in a Fluidstack region — the infrastructure delivering frontier AI compute at gigawatt scale. Built the regional program from a standing start.
- Delivered a ranked, costed physical security baseline at every site in the region inside 90 days, and closed or funded every critical finding inside 180.
- Wrote and put in force post orders at every site, written to the threat and signed by site leadership.
- Ran a 100% access-control entitlement audit across the region; every credential mapped to a named owner, an approval record and a current justification, every orphan closed.
- Standardized SOPs, access management, visitor and vendor control, and incident response across the cluster with site-specific annexes.
- Built and ran a guard vendor performance framework: measurable post standards, QA at published cadence, monthly scorecards.
- Tested incident response by tabletop at every site with documented after-action, including a joint physical/cyber exercise with security engineering.
- Carried an enterprise customer through a security audit cycle as the accountable owner of the physical evidence package.
- Published the region's first monthly security metric set — incidents, response times, access anomalies, post compliance, open findings — for twelve consecutive months.
- Integrated security into site activation from the construction phase forward; no retrofits.
Credentials added in role: ASIS CPP · ISO 27001 implementer · enterprise ACS/VMS administrator · data centre infrastructure credential · perimeter intrusion detection commissioning
And if it does not go that way — if I miss, you exercised the off-ramp at month six and it cost you a discounted salary and nothing else. No severance, no notice, no argument. That is written into the offer and it is yours alone to trigger.
You still keep the baseline assessment, the post orders, the entitlement audit and the remediation plan, because those are delivered by Day 90. Even the failure case leaves your region better documented than it is today.
Your five scope bullets.
What I have already run,
and exactly what I would do.
No fluff, just facts. Each block below quotes one line of your role scope, states what I have already been accountable for against it, and then states specifically what I would do in your region — with a date attached wherever a date is possible.
Scope, line by line
Own physical security operations across a Fluidstack region: every site, every shift, accountable end-to-end for posture, performance, and incidents.
I have held end-to-end posture across a footprint I could not see from where I stood, four times
- Four-site VA hospital contract portfolio at federal facility security standards, built from a standing start as the first hire, 2014–2016
- Up to fifty officers deployed nightly across 10–15 properties, 2010–2020
- 600 acres, 1,000+ rooms, 22 departments, a $8.5M operating budget plus capital submissions and 34 officers today — every shift, every day, including the ones I am not there for
- A property I had never walked, stabilized on a corporate task force in under three weeks — I mapped it, named every door, built a grand master key program and wrote ~20 SOPs, and was offered the permanent Director role
- Full detail on Sheet 14
A single physical security assessment methodology run at every site in the cluster, findings ranked by risk and consequence rather than by which site complains loudest, with a costed remediation plan in your hands by Day 90.
Then a published monthly regional metric set — incidents, response times, access anomalies, post compliance, open findings, by site. If a site is drifting you should not need me to tell you. You should be able to read it.
Lead the regional security team, including site-level personnel and contract guard force, setting the standard for discipline and execution at every facility.
I have led employed teams, managed contract forces, and been the contract force
- 34 officers on staff across three shifts today — supervisors, officers, an EMT, an investigator, admin
- Contract guard force across four VA hospital sites, held to a federal standard — I was the first hire and built the program
- Ten years as the vendor being inspected — I know which metrics a guard vendor can quietly game
- Full detail on Sheet 09
Post orders written to the threat — not inherited from the last contract — in force and signed by site leadership at every site by Day 90.
A guard vendor performance framework live by Day 180: measurable post standards, QA inspections at a published cadence, and a monthly scorecard reviewed with the vendor. Guard performance should be a number you see before it becomes an incident you explain to a customer.
Serve as the senior security presence for customer commitments in the region: audits, site visits, contractual obligations, and the relationships behind them.
I have been the accountable name on audits where failing had a commercial consequence
- Three concurrent audit regimes at the JW Marriott — brand standard, ownership and Marriott corporate, each with its own control set. 100% compliance on the most recent brand standard audit
- Federal facility security standards across four VA hospital sites, where passing was the commercial condition of the contract
- Thirteen proposals presented to leadership, eleven approved and funded, each with ROI and risk analysis — security arguments built to survive scrutiny from people who do not work in security
- Full detail on Sheet 11
A customer-facing security package ready by Day 270: audit-ready documentation, evidence artifacts, and a standard site tour. When a customer asks how you control access to the hall their weights are training in, the answer should already be written, already be evidenced, and be identical at every site in the region.
I will say plainly what I have not done: I have never carried a customer through SOC 2 Type II or ISO 27001. My plan and date for closing that is on Sheet 14.
Standardize post orders, SOPs, access management, and incident response across the cluster while tailoring execution to each site.
27 SOPs, ~95 documented processes, ~40 RACI tasks — and a three-week read of a site I had never seen
- Rewrote the SOP estate at the JW Marriott from institutional memory into 27 standing procedures covering ~95 documented processes
- Built a RACI matrix across ~40 tasks so no responsibility lives in the gap between two people who each assumed the other had it
- Wrote the occupancy-based deployment model as a standard, not a judgment call — six posts at or below 60% occupancy, ten at 100%, six manned 24/7/365 as a floor the model may not breach
- Full detail on Sheet 11
One regional SOP set in force by Day 180 — access management, visitor and vendor control, incident response, guard post standards — with site-specific annexes rather than site-specific reinventions.
Incident response tabletopped at every site in the region by Day 180, with a documented after-action for each. A process that has never been run is a document, not a capability.
Partner with site operations, facilities, construction, and vendors to integrate security into every phase of the region’s growth.
This is the strongest argument I have, and it is the one that does not appear on other résumés
- Owner of a construction company scaled from solo operator to $2M+ annual revenue, residential and commercial
- ICC Plans Examiner — I review construction documents for code compliance as a discipline, not as a favor
- I currently own the entire security profile of a live 18-month, nine-figure renovation: vendor and contractor credentialing at a rate of hundreds daily, site safety and compliance reviews, coordination of planned utility shutoffs each evaluated against safety and security risk, and a standing weekly working cadence with site operations and the renovation vendors — inside a resort still operating at occupancy
- Full detail on Sheet 13
Every new site brought online in the region enters operations with security integrated from the construction phase — nothing retrofitted. Verified by a turnover checklist per site activation.
You are deploying gigawatts in months, not years. Security at a Fluidstack site is therefore not an operations problem that begins at handover; it is a deployment problem that begins in the drawing set and peaks during construction, when the site is valuable, crowded with trades, and not yet controlled. There are many security leaders who can run a finished site. There are very few who have been the general contractor on one.
I have never owned one site.
I have owned portfolios.
Four times in seventeen years I have been handed responsibility for security across a set of places at once — a four-site federal hospital contract I built from nothing, a nightly patrol operation across a dozen properties, a 600-acre resort complex, and a mountain resort I had never seen until the day I ran it. The common thread is not the industry. It is accountability that does not stop at a property line.
The requirement
You’ve owned physical security across multiple sites or a region, accountable for posture and incidents end to end.
The record
Four VA hospital sites, built from the ground up. I was the first hire.
My first regional portfolio was healthcare for veterans — a contract guard force across four Department of Veterans Affairs hospital sites in Texas, held to federal facility security standards rather than to a client’s preference.
I did not inherit this program. I was the first hire on the contract and I built it. I wrote the post orders, hired and onboarded every officer who came after me, stood up the quality assurance program, and owned the client relationship across all four sites simultaneously.
For accuracy: I left before the contract came up for renewal, so I make no claim about how it was ultimately renewed.
- Built a four-site federal contract program from a standing start as employee number one
- Wrote and enforced post orders per site against a common contract standard
- Ran QA inspections and corrected officer performance across locations
- Learned the discipline that a federal standard is a floor, not a target
Up to fifty officers deployed nightly across ten to fifteen properties
For a decade, concurrent with my police service, I ran an armed patrol operation providing deterrence and response to San Antonio–area properties. Every officer was a commissioned SAPD peace officer working an off-duty detail, engaged as an independent contractor. I personally handled contract negotiation, scheduling, post assignment, and payroll submission.
This matters for one specific reason: I have sat on both sides of a guard services contract. I know what a vendor does when a client stops inspecting.
One security department across a 600-acre complex that behaves like several sites
The resort is not a building. It is 600 acres carrying a 1,000+ room hotel, a convention center, a water park, two golf courses, and retail — each with its own access profile, its own population, and its own failure modes. Twenty-two departments operate on that footprint. I own one of them, and my department’s posture covers all of it.
I carry an $8.5M operating budget across that footprint — plus capital expenditure submissions and a discretionary spending account for larger purchases — and staff it against demand that swings with occupancy rather than against a flat headcount.
Dropped into an unfamiliar property on a corporate task force. Under three weeks to fix it.
Marriott selected me for a national interim executive task force and sent me to a property I had never walked, with a team I had never met, to stabilize a security operation across a resort that included an employee housing complex. I had under three weeks.
This is the closest analogue in my record to what a regional lead actually does: arrive at a site you did not build, read it fast, find what is actually broken, and fix it before you leave.
- The property had no maps. I hand-drew the property, then digitized it, so that access points and posts could be named and referenced at all
- Created a door naming convention — my own system — so every opening had a unique, logical identifier that an officer, a technician and an audit could all use
- Built a grand master key program from scratch, with the hierarchy documented
- Ran a property-wide re-key and a full lock and access-control audit, correcting Visionline/VingCard configuration errors I found during it
- Wrote approximately 20 SOPs and supporting processes for a property that had none
- Rebuilt the Lost & Found from the ground up
- Snowmass offered me the permanent Director role at the end of the assignment.
What this does not cover
I have never held a portfolio of hyperscale data centers. My largest single footprint is 600 acres of resort; my largest true multi-site portfolio is four VA hospital sites, an order of magnitude below a gigawatt-scale region in consequence.
What I am claiming is the shape of the job — distributed accountability, posture I cannot see from where I stand, and incidents I own whether or not I was on site. Not the wattage.
Applied to a Fluidstack region
A region is not a set of sites, it is one posture expressed in several places. The first thing I would build is a common baseline — a single physical security assessment methodology run at every site in the cluster, findings ranked by risk and consequence rather than by how loud the site is about them, and a costed remediation plan I would hand you inside ninety days.
The second thing I would build is the thing that keeps a region honest: a published monthly metric set. Incidents, response times, access anomalies, post compliance, open findings, by site. If a site is drifting, you should not need me to tell you. You should be able to read it.
And I would do at every site what I did at Snowmass in under three weeks: walk it, map it, name every opening, and find out what is actually true rather than what the documentation says.
A guard force is a promise
somebody has to keep at 3 a.m.
I have run officers as an employer, as a contract manager, and as the vendor being inspected. Ten of those years I was the company a client could have fired. That is the perspective I bring to holding a contract guard force to a standard — I know exactly where the slack hides, because I have been the one responsible for not letting it.
The requirement
You lead security teams and contract guard forces, setting and holding a high bar for discipline and professionalism.
The team I run today
Thirty-four people, six posts that never go dark, and a staffing model tied to demand
My department is thirty-four people across day, afternoon, and night shifts — supervisors, officers, an EMT, an investigator, and administrative support. Six positions are staffed 24/7/365 as the floor. That floor is not a budget number, it is a risk decision, and it does not move.
Above the floor, deployment scales with occupancy: six posts at 60% occupancy or below, ten at 100%. Third-party vendors carry group security demand so that Marriott employees stay on the hotel operation. I am budgeted for 24.5 FTE against an operational demand of 31.1. Managing that delta honestly — in writing, with the risk stated — is a large part of the job.
I was the first hire. I built the force I then managed.
A contract force is harder than an employed one. You are holding a bar for people whose paycheck you do not sign, inside a client’s building, against a scope somebody negotiated before you arrived.
At the VA contract I did not inherit that problem — I created the program that solved it. As employee number one across four hospital sites, I wrote the post orders, hired and onboarded the officers, and stood up the QA program, all to federal facility security standards.
Ten years on the other side of the clipboard
I was the vendor. Up to fifty commissioned peace officers deployed nightly across ten to fifteen properties, drawn from a callable bench of about two hundred, all engaged as independent contractors on off-duty details. I negotiated the contracts, built the schedules, assigned the posts, and submitted the payroll myself.
So when I write a guard vendor scorecard, I am writing it as someone who knows which metrics a vendor can quietly game and which ones they cannot.
How I hold the bar
Discipline is a system, not a speech
- Written post standards. 27 SOPs and roughly 95 documented processes, so “the bar” is a document an officer can be held to rather than a supervisor’s mood.
- A RACI matrix across ~40 tasks, so no responsibility lives in the gap between two people who each assumed the other had it.
- The “5/15” Base Officer visibility program — a deliberate standard for guest and employee contact that converts a static post into presence.
- A tiered Emergency Response Team notification plan I built for incident response, so escalation is defined by severity rather than by whoever happens to pick up.
- The Be Safe Committee, which I chair. The concept existed before me and had lapsed — nobody was running it. I revamped it and restarted it, cross-departmental, so safety findings come from the 22 departments who actually see them rather than only from my officers.
- A hazard identification and safe-work-practice recognition tool I developed, so good practice gets caught and named, not just failures.
Thirteen proposals to leadership. Eleven approved and funded.
Holding a standard costs money, and money means persuading people who do not work in security. I have built and presented thirteen proposals to leadership, of which eleven have been approved and funded — each with ROI and risk analysis attached.
Those include the armed-officer business case and a FY2027 capital proposal for perimeter intrusion detection. An 85% funding rate is not luck; it is what happens when a security argument is built to survive a finance conversation.
Independent read
What this does not cover
I have not managed a guard contract at hyperscale, multi-region scale. My largest contract force is four VA hospital sites; my largest employed team is thirty-four.
If your regional guard spend is an order of magnitude above that, what transfers is the method — written post standards, documented QA at a fixed cadence, a vendor scorecard the vendor cannot game, and a willingness to put a performance failure in writing. Not the headcount.
Applied to a Fluidstack region
Post orders in force at every site in the region, signed by site leadership, written to the threat rather than inherited from the last contract. A guard force that cannot tell you why a post exists will not hold it at 3 a.m.
A vendor performance framework with teeth: measurable post standards, QA inspections at a published cadence, and a scorecard reviewed with the vendor monthly. Guard performance should be a number you can see before it becomes an incident you have to explain to a customer.
I spent thirteen years
being the response.
Before I managed incident response, I was what showed up. Thirteen and a half years at the San Antonio Police Department — patrol, street crimes, gang unit, narcotics, intelligence, and a federal HIDTA task force as a detective. I am not describing a policy I wrote. I am describing what I did at 2 a.m. for over a decade, and then what I built so somebody else could do it well.
The requirement
You’re as effective walking a perimeter at 2 AM as briefing executives on regional risk. … Experience handling end-to-end incident response processes.
The 2 a.m. half
Thirteen years, six months. TCOLE ID 376951. Master Peace Officer.
I graduated top of my academy class, later served as academy president, and returned as an instructor. In between I worked patrol, Street Crimes, the Gang Unit, TAG, narcotics and intelligence, and served as a Task Force Officer on a federal HIDTA task force. I was also elected by my peers as a Police Association Representative.
Documentation that had to survive a U.S. Attorney and a federal grand jury
This is the part of my record that matters most for a company whose incidents will be investigated by people with subpoena power.
I handled evidence and maintained chain of custody to federal standards, and I prepared federal prosecution guides that were reviewed and approved by the United States Attorney’s Office and presented to a federal grand jury. That is the highest external bar my documentation has ever been held to, and it was cleared.
An incident report that cannot survive scrutiny is not a report, it is a liability. I learned that where the consequences were somebody’s liberty.
The training behind the response
- FBI Academy, Quantico — multiple courses, including hazardous materials, clandestine laboratories, and tactical entries
- Advanced Surveillance Operations
- FEMA / incident command and incident management training
- Former licensed EMT — I have been the medical response, not just the person who called it
- TCOLE Master Peace Officer, with Intermediate, Advanced and Master certificates issued February 2021
- Platforms: Mark43 RMS, Axon digital evidence management — see Sheet 14 for the full list
The executive half
Owning response instead of performing it
My job now is to make sure the response happens correctly when I am not the one running to it. That means incident response as a written process with defined roles, a Command Center that dispatches it, crisis response planning, and emergency management across a 600-acre footprint and twenty-two departments.
- I built a tiered Emergency Response Team notification plan — escalation defined by severity, so the right people are woken up and the wrong people are not
- I create, design, host and personally present active shooter tabletop exercises for our executive leadership and the Emergency Response Team. Not a vendor’s deck — mine, run by me
- I built and delivered an armed-officer business case with ROI and risk analysis to leadership — one of thirteen proposals I have presented, eleven of which were funded
Selected to be the person sent when a site is in trouble
Marriott put me on a national task force of interim executives and deployed me to Viewline Snowmass. The selection is the point: when a property’s security operation needed stabilizing, I was who they sent. The property offered me the permanent Director role at the end of it.
What this does not cover
My incident response experience is physical and criminal. I have not run a joint physical/cyber incident inside a CISO organization, and I have never responded to an incident where the asset at risk was model weights.
That is a real gap and I will not paper over it. What I would bring to it is thirteen years of habit around evidence, federal-standard chain of custody, timeline reconstruction, and interviewing — which is most of what the physical leg of a weight-exfiltration investigation actually consists of — and the willingness to be the junior voice in the room on the logical side until I have earned otherwise. The dated plan for closing it is on Sheet 14.
Applied to a Fluidstack region
One incident response process across the region, tested by tabletop at every site inside six months, with a documented after-action for each. A process that has never been run is a document, not a capability. I already write and run these exercises personally for an executive audience.
And a rule I hold personally: I walk the perimeter at 2 a.m. Not as theater — because the posture you have at 2 a.m. on a Sunday is your real posture, and it is never the one in the daytime briefing.
Standards are the only thing
that scales across sites.
Everything else — instinct, relationships, the fact that you personally noticed something — stops at the property line. A written standard travels. So does an audit finding. This sheet is what I have standardized, the three separate audits I am measured against, and the frameworks I have never run, each with a date attached.
The requirement
You standardize SOPs and post orders across sites without losing the on-site instinct for what each facility actually needs. … You’ve carried security commitments to enterprise customers through audits and contractual obligations.
What I have standardized
Twenty-seven SOPs, ninety-five processes, forty RACI tasks
When I arrived, the operation ran on institutional memory. It now runs on documents. I rewrote and expanded the SOP set to 27 standing procedures covering roughly 95 documented processes, and built a RACI matrix across about 40 tasks so that no responsibility lives in the gap between two people who each assumed the other had it.
The occupancy-based deployment model is itself a written standard rather than a supervisor’s judgment call — six posts at or below 60% occupancy, scaling to ten at 100%, with six manned 24/7/365 as a floor the model is not permitted to breach.
Roughly twenty SOPs for a property that had zero — in under three weeks
Snowmass is my evidence for both halves of the requirement at once. The property had no security SOPs and no property maps. I wrote approximately 20 SOPs and supporting processes, hand-drew and then digitized the property so locations could be referenced at all, created a door naming convention, and built a grand master key program.
That is standardization built from a blank page under time pressure — which is closer to a greenfield site activation than anything else on my résumé.
Standardizing across sites, to somebody else’s standard
Federal facility security standards across four hospital sites is where I learned that standardization is not sameness. Each site got post orders written to its own layout, population and risk — against one contract standard that did not bend. The QA program is what kept those two things from drifting apart. I built all of it as the first hire on the contract.
Three audits, three control sets
The JW Marriott security department is measured against three separate audit regimes, each with its own controls. Running one department against three different control sets simultaneously is the closest thing in my record to carrying enterprise customer commitments across a region.
| Audit | Who runs it | Different controls, same department |
|---|---|---|
| Brand Standard Audit | Marriott brand | Brand-defined safety and security standards. Most recent result: 100% compliance. |
| Owner Audit | Property ownership | Ownership’s own control set — asset protection, liability and financial exposure. |
| Marriott Corporate Audit | Marriott corporate | Corporate control set, distinct from the brand standard. |
Executive commitments
Thirteen presented. Eleven approved and funded.
Every one carried ROI and risk analysis. They include the armed-officer business case and a FY2027 capital proposal for perimeter intrusion detection — which is to say I have already written a PIDS requirement and its business case, even though I have not yet commissioned a system.
This is the executive-facing muscle the role needs: constructing a security argument that survives scrutiny from people who do not work in security.
Framework position, with dates
| Framework | Status today | Plan | Closed by |
|---|---|---|---|
| SRMP-C — Security Risk Management Professional | Held | Issued by INSSA, valid three years from July 2026 | — |
| Federal facility security standards | Operated to | Four VA hospital sites, 2014–2016 | — |
| ICC Plans Examiner | Certified | Code review of construction drawings | — |
| ASIS CPP | Not yet held | Board exam, sat within the contract year | Day 365 |
| ISO 27001 | Not held | Implementer-level training, self-funded | Day 270 |
| SOC 2 Type II | Never run one | Own the physical security evidence package for one real customer audit cycle | Day 270 |
| NIST CSF / 800-53 | Not owned | Map the regional physical control set to the relevant families | Day 180 |
| Data center infrastructure credential | Not held | Uptime-equivalent tier/design credential, self-funded | Day 270 |
| ASIS PSP | Not held | After CPP | Post-term |
What this does not cover
I have never personally run a SOC 2 Type II examination, an ISO 27001 certification cycle, a NIST CSF or 800-53 assessment, or a DoD-standard program. If carrying an enterprise customer through one of those in the first quarter is the job, I am not the finished article and you should know that before you decide.
What I have done is be the accountable person in three concurrent audit regimes where failing had a commercial consequence, and pass. The framework I would have to learn — on the dates above, at my own cost. The posture of being audited I already have.
Applied to a Fluidstack region
A single regional SOP set in force inside six months — access management, visitor and vendor control, incident response, guard post standards — with site-specific annexes rather than site-specific reinventions.
And a customer-facing security package: audit-ready documentation, evidence artifacts, and a standard site tour. When a customer asks how you control access to the hall their weights are training in, the answer should already be written, already be evidenced, and already be the same at every site in the region.
Here is the line between
what I have touched and
what I have only designed around.
Most candidates blur this. I am printing it, because you are a CISO and a physical security engineer and you will find the line in the first ten minutes anyway. Finding it in my own document should tell you something about how I will report a finding you do not want to hear.
The requirement
Bonus: Physical security systems fluency (ACS, VMS).
Every platform, stated honestly
| Platform | Depth | What that actually means |
|---|---|---|
| Access control & physical security | ||
| Dormakaba | Hands-on | Daily administration, credential lifecycle, troubleshooting |
| Safelock / Ambiance | Hands-on | Administration and maintenance in a live operation |
| Visionline / VingCard | Hands-on | Full lock and access audit at Viewline Snowmass; corrected configuration errors myself |
| Key Commander | Hands-on | Key system administration and control |
| KeyWatcher | Hands-on | Electronic key management with two-person authorization to issue |
| Amano One | Hands-on | Parking and vehicle access administration |
| Milestone (VMS) | Hands-on | Video management in daily operational use across 500+ CCTV devices |
| License plate recognition | Hands-on | Various platforms across nine controlled vehicle access points |
| Operations, records & evidence | ||
| Mark43 RMS | Hands-on | SAPD records management — case reporting and records to a standard that had to survive prosecution |
| Axon | Hands-on | Body-worn camera and digital evidence management, with chain of custody |
| MS Shift | Hands-on | Safety, security and operations platform — dispatch, incident capture, reporting |
| RelayDash | Hands-on | Operational dispatch and task management |
| Design-fluent, not hands-on | ||
| Lenel OnGuard | Design-fluent | Can specify to it and read its architecture. Have not administered it. |
| Genetec Security Center | Design-fluent | Fluent in the design conversation, not the console. |
| C•CURE 9000 | Design-fluent | Same. |
| PSIM | Design-fluent | Understand the integration model; have not deployed one. |
| Perimeter intrusion detection (PIDS) | Specified, not commissioned | I authored and submitted a FY2027 capital proposal for perimeter intrusion detection. I have written the requirement and the business case; I have not yet commissioned a system. |
Scale administered
The estate I administer today
I own the administration, expansion, maintenance and audit of this estate. I want to be precise about one thing: I did not design or specify the access control system in place here. It was inherited. What I own is everything that happens to it after the install — which, over a system’s life, is most of what determines whether it actually works.
I built the room
I consolidated CCTV monitoring, alarm annunciation, fire suppression controls and dispatch into a single unified Command Center and put it into service on 6 March 2026. The consolidation took three staffed positions down to two — a 33% reduction — while increasing what a single operator can actually see.
This is the piece of my record closest to what you would ask me to stand up at a site: taking scattered monitoring and turning it into one place where somebody is accountable for noticing.
The hands-on system work — from a blank page
This is where my direct configuration experience actually lives, and it was not just administration. The property had no maps and no key hierarchy.
- Hand-drew the property and digitized it, so openings could be located and referenced at all
- Created a door naming convention — my own system — giving every opening a unique identifier usable by an officer, a technician and an auditor alike
- Built a grand master key program from scratch, with the hierarchy documented
- Ran a property-wide re-key and a full lock and access-control audit
- Identified and corrected Visionline/VingCard configuration errors myself, at the console
- Footprint was far smaller than 1,500 points — but the work was mine, not delegated
The access control standard I own
A platform list tells you what I have clicked. A standard tells you how I think about entitlement.
- Least-privilege, role-based provisioning — with written approval required for restricted areas
- Two-person authorization on every credential. No single person can grant access at this property — two people sign off to issue a credential, and two-person authorization is required to release a key from electronic key management
- Two-person integrity sign-off across HR, Security and Engineering/IT
- Immediate deactivation on separation. Not same-day. Immediate.
- Annual entitlement review — every credential mapped to a named owner and an approval record
- Visitor badging and escort discipline
- Vendor staging and dock-only routing, so contractor access is a defined path rather than a courtesy
What this does not cover
I have not administered an enterprise ACS/VMS stack of the class you are likely running — Lenel, Genetec or C•CURE at regional scale. I can specify to those platforms, read their architecture, and hold an integrator accountable to a design. I would be learning the console, on the dated plan on Sheet 14.
On perimeter intrusion detection: I have written the requirement and the business case — a FY2027 capital proposal for PIDS is submitted at my current property — but I have not commissioned a system.
I am not going to tell you that hospitality access control is the same as data center access control. It is not. The credential lifecycle discipline transfers; the platform depth I would have to earn, and I would rather earn it on your clock at a reduced rate than have you find out about it after the offer.
Applied to a Fluidstack region
A 100% access control entitlement audit across the region: every credential mapped to a named owner, an approval record and a current business justification. Every orphaned credential closed. This audit finds something in every environment it has ever been run in, and it is the cheapest posture improvement available at any site.
Then device-level verification against design intent rather than against an install checklist. A camera that is online is not a camera that covers what the drawing said it would cover. I would walk it — and where there is no drawing, I would draw it, the way I did at Snowmass.
Most security leaders inherit
a building. I have built them.
This is the part of my record that does not appear on other candidates’ résumés. I own a construction company. I hold an ICC Plans Examiner certification. And I currently own the entire security profile of a live, eighteen-month, nine-figure renovation with hundreds of vendors on site every day. Fluidstack acquires power, designs and builds data centers, and operates them — I have done the middle part of that sentence for a living.
The requirement
Partner with site operations, facilities, construction, and vendors to integrate security into every phase of the region’s growth.
The record
Solo operator to $2M+ annual revenue, residential and commercial
I built a construction business from nothing to over $2M in annual revenue across residential and commercial work, including a contracting arrangement with American Woodmark under RE Services LLC. I have negotiated with subs, held trades to a schedule, read and corrected drawing sets, and been personally liable for what got built.
For transparency about my commitments: I am closing this business once my current build finishes. I am not carrying it into this role.
I can read the drawing set before it is a building
A plans examiner certification means I review construction documents for code compliance as a discipline, not as a favor. In a security context that is the difference between specifying a door and knowing whether the conduit to reach it exists in the drawing you are about to approve.
A nine-figure renovation, running inside an operating resort
The property is mid-way through an eighteen-month renovation in the several-hundred-million-dollar range, and I own the entire security profile of it while the resort continues to operate at occupancy.
- Vendor and contractor control and credentialing — hundreds of vendors credentialed daily
- Site safety and compliance reviews across active construction areas
- Coordination of planned utility shutoffs, each evaluated against safety and security risk before it happens
- Maintaining guest-facing posture at a property that is simultaneously a construction site
- A standing weekly cadence with site operations and the renovation vendors — not a status email, a recurring working session where security is in the room while decisions are still reversible
Greenfield versus brownfield
| Greenfield | Brownfield / live site | |
|---|---|---|
| What sets the pace | The construction schedule. Security either lands in the drawing set or it gets retrofitted at ten times the cost. | The operation. You cannot take a door out of service because your standard says so. |
| Where risk concentrates | The window between first perimeter and first credentialed access — when the site is valuable, populated by trades, and not yet controlled. | The credential population and the vendor path. Both grow quietly until somebody audits them. |
| The failure mode | Security shows up at commissioning and discovers the conduit was never pulled. | Everyone assumes the inherited system does what it did the day it was installed. |
| My grounding | General contractor and ICC Plans Examiner — I read the drawing set before it is built. | The JW Marriott renovation: hundreds of vendors credentialed daily inside a running operation. |
The sequence I run on a build
- Define threat and consequence first — Before a single line is drawn. What is actually being protected, from whom, and what does losing it cost? Everything downstream is an answer to this question or it is decoration.
- Read the site, not the plan — Terrain, approach routes, sightlines, utility and fiber ingress, neighbors, and how somebody would actually get to the thing that matters.
- Layer to deter, detect, delay, respond — With delay budgeted explicitly against real response time. A ten-minute delay is a failure if response is fifteen.
- Examine the drawing set — Door schedules, hardware, conduit and pathway, camera sightlines against final landscaping and lighting. This is where my plans examiner certification earns its keep — the cheapest security fix is a redline before pour.
- Secure the construction phase itself — Perimeter before steel. Credentialing, materials and lay-down control, badge and escort discipline for trades. A site is at its most exposed while it is being built.
- Commission against design intent — Not against an install checklist. A device that is online is not a device that does what the drawing promised. Test it against the threat it was specified for.
- Activate the human layer — Post orders, staffing model, training, and a tabletop exercise before turnover, not after the first incident.
- Turn over with metrics already running — Audit cadence set, entitlement review scheduled, incident and response metrics baselined on day one. A site that goes live without a baseline can never prove it improved.
What this does not cover
I have not built a data center. I have not sat in a design review for a hall, a meet-me room, or a substation, and I do not have the vocabulary of your build teams yet.
What I have is the thing that is harder to teach: I have stood on a job site as the person responsible, read the set, argued with a sub about a detail, and watched what happens when security is added after the concrete cures. Your build teams will not have to explain construction to me. They will have to explain data centers to me, and I will learn that faster than a data center person will learn how to run a job.
Why this is the strongest argument I have
You are deploying gigawatts in months, not years. That means security at a Fluidstack site is not an operations problem that begins at handover — it is a deployment problem that begins in the drawing set and is most acute during construction, when the site is valuable, crowded with trades, and not yet controlled.
There are a lot of physical security leaders who can run a finished site. There are very few who have been the general contractor, hold a plans examiner certification, and are currently running security for a nine-figure build inside a live operation. That intersection is the reason I am writing to you at all.
Here is what I don’t have,
the dated plan to fix it,
and what it costs me.
Your posting lists four bonus qualifications. I have three of them and I am missing the first one entirely. Rather than argue around that, this sheet scores all four honestly, itemizes every security platform I have and have not touched, and then commits to a dated plan — with my own money attached — that closes every deficiency I have inside the contract term.
The four bonus items, scored
| Bonus item, as posted | Honest score | The facts |
|---|---|---|
| Hyperscale or data center security | Do not have it. | None. Not adjacent, not translatable — absent. This is my single largest deficiency and it is likely the reason your team said no. Closure plan below. |
| Guard force vendor management at scale | Have it — both sides | Built and managed a contract guard force across four VA hospital sites to federal facility security standards, as the first hire on the contract. And I was the vendor for ten years: up to 50 officers deployed nightly across 10–15 properties. Caveat: not at your spend scale. Sheet 09. |
| Physical security systems fluency (ACS, VMS) | Partial — itemized below | 1,500+ access control points and 500+ CCTV devices administered daily; built a grand master key program and a door naming convention from scratch at Snowmass. But the enterprise platforms you most likely run are design-fluent for me, not hands-on. Sheet 12. |
| Multi-site or regional leadership | Have it | Four portfolios across seventeen years. Regional Security Manager over four Texas VA hospital sites; ten years running nightly coverage across 10–15 properties; 600 acres and 22 departments today. Sheet 14. |
Every security platform, itemized
You asked for systems fluency. Here is the complete list — access control and physical security, then operations, records and evidence, then the platforms I am design-fluent on but have not administered. The line is printed rather than blurred.
| Platform | Depth | What that actually means |
|---|---|---|
| Access control & physical security | ||
| Dormakaba | Hands-on | Daily administration, credential lifecycle, troubleshooting |
| Safelock / Ambiance | Hands-on | Administration and maintenance in a live operation |
| Visionline / VingCard | Hands-on | Full lock and access audit at Viewline Snowmass; corrected configuration errors myself |
| Key Commander | Hands-on | Key system administration and control |
| KeyWatcher | Hands-on | Electronic key management with two-person authorization to issue |
| Amano One | Hands-on | Parking and vehicle access administration |
| Milestone (VMS) | Hands-on | Video management in daily operational use across 500+ CCTV devices |
| License plate recognition | Hands-on | Various platforms across nine controlled vehicle access points |
| Operations, records & evidence | ||
| Mark43 RMS | Hands-on | SAPD records management — case reporting and records to a standard that had to survive prosecution |
| Axon | Hands-on | Body-worn camera and digital evidence management, with chain of custody |
| MS Shift | Hands-on | Safety, security and operations platform — dispatch, incident capture, reporting |
| RelayDash | Hands-on | Operational dispatch and task management |
| Design-fluent, not hands-on | ||
| Lenel OnGuard | Design-fluent | Can specify to it and read its architecture. Have not administered it. |
| Genetec Security Center | Design-fluent | Fluent in the design conversation, not the console. |
| C•CURE 9000 | Design-fluent | Same. |
| PSIM | Design-fluent | Understand the integration model; have not deployed one. |
| Perimeter intrusion detection (PIDS) | Specified, not commissioned | I authored and submitted a FY2027 capital proposal for perimeter intrusion detection. I have written the requirement and the business case; I have not yet commissioned a system. |
Scale administered today
The deficiency closure plan
Every gap above, with a method, a cost to me, and a date. The operational gaps close by Day 180; the credential-dependent ones by Day 270, and the board certification by Day 365 — deliberately, because I am not going to miss nine other dated commitments while studying for an exam.
I have kept the specific programs unnamed on purpose. I want the latitude to pick the route that actually teaches the most, including non-traditional or no-cost ones, rather than being held to a course catalogue I chose before I saw your estate.
| # | Deficiency | How I close it | My cost | Closed by |
|---|---|---|---|---|
| D1 | No hyperscale or data center security experience | Two tracks. Immersion: shadow the build and critical facilities teams at every site in the region and document the power, cooling and hall architecture myself rather than being briefed on it. Credential: a recognised data centre infrastructure / tier design credential, or a demonstrably equivalent program — I want latitude to pick the one that actually teaches the most, including non-traditional or no-cost routes. | $3,000–7,000 | Immersion Day 180 Credential Day 270 |
| D2 | No hands-on enterprise ACS/VMS (Lenel, Genetec, C•CURE) | Vendor-led administrator-level certification on whichever platform is actually in the Fluidstack estate — console-level, not overview-level. Vendor and integrator training routes are often bundled with an install, so this may cost less or nothing. | $0–4,000 | Day 180 |
| D3 | No SOC 2, ISO 27001 or NIST cycle personally owned | Implementer-level information security management training, plus I own the physical security evidence package for one real customer audit cycle end to end rather than supporting someone else’s. The training I pay for; the audit is the job. | $1,500–3,500 | Training Day 270 NIST control mapping Day 180 |
| D4 | No ASIS board certification | CPP board exam, sat within the contract year. I am deliberately not front-loading this — I am not going to spend my first six months studying when I have nine other commitments with dates on them. | $1,000–1,500 | Day 365 |
| D5 | Never commissioned a perimeter intrusion detection system | Partial credit already: I authored and submitted a FY2027 capital proposal for PIDS at my current property, so I have written the requirement and the business case. What I have not done is commission one. I would participate in the commissioning of at least one perimeter system in the region, at device level, against design intent. | — | Day 180, or first commissioning |
| D6 | Never responded to an incident where the asset was model weights | Build and run the physical leg of a joint physical/cyber tabletop with your security engineering team — I already write, host and present active shooter tabletops for executive leadership, so the exercise craft is there; the threat model is what I need. And be the junior voice in the room on the logical side until I have earned otherwise. | — | Day 180 |
What this costs me
Costs are my own estimates and will move. The point is not the exact figure — it is that closing my gaps is not a line item I am asking you to approve. Between the discounted salary and the training I fund myself, I am putting somewhere between $26,500 and $37,000 of my own money behind the claim that I can do this job. That is the strongest signal of confidence I am able to send you, and it is the reason I think this proposal is worth twenty minutes rather than a polite decline.
What I am not promising
I am not promising that a year of deliberate work makes me equivalent to someone who has run hyperscale physical security for a decade. It does not, and anyone who tells you otherwise is selling.
What I am promising is that the deficiency stops being a reason to worry about me — because it will be documented, dated and closed against evidence you can inspect — while the things I already bring that are hard to hire for are there from week one.
And that if I am wrong about that, you exercise the month-six off-ramp on Sheet 01 and it costs you nothing but the discounted salary you already paid.