The Playbook
Prepared for Fluidstack — Security

The
Playbook

A 365-day plan to execute the Regional Security Operations Lead role, and to close every gap I have, on dates you can hold me to.
Prepared byJonathon Hoggard, SRMP-C
ForJason Kichen · Logan Beach
Joey Johnsen · Steven Heishman
RoleRegional Security
Operations Lead
Date26 August 2026
Part One — The Plan · Sheets 01–06 Part Two — The Evidence · Sheets 07–14
Swipe, or use ← →
01Part OneThe Offer

All good things
start with an offer.

Here is mine. It is priced below your floor, bounded by a term, and built so that the only person carrying risk past month six is me.

1.0

The terms

$200,000
Base — $21K below your posted floor
12 months
Defined term
Month 6
Your unilateral off-ramp
180 days
Operational deficiencies closed
$221,000
Base at month 12 on delivery
10
Commitments, self-set, dated
TERMSWhat each side is actually agreeing to
  • You pay 10% under your own floor for twelve months, in exchange for a candidate without hyperscale data center experience. The discount is priced to exactly the gap you identified.
  • You carry no downside risk past month six. The off-ramp is yours alone to exercise, on evidence I defined in advance and cannot move later.
  • I carry the burden of proof. Every commitment produces an artifact you can hold, or it does not count. “Improved posture” is not a deliverable. A signed post order is.
  • I fund my own gap closure. Four of six items out of my pocket, an estimated $5,500 to $16,000. With the salary discount, that is $26,500 to $37,000 of my own money behind the claim.
  • Equity on your standard terms. No premium sought anywhere else.
  • No competing commitments. I am closing my construction business on completion of my current build. It does not come with me.
  • Or make it interim. Run me until you find the right person. I am not precious about the title — I am confident you already found the right person, you just do not know it yet.
2.0

The ten commitments

#CommitmentHow you verify itBy
01Baseline physical security assessment complete at every site in the region, findings ranked by risk and consequence, with a costed remediation planThe document, in your handsDay 90
02Post orders written to the threat and in force at every site, signed by site leadershipSigned post orders on file, per siteDay 90
03100% access control entitlement audit — every credential mapped to a named owner, an approval record and a current justification; every orphan closedAudit record, with the count of credentials closedDay 90
04One regional SOP set in force: access management, visitor and vendor control, incident response, guard post standardsThe SOP set, adoptedDay 180
05Guard vendor performance framework live — measurable post standards, QA at a published cadence, monthly scorecardThree consecutive months of scorecardsDay 180
06Every critical finding from the Day 90 baseline either closed, or funded-and-scheduled with an interim mitigation in forceThe baseline document, line by lineDay 180
07Incident response tabletop run at every site, with documented after-actionAfter-action reports, one per siteDay 180
08My operational deficiencies closed — hyperscale immersion documented, enterprise ACS/VMS certification held, NIST control mapping delivered, PIDS commissioning participated in, joint physical/cyber tabletop runCertificates and artifacts, five itemsDay 180
09Customer-facing security package ready: audit-ready documentation, evidence artifacts, standard site tourYou put a real customer through itDay 270
10Regional metrics published monthly from month one: incidents, response times, access anomalies, post compliance, open findings, by siteTwelve consecutive months of published metricsMonthly
3.0

How the year is shaped

Four phases, in order

Phase I, Day 1–90 — Establish. Find out what is actually true at every site, write it down, and price the fix.

Phase II, Day 91–180 — Standardize. One region, one standard. And every operational gap I have is closed and evidenced by the end of it.

Phase III, Day 181–270 — Prove. Put the program in front of a real customer and let it be tested by someone who is not me.

Phase IV, Day 271–365 — Institutionalize. Make it survive me.

02Part OnePhase I · Establish
Phase IDay 1 – 90

Establish
the baseline.

You cannot standardize a region you have not walked. The first ninety days are spent finding out what is actually true at every site, writing it down in a form you can act on, and putting a price on the fix. Nothing in this phase is assessed from a desk.

1.0

What I do

P1-AWeeks 1–4 — Walk it
  • Walk every site in the region, including nights and weekends. The posture you have at 2 a.m. on a Sunday is your real posture, and it is never the one in the daytime briefing.
  • Map what is not mapped. At Snowmass I hand-drew a property that had no maps and then digitized it, because you cannot reference a door that has no name. I would do the same here for anything missing.
  • Meet the site personnel and the contract guard force on their post, on their shift — not in a conference room.
  • Sit with site operations, facilities and the build teams. Ask what security does that gets in their way, and write the answers down.
P1-BWeeks 2–10 — Assess to one methodology
  • Run a single physical security assessment methodology at every site so the results are comparable. Deter, detect, delay, respond — with delay budgeted explicitly against real response time.
  • Rank every finding by risk and consequence rather than by which site complains loudest.
  • Verify devices against design intent, not against an install checklist. A camera that is online is not a camera that covers what the drawing said it would cover.
  • Run a 100% access control entitlement audit: every credential mapped to a named owner, an approval record and a current business justification. Close every orphan. This audit finds something in every environment it has ever been run in.
P1-CWeeks 6–13 — Write it down
  • Post orders written to the threat at each site — not inherited from the last contract — and signed by site leadership. A guard force that cannot tell you why a post exists will not hold it at 3 a.m.
  • A costed remediation plan in your hands: every finding, what it costs to fix, and what it costs not to.
  • The first monthly regional metric publication goes out at Day 30, with whatever is knowable then. The baseline starts on day one or it never exists at all.
2.0

What closes in this phase

CommitmentArtifact you receiveBy
01 — Baseline assessment at every siteThe document, ranked and costedDay 90
02 — Post orders in forceSigned post orders, per siteDay 90
03 — 100% entitlement auditAudit record with orphans closedDay 90
10 — Regional metricsFirst issue publishedDay 30, then monthly
Gap work running underneath

D1 — hyperscale immersion begins in week one. I shadow the build and critical facilities teams at every site and document the power, cooling and hall architecture myself rather than being briefed on it. By Day 90 I can read your estate; by Day 180 it is documented and evidenced.

D2 — enterprise ACS/VMS. I find out which platform is actually in your estate and enrol in vendor-led administrator training on it. Console-level, not overview-level, at my cost.

3.0

Why this order

First principles

Every instinct in a new job says to start fixing things. That is the wrong move in a region, because the fixes you can see in week one are the ones the site already knows about — they are visible precisely because somebody already flagged them.

The findings that matter are the ones nobody has looked for. Those only surface from a methodology applied uniformly, at every site, by someone who does not yet have a reason to look away from any of them. That window closes about ninety days in, and it does not reopen.

03Part OnePhase II · Standardize
Phase IIDay 91 – 180

Standardize
the region.

One region, one standard, with site-specific annexes rather than site-specific reinventions. This is also the phase where every operational deficiency I have is closed and evidenced — because month six is your off-ramp, and I am not going to arrive at it still owing you something.

1.0

What I do

P2-AOne SOP set, in force
  • Access management, visitor and vendor control, incident response, guard post standards — written once for the region, annexed per site.
  • A RACI across the regional security tasks, so no responsibility lives in the gap between two people who each assumed the other had it. I run about forty of these at my current property.
  • Vendor staging and dock-only routing written as standard, so contractor access is a defined path rather than a courtesy.
P2-BA guard force you can measure
  • Measurable post standards, QA inspections at a published cadence, and a monthly vendor scorecard reviewed face to face.
  • I write that scorecard as someone who spent ten years as the vendor being inspected. I know which metrics a guard vendor can quietly game and which ones they cannot.
  • Guard performance becomes a number you see before it becomes an incident you have to explain to a customer.
P2-CResponse that has actually been run
  • One incident response process across the region, tested by tabletop at every site, with a documented after-action for each. A process that has never been run is a document, not a capability.
  • I write, host and present these myself — I already do it for executive leadership and an emergency response team at my current property.
  • One of those exercises is a joint physical/cyber tabletop with your security engineering team. I own the physical leg and I am the junior voice on the logical side until I have earned otherwise.
P2-DClose out the baseline
  • Every critical finding from the Day 90 assessment either closed, or funded-and-scheduled with an interim mitigation in force and written down.
  • Nothing sits open and unexplained. If it is not fixed, you know why, what it costs, and what is holding the line in the meantime.
2.0

What closes in this phase

ItemWhat it isVerified byBy
C-04One regional SOP set in forceThe SOP set, adoptedDay 180
C-05Guard vendor performance framework liveThree consecutive monthly scorecardsDay 180
C-06Every critical Day 90 finding closed or funded-and-mitigatedThe baseline document, line by lineDay 180
C-07Incident response tabletop at every siteAfter-action reports, one per siteDay 180
C-08My operational deficiencies closedCertificates and artifacts, five itemsDay 180
D-1Hyperscale immersion — power, cooling and hall architecture at every site, documented by meThe documentDay 180
D-2Enterprise ACS/VMS administrator certification on the platform in your estate, console-level. My cost: $0–4,000The certificateDay 180
D-3Regional physical control set mapped to the relevant NIST control familiesThe mappingDay 180
D-5Perimeter intrusion detection commissioned at device level against design intentCommissioning recordDay 180
D-6Joint physical/cyber tabletop built and run with your security engineering teamAfter-action reportDay 180
3.0

The checkpoint

Month six — your call, not mine

At the end of this phase you hold a unilateral off-ramp. If commitments 01 through 08 are not delivered and verifiable against the artifacts named above, you end it. No severance, no notice period, no argument.

I have deliberately front-loaded the hardest work and all of my own gap closure into the first six months, so that the decision you make at that checkpoint is made on evidence rather than on optimism.

04Part OnePhase III · Prove
Phase IIIDay 181 – 270

Prove it to
somebody who
isn’t me.

A security program that has only ever been graded by the person who built it has not been graded. This phase puts the region in front of a real enterprise customer and lets it be tested.

1.0

What I do

P3-ABuild the customer-facing package
  • Audit-ready documentation: the control set, the evidence behind each control, and the artifacts that prove it operating rather than existing.
  • A standard site tour — the same at every site in the region, so a customer visiting two sites sees one company.
  • When a customer asks how you control access to the hall their weights are training in, the answer is already written, already evidenced, and identical everywhere.
P3-BPut a customer through it
  • Not a rehearsal. A real customer, a real visit or audit cycle, with me as the accountable name on the physical security evidence package end to end.
  • This is the part of the job I have done longest under real consequence. At my current property the department is measured against three concurrent audit regimes — brand standard, ownership, and Marriott corporate — each with its own control set. Before that, federal facility security standards across four VA hospital sites.
P3-CTake the findings seriously
  • Whatever the customer finds goes into the same ranked, costed format as the Day 90 baseline, and gets closed or funded on the same discipline.
  • An audit finding you argue with is a finding you will see again.
2.0

What closes in this phase

ItemWhat it isVerified byBy
C-09Customer-facing security package: audit-ready documentation, evidence artifacts, standard site tourYou put a real customer through itDay 270
D-3Implementer-level information security management training, plus ownership of one real customer audit evidence package end to end. My cost: $1,500–3,500Certificate and the audit recordDay 270
D-1A recognised data centre infrastructure or tier design credential, or a demonstrable equivalent. My cost: $3,000–7,000The credentialDay 270
Limitation of scope

A year of deliberate work does not make me equivalent to someone who has run hyperscale physical security for a decade, and anyone who tells you otherwise is selling. What it does is make the gap documented, dated and closed against evidence you can inspect — so it stops being a reason to worry about me.

05Part OnePhase IV · Institutionalize
Phase IVDay 271 – 365

Make it
survive me.

A program that depends on the person who built it is a liability, not an asset. The last quarter is about making the standard hold whether or not I am the one enforcing it — and about the one credential I deliberately left until last.

1.0

What I do

P4-AInstitutionalize the standard
  • Twelve consecutive months of published regional metrics — incidents, response times, access anomalies, post compliance, open findings, by site. A region that cannot be read cannot be managed.
  • The annual entitlement review scheduled and running on its own cadence, not because I remembered.
  • Audit cadence set and calendared. QA inspections happening on a published schedule that does not depend on my attention.
P4-BSecurity enters at the drawing set
  • Every new site brought online in the region enters operations with security integrated from the construction phase — nothing retrofitted — verified by a turnover checklist per activation.
  • This is the part I am most confident about. I own a construction company, I hold an ICC Plans Examiner certification, and I currently run the security profile of a live eighteen-month, nine-figure renovation with hundreds of vendors credentialed daily inside an operating property.
  • The cheapest security fix available at any site is a redline before pour.
P4-CBuild the bench, and take the last credential
  • Develop site-level leadership to the point where a site runs its standard without me on it. I am deliberately not making this a numbered commitment — it depends on who you hire, and I will not ask you to score me on someone else's appointment. But it is the work, and you will see it or you will not.
  • ASIS CPP board exam, sat inside the contract year. Deliberately last: I am not going to miss nine dated operational commitments while studying for an exam. PSP to follow, after the term.
2.0

What closes in this phase

ItemWhat it isVerified byBy
C-10Regional metrics published monthly from month oneTwelve consecutive months, publishedDay 365
D-4ASIS CPP board exam, sat inside the contract year. My cost: $1,000–1,500The resultDay 365
06Part OneDay 365 · What You Have
Day 365What you have

What you are
actually buying.

Not a hire. A regional security program that exists, is documented, has been tested by somebody outside the company, and can be read from a dashboard — plus a person who is no longer the candidate you turned down.

1.0

The operation

O-01Every site runs one standard
  • One SOP set in force across the cluster — access management, visitor and vendor control, incident response, guard post standards — with site-specific annexes rather than site-specific inventions.
  • Post orders at every site, written to the threat, signed, and audited against.
  • A guard force measured monthly against a scorecard the vendor cannot game, with QA inspections on a published cadence.
O-02The credential population is clean and stays clean
  • Every badge in the region maps to a named owner, an approval record and a current business justification.
  • Least-privilege provisioning with written approval for restricted areas, two-person authorization to issue, immediate deactivation on separation, and an annual entitlement review running on its own schedule.
O-03Response is a capability, not a document
  • One incident response process across the region, run at every site, with after-action reports on file.
  • At least one joint physical/cyber exercise completed with security engineering.
O-04The region can be read
  • Twelve consecutive months of published metrics: incidents, response times, access anomalies, post compliance, open findings, by site. A baseline that did not exist before, and now cannot be argued with.
  • If a site is drifting, you do not need me to tell you. You can read it.
O-05Customers have already tested it
  • An audit-ready documentation and evidence package that a real enterprise customer has been through — not a rehearsal.
  • A standard site tour, identical everywhere, so a customer visiting two sites sees one company.
O-06Growth carries security with it
  • Every site activated during the year entered operations with security integrated from the construction phase, verified by a turnover checklist. Nothing retrofitted.
  • Security enters at the drawing set, which is the only place it is cheap.
2.0

Who is at the helm

The same person, with the gap closed. Everything I brought on day one is still there — seventeen and a half years across law enforcement, federal-standard contract security, multi-site portfolios, construction ownership, and a live nine-figure build. What is added is the part you were right to worry about.

What I lacked on day oneStatus at Day 365
Hyperscale / data center security experienceDocumented immersion across every site in the region, written by me, plus a recognised infrastructure credential
Hands-on enterprise ACS/VMSAdministrator-certified on the platform in your estate
SOC 2 / ISO 27001 / NIST cycle ownedImplementer-trained, NIST control mapping delivered, one real customer audit cycle owned end to end
PIDS commissioningCommissioned at device level against design intent
Joint physical/cyber incident responseBuilt and ran the physical leg of a joint exercise with your security engineering team
ASIS board certificationCPP
3.0

What my résumé says in August 2027

This is the entry I intend to have earned. I am printing it now so that in twelve months you can hold it against what actually happened.

Regional Security Operations Lead — Fluidstack Aug 2026 – present

Own physical security across every site in a Fluidstack region — the infrastructure delivering frontier AI compute at gigawatt scale. Built the regional program from a standing start.

  • Delivered a ranked, costed physical security baseline at every site in the region inside 90 days, and closed or funded every critical finding inside 180.
  • Wrote and put in force post orders at every site, written to the threat and signed by site leadership.
  • Ran a 100% access-control entitlement audit across the region; every credential mapped to a named owner, an approval record and a current justification, every orphan closed.
  • Standardized SOPs, access management, visitor and vendor control, and incident response across the cluster with site-specific annexes.
  • Built and ran a guard vendor performance framework: measurable post standards, QA at published cadence, monthly scorecards.
  • Tested incident response by tabletop at every site with documented after-action, including a joint physical/cyber exercise with security engineering.
  • Carried an enterprise customer through a security audit cycle as the accountable owner of the physical evidence package.
  • Published the region's first monthly security metric set — incidents, response times, access anomalies, post compliance, open findings — for twelve consecutive months.
  • Integrated security into site activation from the construction phase forward; no retrofits.

Credentials added in role: ASIS CPP · ISO 27001 implementer · enterprise ACS/VMS administrator · data centre infrastructure credential · perimeter intrusion detection commissioning

Limitation of scope

And if it does not go that way — if I miss, you exercised the off-ramp at month six and it cost you a discounted salary and nothing else. No severance, no notice, no argument. That is written into the offer and it is yours alone to trigger.

You still keep the baseline assessment, the post orders, the entitlement audit and the remediation plan, because those are delivered by Day 90. Even the failure case leaves your region better documented than it is today.

07Part TwoRole Scope

Your five scope bullets.
What I have already run,
and exactly what I would do.

No fluff, just facts. Each block below quotes one line of your role scope, states what I have already been accountable for against it, and then states specifically what I would do in your region — with a date attached wherever a date is possible.

1.0

Scope, line by line

SC-01Role scope, as posted
Fluidstack — Role ScopeOwn physical security operations across a Fluidstack region: every site, every shift, accountable end-to-end for posture, performance, and incidents.

I have held end-to-end posture across a footprint I could not see from where I stood, four times

  • Four-site VA hospital contract portfolio at federal facility security standards, built from a standing start as the first hire, 2014–2016
  • Up to fifty officers deployed nightly across 10–15 properties, 2010–2020
  • 600 acres, 1,000+ rooms, 22 departments, a $8.5M operating budget plus capital submissions and 34 officers today — every shift, every day, including the ones I am not there for
  • A property I had never walked, stabilized on a corporate task force in under three weeks — I mapped it, named every door, built a grand master key program and wrote ~20 SOPs, and was offered the permanent Director role
  • Full detail on Sheet 14
How I would execute it here

A single physical security assessment methodology run at every site in the cluster, findings ranked by risk and consequence rather than by which site complains loudest, with a costed remediation plan in your hands by Day 90.

Then a published monthly regional metric set — incidents, response times, access anomalies, post compliance, open findings, by site. If a site is drifting you should not need me to tell you. You should be able to read it.

SC-02Role scope, as posted
Fluidstack — Role ScopeLead the regional security team, including site-level personnel and contract guard force, setting the standard for discipline and execution at every facility.

I have led employed teams, managed contract forces, and been the contract force

  • 34 officers on staff across three shifts today — supervisors, officers, an EMT, an investigator, admin
  • Contract guard force across four VA hospital sites, held to a federal standard — I was the first hire and built the program
  • Ten years as the vendor being inspected — I know which metrics a guard vendor can quietly game
  • Full detail on Sheet 09
How I would execute it here

Post orders written to the threat — not inherited from the last contract — in force and signed by site leadership at every site by Day 90.

A guard vendor performance framework live by Day 180: measurable post standards, QA inspections at a published cadence, and a monthly scorecard reviewed with the vendor. Guard performance should be a number you see before it becomes an incident you explain to a customer.

SC-03Role scope, as posted
Fluidstack — Role ScopeServe as the senior security presence for customer commitments in the region: audits, site visits, contractual obligations, and the relationships behind them.

I have been the accountable name on audits where failing had a commercial consequence

  • Three concurrent audit regimes at the JW Marriott — brand standard, ownership and Marriott corporate, each with its own control set. 100% compliance on the most recent brand standard audit
  • Federal facility security standards across four VA hospital sites, where passing was the commercial condition of the contract
  • Thirteen proposals presented to leadership, eleven approved and funded, each with ROI and risk analysis — security arguments built to survive scrutiny from people who do not work in security
  • Full detail on Sheet 11
How I would execute it here

A customer-facing security package ready by Day 270: audit-ready documentation, evidence artifacts, and a standard site tour. When a customer asks how you control access to the hall their weights are training in, the answer should already be written, already be evidenced, and be identical at every site in the region.

I will say plainly what I have not done: I have never carried a customer through SOC 2 Type II or ISO 27001. My plan and date for closing that is on Sheet 14.

SC-04Role scope, as posted
Fluidstack — Role ScopeStandardize post orders, SOPs, access management, and incident response across the cluster while tailoring execution to each site.

27 SOPs, ~95 documented processes, ~40 RACI tasks — and a three-week read of a site I had never seen

  • Rewrote the SOP estate at the JW Marriott from institutional memory into 27 standing procedures covering ~95 documented processes
  • Built a RACI matrix across ~40 tasks so no responsibility lives in the gap between two people who each assumed the other had it
  • Wrote the occupancy-based deployment model as a standard, not a judgment call — six posts at or below 60% occupancy, ten at 100%, six manned 24/7/365 as a floor the model may not breach
  • Full detail on Sheet 11
How I would execute it here

One regional SOP set in force by Day 180 — access management, visitor and vendor control, incident response, guard post standards — with site-specific annexes rather than site-specific reinventions.

Incident response tabletopped at every site in the region by Day 180, with a documented after-action for each. A process that has never been run is a document, not a capability.

SC-05Role scope, as posted
Fluidstack — Role ScopePartner with site operations, facilities, construction, and vendors to integrate security into every phase of the region’s growth.

This is the strongest argument I have, and it is the one that does not appear on other résumés

  • Owner of a construction company scaled from solo operator to $2M+ annual revenue, residential and commercial
  • ICC Plans Examiner — I review construction documents for code compliance as a discipline, not as a favor
  • I currently own the entire security profile of a live 18-month, nine-figure renovation: vendor and contractor credentialing at a rate of hundreds daily, site safety and compliance reviews, coordination of planned utility shutoffs each evaluated against safety and security risk, and a standing weekly working cadence with site operations and the renovation vendors — inside a resort still operating at occupancy
  • Full detail on Sheet 13
How I would execute it here

Every new site brought online in the region enters operations with security integrated from the construction phase — nothing retrofitted. Verified by a turnover checklist per site activation.

You are deploying gigawatts in months, not years. Security at a Fluidstack site is therefore not an operations problem that begins at handover; it is a deployment problem that begins in the drawing set and peaks during construction, when the site is valuable, crowded with trades, and not yet controlled. There are many security leaders who can run a finished site. There are very few who have been the general contractor on one.

08Part TwoMulti-Site Ownership

I have never owned one site.
I have owned portfolios.

Four times in seventeen years I have been handed responsibility for security across a set of places at once — a four-site federal hospital contract I built from nothing, a nightly patrol operation across a dozen properties, a 600-acre resort complex, and a mountain resort I had never seen until the day I ran it. The common thread is not the industry. It is accountability that does not stop at a property line.

1.0

The requirement

Fluidstack — Regional Security Operations Lead postingYou’ve owned physical security across multiple sites or a region, accountable for posture and incidents end to end.
2.0

The record

R-01Prudential Security (now Titan Security)Regional Security Manager, TexasJan 2014 – Jan 2016

Four VA hospital sites, built from the ground up. I was the first hire.

My first regional portfolio was healthcare for veterans — a contract guard force across four Department of Veterans Affairs hospital sites in Texas, held to federal facility security standards rather than to a client’s preference.

I did not inherit this program. I was the first hire on the contract and I built it. I wrote the post orders, hired and onboarded every officer who came after me, stood up the quality assurance program, and owned the client relationship across all four sites simultaneously.

For accuracy: I left before the contract came up for renewal, so I make no claim about how it was ultimately renewed.

  • Built a four-site federal contract program from a standing start as employee number one
  • Wrote and enforced post orders per site against a common contract standard
  • Ran QA inspections and corrected officer performance across locations
  • Learned the discipline that a federal standard is a floor, not a target
4
VA hospital sites
1st
Hire on the contract
2 yrs
Program ownership
R-02Independent armed patrol operationOwner / Operator2010 – 2020

Up to fifty officers deployed nightly across ten to fifteen properties

For a decade, concurrent with my police service, I ran an armed patrol operation providing deterrence and response to San Antonio–area properties. Every officer was a commissioned SAPD peace officer working an off-duty detail, engaged as an independent contractor. I personally handled contract negotiation, scheduling, post assignment, and payroll submission.

This matters for one specific reason: I have sat on both sides of a guard services contract. I know what a vendor does when a client stops inspecting.

10–15
Properties under nightly coverage
Up to 50
Officers deployed per night
~200
Officer bench, callable
10 yrs
Continuous operation
R-03JW Marriott San Antonio Hill Country Resort & SpaAssistant Director, Safety & SecurityJun 2025 – present

One security department across a 600-acre complex that behaves like several sites

The resort is not a building. It is 600 acres carrying a 1,000+ room hotel, a convention center, a water park, two golf courses, and retail — each with its own access profile, its own population, and its own failure modes. Twenty-two departments operate on that footprint. I own one of them, and my department’s posture covers all of it.

I carry an $8.5M operating budget across that footprint — plus capital expenditure submissions and a discretionary spending account for larger purchases — and staff it against demand that swings with occupancy rather than against a flat headcount.

600
Acres under posture
1,000+
Guest rooms
$8.5M
Operating budget
+ CapEx
Capital submissions & discretionary account
34
Officers on staff
9
Controlled vehicle access points
R-04Viewline Resort Snowmass, ColoradoInterim Director, Safety & SecurityFeb – Mar 2026

Dropped into an unfamiliar property on a corporate task force. Under three weeks to fix it.

Marriott selected me for a national interim executive task force and sent me to a property I had never walked, with a team I had never met, to stabilize a security operation across a resort that included an employee housing complex. I had under three weeks.

This is the closest analogue in my record to what a regional lead actually does: arrive at a site you did not build, read it fast, find what is actually broken, and fix it before you leave.

  • The property had no maps. I hand-drew the property, then digitized it, so that access points and posts could be named and referenced at all
  • Created a door naming convention — my own system — so every opening had a unique, logical identifier that an officer, a technician and an audit could all use
  • Built a grand master key program from scratch, with the hierarchy documented
  • Ran a property-wide re-key and a full lock and access-control audit, correcting Visionline/VingCard configuration errors I found during it
  • Wrote approximately 20 SOPs and supporting processes for a property that had none
  • Rebuilt the Lost & Found from the ground up
  • Snowmass offered me the permanent Director role at the end of the assignment.
3.0

What this does not cover

Limitation of scope

I have never held a portfolio of hyperscale data centers. My largest single footprint is 600 acres of resort; my largest true multi-site portfolio is four VA hospital sites, an order of magnitude below a gigawatt-scale region in consequence.

What I am claiming is the shape of the job — distributed accountability, posture I cannot see from where I stand, and incidents I own whether or not I was on site. Not the wattage.

4.0

Applied to a Fluidstack region

How I would run it

A region is not a set of sites, it is one posture expressed in several places. The first thing I would build is a common baseline — a single physical security assessment methodology run at every site in the cluster, findings ranked by risk and consequence rather than by how loud the site is about them, and a costed remediation plan I would hand you inside ninety days.

The second thing I would build is the thing that keeps a region honest: a published monthly metric set. Incidents, response times, access anomalies, post compliance, open findings, by site. If a site is drifting, you should not need me to tell you. You should be able to read it.

And I would do at every site what I did at Snowmass in under three weeks: walk it, map it, name every opening, and find out what is actually true rather than what the documentation says.

09Part TwoGuard Force Command

A guard force is a promise
somebody has to keep at 3 a.m.

I have run officers as an employer, as a contract manager, and as the vendor being inspected. Ten of those years I was the company a client could have fired. That is the perspective I bring to holding a contract guard force to a standard — I know exactly where the slack hides, because I have been the one responsible for not letting it.

1.0

The requirement

Fluidstack — Regional Security Operations Lead postingYou lead security teams and contract guard forces, setting and holding a high bar for discipline and professionalism.
2.0

The team I run today

G-01JW Marriott San Antonio34 officers, three shiftsCurrent

Thirty-four people, six posts that never go dark, and a staffing model tied to demand

My department is thirty-four people across day, afternoon, and night shifts — supervisors, officers, an EMT, an investigator, and administrative support. Six positions are staffed 24/7/365 as the floor. That floor is not a budget number, it is a risk decision, and it does not move.

Above the floor, deployment scales with occupancy: six posts at 60% occupancy or below, ten at 100%. Third-party vendors carry group security demand so that Marriott employees stay on the hotel operation. I am budgeted for 24.5 FTE against an operational demand of 31.1. Managing that delta honestly — in writing, with the risk stated — is a large part of the job.

34
On staff
6
Posts 24/7/365
10+
Posts at peak occupancy
24.5
Budgeted FTE
31.1
Demand FTE
$3.5M
Labor budget
G-02Prudential Security (now Titan Security)Contract guard force, four VA hospitals2014 – 2016

I was the first hire. I built the force I then managed.

A contract force is harder than an employed one. You are holding a bar for people whose paycheck you do not sign, inside a client’s building, against a scope somebody negotiated before you arrived.

At the VA contract I did not inherit that problem — I created the program that solved it. As employee number one across four hospital sites, I wrote the post orders, hired and onboarded the officers, and stood up the QA program, all to federal facility security standards.

G-03Independent armed patrol operationOwner / Operator2010 – 2020

Ten years on the other side of the clipboard

I was the vendor. Up to fifty commissioned peace officers deployed nightly across ten to fifteen properties, drawn from a callable bench of about two hundred, all engaged as independent contractors on off-duty details. I negotiated the contracts, built the schedules, assigned the posts, and submitted the payroll myself.

So when I write a guard vendor scorecard, I am writing it as someone who knows which metrics a vendor can quietly game and which ones they cannot.

3.0

How I hold the bar

G-04Standards in forceJW Marriott2025 – present

Discipline is a system, not a speech

  • Written post standards. 27 SOPs and roughly 95 documented processes, so “the bar” is a document an officer can be held to rather than a supervisor’s mood.
  • A RACI matrix across ~40 tasks, so no responsibility lives in the gap between two people who each assumed the other had it.
  • The “5/15” Base Officer visibility program — a deliberate standard for guest and employee contact that converts a static post into presence.
  • A tiered Emergency Response Team notification plan I built for incident response, so escalation is defined by severity rather than by whoever happens to pick up.
  • The Be Safe Committee, which I chair. The concept existed before me and had lapsed — nobody was running it. I revamped it and restarted it, cross-departmental, so safety findings come from the 22 departments who actually see them rather than only from my officers.
  • A hazard identification and safe-work-practice recognition tool I developed, so good practice gets caught and named, not just failures.
G-05JW Marriott San AntonioCapital and business cases2025 – present

Thirteen proposals to leadership. Eleven approved and funded.

Holding a standard costs money, and money means persuading people who do not work in security. I have built and presented thirteen proposals to leadership, of which eleven have been approved and funded — each with ROI and risk analysis attached.

Those include the armed-officer business case and a FY2027 capital proposal for perimeter intrusion detection. An 85% funding rate is not luck; it is what happens when a security argument is built to survive a finance conversation.

13
Proposals presented
11
Approved and funded
85%
Funding rate
4.0

Independent read

Q4 2025
Named Leader of the Quarter — first quarter of eligibility
National
Selected for Marriott interim executive task force
Offered
Permanent Director role at Snowmass after the interim assignment
5.0

What this does not cover

Limitation of scope

I have not managed a guard contract at hyperscale, multi-region scale. My largest contract force is four VA hospital sites; my largest employed team is thirty-four.

If your regional guard spend is an order of magnitude above that, what transfers is the method — written post standards, documented QA at a fixed cadence, a vendor scorecard the vendor cannot game, and a willingness to put a performance failure in writing. Not the headcount.

6.0

Applied to a Fluidstack region

First ninety days on the guard force

Post orders in force at every site in the region, signed by site leadership, written to the threat rather than inherited from the last contract. A guard force that cannot tell you why a post exists will not hold it at 3 a.m.

A vendor performance framework with teeth: measurable post standards, QA inspections at a published cadence, and a scorecard reviewed with the vendor monthly. Guard performance should be a number you can see before it becomes an incident you have to explain to a customer.

10Part TwoThe 2 A.M. Standard

I spent thirteen years
being the response.

Before I managed incident response, I was what showed up. Thirteen and a half years at the San Antonio Police Department — patrol, street crimes, gang unit, narcotics, intelligence, and a federal HIDTA task force as a detective. I am not describing a policy I wrote. I am describing what I did at 2 a.m. for over a decade, and then what I built so somebody else could do it well.

1.0

The requirement

Fluidstack — Regional Security Operations Lead postingYou’re as effective walking a perimeter at 2 AM as briefing executives on regional risk. … Experience handling end-to-end incident response processes.
2.0

The 2 a.m. half

I-01San Antonio Police DepartmentPatrol Officer → Detective → Task Force Officer → InstructorDec 2009 – May 2023

Thirteen years, six months. TCOLE ID 376951. Master Peace Officer.

I graduated top of my academy class, later served as academy president, and returned as an instructor. In between I worked patrol, Street Crimes, the Gang Unit, TAG, narcotics and intelligence, and served as a Task Force Officer on a federal HIDTA task force. I was also elected by my peers as a Police Association Representative.

13 yr 6 mo
Sworn service
5,142
Documented training hours
2,662
TCOLE course hours
2,480
Career / professional hours
Master
Peace Officer certification
I-02Federal caseworkEvidence, chain of custody, and prosecution2009 – 2023

Documentation that had to survive a U.S. Attorney and a federal grand jury

This is the part of my record that matters most for a company whose incidents will be investigated by people with subpoena power.

I handled evidence and maintained chain of custody to federal standards, and I prepared federal prosecution guides that were reviewed and approved by the United States Attorney’s Office and presented to a federal grand jury. That is the highest external bar my documentation has ever been held to, and it was cleared.

An incident report that cannot survive scrutiny is not a report, it is a liability. I learned that where the consequences were somebody’s liberty.

I-03Specialist trainingFBI Academy, Quantico and beyondVarious

The training behind the response

  • FBI Academy, Quantico — multiple courses, including hazardous materials, clandestine laboratories, and tactical entries
  • Advanced Surveillance Operations
  • FEMA / incident command and incident management training
  • Former licensed EMT — I have been the medical response, not just the person who called it
  • TCOLE Master Peace Officer, with Intermediate, Advanced and Master certificates issued February 2021
  • Platforms: Mark43 RMS, Axon digital evidence management — see Sheet 14 for the full list
3.0

The executive half

I-04JW Marriott San AntonioIncident response, crisis planning, emergency management2025 – present

Owning response instead of performing it

My job now is to make sure the response happens correctly when I am not the one running to it. That means incident response as a written process with defined roles, a Command Center that dispatches it, crisis response planning, and emergency management across a 600-acre footprint and twenty-two departments.

  • I built a tiered Emergency Response Team notification plan — escalation defined by severity, so the right people are woken up and the wrong people are not
  • I create, design, host and personally present active shooter tabletop exercises for our executive leadership and the Emergency Response Team. Not a vendor’s deck — mine, run by me
  • I built and delivered an armed-officer business case with ROI and risk analysis to leadership — one of thirteen proposals I have presented, eleven of which were funded
I-05Marriott InternationalNational interim executive task force2026

Selected to be the person sent when a site is in trouble

Marriott put me on a national task force of interim executives and deployed me to Viewline Snowmass. The selection is the point: when a property’s security operation needed stabilizing, I was who they sent. The property offered me the permanent Director role at the end of it.

4.0

What this does not cover

Limitation of scope

My incident response experience is physical and criminal. I have not run a joint physical/cyber incident inside a CISO organization, and I have never responded to an incident where the asset at risk was model weights.

That is a real gap and I will not paper over it. What I would bring to it is thirteen years of habit around evidence, federal-standard chain of custody, timeline reconstruction, and interviewing — which is most of what the physical leg of a weight-exfiltration investigation actually consists of — and the willingness to be the junior voice in the room on the logical side until I have earned otherwise. The dated plan for closing it is on Sheet 14.

5.0

Applied to a Fluidstack region

The standard I would set

One incident response process across the region, tested by tabletop at every site inside six months, with a documented after-action for each. A process that has never been run is a document, not a capability. I already write and run these exercises personally for an executive audience.

And a rule I hold personally: I walk the perimeter at 2 a.m. Not as theater — because the posture you have at 2 a.m. on a Sunday is your real posture, and it is never the one in the daytime briefing.

11Part TwoStandards & Audits

Standards are the only thing
that scales across sites.

Everything else — instinct, relationships, the fact that you personally noticed something — stops at the property line. A written standard travels. So does an audit finding. This sheet is what I have standardized, the three separate audits I am measured against, and the frameworks I have never run, each with a date attached.

1.0

The requirement

Fluidstack — Regional Security Operations Lead postingYou standardize SOPs and post orders across sites without losing the on-site instinct for what each facility actually needs. … You’ve carried security commitments to enterprise customers through audits and contractual obligations.
2.0

What I have standardized

D-01JW Marriott San AntonioDocumentation estate2025 – present

Twenty-seven SOPs, ninety-five processes, forty RACI tasks

When I arrived, the operation ran on institutional memory. It now runs on documents. I rewrote and expanded the SOP set to 27 standing procedures covering roughly 95 documented processes, and built a RACI matrix across about 40 tasks so that no responsibility lives in the gap between two people who each assumed the other had it.

The occupancy-based deployment model is itself a written standard rather than a supervisor’s judgment call — six posts at or below 60% occupancy, scaling to ten at 100%, with six manned 24/7/365 as a floor the model is not permitted to breach.

27
Standing SOPs
~95
Documented processes
~40
RACI tasks
3
Separate audit regimes
D-02Viewline Resort SnowmassBuilt from nothingFeb – Mar 2026

Roughly twenty SOPs for a property that had zero — in under three weeks

Snowmass is my evidence for both halves of the requirement at once. The property had no security SOPs and no property maps. I wrote approximately 20 SOPs and supporting processes, hand-drew and then digitized the property so locations could be referenced at all, created a door naming convention, and built a grand master key program.

That is standardization built from a blank page under time pressure — which is closer to a greenfield site activation than anything else on my résumé.

D-03Prudential Security (now Titan Security)Four VA hospital sites2014 – 2016

Standardizing across sites, to somebody else’s standard

Federal facility security standards across four hospital sites is where I learned that standardization is not sameness. Each site got post orders written to its own layout, population and risk — against one contract standard that did not bend. The QA program is what kept those two things from drifting apart. I built all of it as the first hire on the contract.

3.0

Three audits, three control sets

The JW Marriott security department is measured against three separate audit regimes, each with its own controls. Running one department against three different control sets simultaneously is the closest thing in my record to carrying enterprise customer commitments across a region.

AuditWho runs itDifferent controls, same department
Brand Standard AuditMarriott brandBrand-defined safety and security standards. Most recent result: 100% compliance.
Owner AuditProperty ownershipOwnership’s own control set — asset protection, liability and financial exposure.
Marriott Corporate AuditMarriott corporateCorporate control set, distinct from the brand standard.
4.0

Executive commitments

D-04Proposals to leadershipJW Marriott2025 – present

Thirteen presented. Eleven approved and funded.

Every one carried ROI and risk analysis. They include the armed-officer business case and a FY2027 capital proposal for perimeter intrusion detection — which is to say I have already written a PIDS requirement and its business case, even though I have not yet commissioned a system.

This is the executive-facing muscle the role needs: constructing a security argument that survives scrutiny from people who do not work in security.

13
Proposals presented
11
Funded
85%
Approval rate
5.0

Framework position, with dates

FrameworkStatus todayPlanClosed by
SRMP-C — Security Risk Management ProfessionalHeldIssued by INSSA, valid three years from July 2026
Federal facility security standardsOperated toFour VA hospital sites, 2014–2016
ICC Plans ExaminerCertifiedCode review of construction drawings
ASIS CPPNot yet heldBoard exam, sat within the contract yearDay 365
ISO 27001Not heldImplementer-level training, self-fundedDay 270
SOC 2 Type IINever run oneOwn the physical security evidence package for one real customer audit cycleDay 270
NIST CSF / 800-53Not ownedMap the regional physical control set to the relevant familiesDay 180
Data center infrastructure credentialNot heldUptime-equivalent tier/design credential, self-fundedDay 270
ASIS PSPNot heldAfter CPPPost-term
6.0

What this does not cover

Limitation of scope

I have never personally run a SOC 2 Type II examination, an ISO 27001 certification cycle, a NIST CSF or 800-53 assessment, or a DoD-standard program. If carrying an enterprise customer through one of those in the first quarter is the job, I am not the finished article and you should know that before you decide.

What I have done is be the accountable person in three concurrent audit regimes where failing had a commercial consequence, and pass. The framework I would have to learn — on the dates above, at my own cost. The posture of being audited I already have.

7.0

Applied to a Fluidstack region

What I would produce

A single regional SOP set in force inside six months — access management, visitor and vendor control, incident response, guard post standards — with site-specific annexes rather than site-specific reinventions.

And a customer-facing security package: audit-ready documentation, evidence artifacts, and a standard site tour. When a customer asks how you control access to the hall their weights are training in, the answer should already be written, already be evidenced, and already be the same at every site in the region.

12Part TwoSecurity Systems

Here is the line between
what I have touched and
what I have only designed around.

Most candidates blur this. I am printing it, because you are a CISO and a physical security engineer and you will find the line in the first ten minutes anyway. Finding it in my own document should tell you something about how I will report a finding you do not want to hear.

1.0

The requirement

Fluidstack — Regional Security Operations Lead postingBonus: Physical security systems fluency (ACS, VMS).
2.0

Every platform, stated honestly

PlatformDepthWhat that actually means
Access control & physical security
DormakabaHands-onDaily administration, credential lifecycle, troubleshooting
Safelock / AmbianceHands-onAdministration and maintenance in a live operation
Visionline / VingCardHands-onFull lock and access audit at Viewline Snowmass; corrected configuration errors myself
Key CommanderHands-onKey system administration and control
KeyWatcherHands-onElectronic key management with two-person authorization to issue
Amano OneHands-onParking and vehicle access administration
Milestone (VMS)Hands-onVideo management in daily operational use across 500+ CCTV devices
License plate recognitionHands-onVarious platforms across nine controlled vehicle access points
Operations, records & evidence
Mark43 RMSHands-onSAPD records management — case reporting and records to a standard that had to survive prosecution
AxonHands-onBody-worn camera and digital evidence management, with chain of custody
MS ShiftHands-onSafety, security and operations platform — dispatch, incident capture, reporting
RelayDashHands-onOperational dispatch and task management
Design-fluent, not hands-on
Lenel OnGuardDesign-fluentCan specify to it and read its architecture. Have not administered it.
Genetec Security CenterDesign-fluentFluent in the design conversation, not the console.
C•CURE 9000Design-fluentSame.
PSIMDesign-fluentUnderstand the integration model; have not deployed one.
Perimeter intrusion detection (PIDS)Specified, not commissionedI authored and submitted a FY2027 capital proposal for perimeter intrusion detection. I have written the requirement and the business case; I have not yet commissioned a system.
3.0

Scale administered

S-01JW Marriott San AntonioAccess control & surveillance estateCurrent

The estate I administer today

I own the administration, expansion, maintenance and audit of this estate. I want to be precise about one thing: I did not design or specify the access control system in place here. It was inherited. What I own is everything that happens to it after the install — which, over a system’s life, is most of what determines whether it actually works.

1,500+
Electronic access control points
~2,000
Doors
500+
CCTV devices
~150
Access points
9
Controlled vehicle access points
S-02JW Marriott San AntonioCommand CenterStood up 6 March 2026

I built the room

I consolidated CCTV monitoring, alarm annunciation, fire suppression controls and dispatch into a single unified Command Center and put it into service on 6 March 2026. The consolidation took three staffed positions down to two — a 33% reduction — while increasing what a single operator can actually see.

This is the piece of my record closest to what you would ask me to stand up at a site: taking scattered monitoring and turning it into one place where somebody is accountable for noticing.

3 → 2
Staffed positions consolidated
33%
Position reduction
Mar 2026
In service
S-03Viewline Resort SnowmassAccess control build, audit & reconfigurationFeb – Mar 2026

The hands-on system work — from a blank page

This is where my direct configuration experience actually lives, and it was not just administration. The property had no maps and no key hierarchy.

  • Hand-drew the property and digitized it, so openings could be located and referenced at all
  • Created a door naming convention — my own system — giving every opening a unique identifier usable by an officer, a technician and an auditor alike
  • Built a grand master key program from scratch, with the hierarchy documented
  • Ran a property-wide re-key and a full lock and access-control audit
  • Identified and corrected Visionline/VingCard configuration errors myself, at the console
  • Footprint was far smaller than 1,500 points — but the work was mine, not delegated
4.0

The access control standard I own

S-04Written standard, in force

A platform list tells you what I have clicked. A standard tells you how I think about entitlement.

  • Least-privilege, role-based provisioning — with written approval required for restricted areas
  • Two-person authorization on every credential. No single person can grant access at this property — two people sign off to issue a credential, and two-person authorization is required to release a key from electronic key management
  • Two-person integrity sign-off across HR, Security and Engineering/IT
  • Immediate deactivation on separation. Not same-day. Immediate.
  • Annual entitlement review — every credential mapped to a named owner and an approval record
  • Visitor badging and escort discipline
  • Vendor staging and dock-only routing, so contractor access is a defined path rather than a courtesy
5.0

What this does not cover

Limitation of scope

I have not administered an enterprise ACS/VMS stack of the class you are likely running — Lenel, Genetec or C•CURE at regional scale. I can specify to those platforms, read their architecture, and hold an integrator accountable to a design. I would be learning the console, on the dated plan on Sheet 14.

On perimeter intrusion detection: I have written the requirement and the business case — a FY2027 capital proposal for PIDS is submitted at my current property — but I have not commissioned a system.

I am not going to tell you that hospitality access control is the same as data center access control. It is not. The credential lifecycle discipline transfers; the platform depth I would have to earn, and I would rather earn it on your clock at a reduced rate than have you find out about it after the offer.

6.0

Applied to a Fluidstack region

First ninety days on the systems

A 100% access control entitlement audit across the region: every credential mapped to a named owner, an approval record and a current business justification. Every orphaned credential closed. This audit finds something in every environment it has ever been run in, and it is the cheapest posture improvement available at any site.

Then device-level verification against design intent rather than against an install checklist. A camera that is online is not a camera that covers what the drawing said it would cover. I would walk it — and where there is no drawing, I would draw it, the way I did at Snowmass.

13Part TwoConstruction to Operations

Most security leaders inherit
a building. I have built them.

This is the part of my record that does not appear on other candidates’ résumés. I own a construction company. I hold an ICC Plans Examiner certification. And I currently own the entire security profile of a live, eighteen-month, nine-figure renovation with hundreds of vendors on site every day. Fluidstack acquires power, designs and builds data centers, and operates them — I have done the middle part of that sentence for a living.

1.0

The requirement

Fluidstack — Regional Security Operations Lead postingPartner with site operations, facilities, construction, and vendors to integrate security into every phase of the region’s growth.
2.0

The record

C-01JMH Construction / Villabuilt Custom Homes / RE Services LLCOwner & Operator2022 – present

Solo operator to $2M+ annual revenue, residential and commercial

I built a construction business from nothing to over $2M in annual revenue across residential and commercial work, including a contracting arrangement with American Woodmark under RE Services LLC. I have negotiated with subs, held trades to a schedule, read and corrected drawing sets, and been personally liable for what got built.

For transparency about my commitments: I am closing this business once my current build finishes. I am not carrying it into this role.

$2M+
Annual revenue at peak
4 yrs
Owner / operator
Res + Comm
Project types
C-02International Code CouncilPlans ExaminerCertified

I can read the drawing set before it is a building

A plans examiner certification means I review construction documents for code compliance as a discipline, not as a favor. In a security context that is the difference between specifying a door and knowing whether the conduit to reach it exists in the drawing you are about to approve.

C-03JW Marriott San AntonioSecurity profile of an active renovationOngoing, 18 months

A nine-figure renovation, running inside an operating resort

The property is mid-way through an eighteen-month renovation in the several-hundred-million-dollar range, and I own the entire security profile of it while the resort continues to operate at occupancy.

  • Vendor and contractor control and credentialing — hundreds of vendors credentialed daily
  • Site safety and compliance reviews across active construction areas
  • Coordination of planned utility shutoffs, each evaluated against safety and security risk before it happens
  • Maintaining guest-facing posture at a property that is simultaneously a construction site
  • A standing weekly cadence with site operations and the renovation vendors — not a status email, a recurring working session where security is in the room while decisions are still reversible
3.0

Greenfield versus brownfield

GreenfieldBrownfield / live site
What sets the paceThe construction schedule. Security either lands in the drawing set or it gets retrofitted at ten times the cost.The operation. You cannot take a door out of service because your standard says so.
Where risk concentratesThe window between first perimeter and first credentialed access — when the site is valuable, populated by trades, and not yet controlled.The credential population and the vendor path. Both grow quietly until somebody audits them.
The failure modeSecurity shows up at commissioning and discovers the conduit was never pulled.Everyone assumes the inherited system does what it did the day it was installed.
My groundingGeneral contractor and ICC Plans Examiner — I read the drawing set before it is built.The JW Marriott renovation: hundreds of vendors credentialed daily inside a running operation.
4.0

The sequence I run on a build

  1. Define threat and consequence first — Before a single line is drawn. What is actually being protected, from whom, and what does losing it cost? Everything downstream is an answer to this question or it is decoration.
  2. Read the site, not the plan — Terrain, approach routes, sightlines, utility and fiber ingress, neighbors, and how somebody would actually get to the thing that matters.
  3. Layer to deter, detect, delay, respond — With delay budgeted explicitly against real response time. A ten-minute delay is a failure if response is fifteen.
  4. Examine the drawing set — Door schedules, hardware, conduit and pathway, camera sightlines against final landscaping and lighting. This is where my plans examiner certification earns its keep — the cheapest security fix is a redline before pour.
  5. Secure the construction phase itself — Perimeter before steel. Credentialing, materials and lay-down control, badge and escort discipline for trades. A site is at its most exposed while it is being built.
  6. Commission against design intent — Not against an install checklist. A device that is online is not a device that does what the drawing promised. Test it against the threat it was specified for.
  7. Activate the human layer — Post orders, staffing model, training, and a tabletop exercise before turnover, not after the first incident.
  8. Turn over with metrics already running — Audit cadence set, entitlement review scheduled, incident and response metrics baselined on day one. A site that goes live without a baseline can never prove it improved.
5.0

What this does not cover

Limitation of scope

I have not built a data center. I have not sat in a design review for a hall, a meet-me room, or a substation, and I do not have the vocabulary of your build teams yet.

What I have is the thing that is harder to teach: I have stood on a job site as the person responsible, read the set, argued with a sub about a detail, and watched what happens when security is added after the concrete cures. Your build teams will not have to explain construction to me. They will have to explain data centers to me, and I will learn that faster than a data center person will learn how to run a job.

6.0

Why this is the strongest argument I have

The case in one paragraph

You are deploying gigawatts in months, not years. That means security at a Fluidstack site is not an operations problem that begins at handover — it is a deployment problem that begins in the drawing set and is most acute during construction, when the site is valuable, crowded with trades, and not yet controlled.

There are a lot of physical security leaders who can run a finished site. There are very few who have been the general contractor, hold a plans examiner certification, and are currently running security for a nine-figure build inside a live operation. That intersection is the reason I am writing to you at all.

14Part TwoWhat I Don’t Have

Here is what I don’t have,
the dated plan to fix it,
and what it costs me.

Your posting lists four bonus qualifications. I have three of them and I am missing the first one entirely. Rather than argue around that, this sheet scores all four honestly, itemizes every security platform I have and have not touched, and then commits to a dated plan — with my own money attached — that closes every deficiency I have inside the contract term.

1.0

The four bonus items, scored

Bonus item, as postedHonest scoreThe facts
Hyperscale or data center securityDo not have it.None. Not adjacent, not translatable — absent. This is my single largest deficiency and it is likely the reason your team said no. Closure plan below.
Guard force vendor management at scaleHave it — both sidesBuilt and managed a contract guard force across four VA hospital sites to federal facility security standards, as the first hire on the contract. And I was the vendor for ten years: up to 50 officers deployed nightly across 10–15 properties. Caveat: not at your spend scale. Sheet 09.
Physical security systems fluency (ACS, VMS)Partial — itemized below1,500+ access control points and 500+ CCTV devices administered daily; built a grand master key program and a door naming convention from scratch at Snowmass. But the enterprise platforms you most likely run are design-fluent for me, not hands-on. Sheet 12.
Multi-site or regional leadershipHave itFour portfolios across seventeen years. Regional Security Manager over four Texas VA hospital sites; ten years running nightly coverage across 10–15 properties; 600 acres and 22 departments today. Sheet 14.
2.0

Every security platform, itemized

You asked for systems fluency. Here is the complete list — access control and physical security, then operations, records and evidence, then the platforms I am design-fluent on but have not administered. The line is printed rather than blurred.

PlatformDepthWhat that actually means
Access control & physical security
DormakabaHands-onDaily administration, credential lifecycle, troubleshooting
Safelock / AmbianceHands-onAdministration and maintenance in a live operation
Visionline / VingCardHands-onFull lock and access audit at Viewline Snowmass; corrected configuration errors myself
Key CommanderHands-onKey system administration and control
KeyWatcherHands-onElectronic key management with two-person authorization to issue
Amano OneHands-onParking and vehicle access administration
Milestone (VMS)Hands-onVideo management in daily operational use across 500+ CCTV devices
License plate recognitionHands-onVarious platforms across nine controlled vehicle access points
Operations, records & evidence
Mark43 RMSHands-onSAPD records management — case reporting and records to a standard that had to survive prosecution
AxonHands-onBody-worn camera and digital evidence management, with chain of custody
MS ShiftHands-onSafety, security and operations platform — dispatch, incident capture, reporting
RelayDashHands-onOperational dispatch and task management
Design-fluent, not hands-on
Lenel OnGuardDesign-fluentCan specify to it and read its architecture. Have not administered it.
Genetec Security CenterDesign-fluentFluent in the design conversation, not the console.
C•CURE 9000Design-fluentSame.
PSIMDesign-fluentUnderstand the integration model; have not deployed one.
Perimeter intrusion detection (PIDS)Specified, not commissionedI authored and submitted a FY2027 capital proposal for perimeter intrusion detection. I have written the requirement and the business case; I have not yet commissioned a system.
3.0

Scale administered today

1,500+
Electronic access control points
500+
CCTV devices
~2,000
Doors
9
Controlled vehicle access points
2-person
Authorization required on every credential and key
Mar 2026
Command Center in service, 3 positions to 2
4.0

The deficiency closure plan

Every gap above, with a method, a cost to me, and a date. The operational gaps close by Day 180; the credential-dependent ones by Day 270, and the board certification by Day 365 — deliberately, because I am not going to miss nine other dated commitments while studying for an exam.

I have kept the specific programs unnamed on purpose. I want the latitude to pick the route that actually teaches the most, including non-traditional or no-cost ones, rather than being held to a course catalogue I chose before I saw your estate.

#DeficiencyHow I close itMy costClosed by
D1No hyperscale or data center security experienceTwo tracks. Immersion: shadow the build and critical facilities teams at every site in the region and document the power, cooling and hall architecture myself rather than being briefed on it. Credential: a recognised data centre infrastructure / tier design credential, or a demonstrably equivalent program — I want latitude to pick the one that actually teaches the most, including non-traditional or no-cost routes.$3,000–7,000Immersion Day 180
Credential Day 270
D2No hands-on enterprise ACS/VMS (Lenel, Genetec, C•CURE)Vendor-led administrator-level certification on whichever platform is actually in the Fluidstack estate — console-level, not overview-level. Vendor and integrator training routes are often bundled with an install, so this may cost less or nothing.$0–4,000Day 180
D3No SOC 2, ISO 27001 or NIST cycle personally ownedImplementer-level information security management training, plus I own the physical security evidence package for one real customer audit cycle end to end rather than supporting someone else’s. The training I pay for; the audit is the job.$1,500–3,500Training Day 270
NIST control mapping Day 180
D4No ASIS board certificationCPP board exam, sat within the contract year. I am deliberately not front-loading this — I am not going to spend my first six months studying when I have nine other commitments with dates on them.$1,000–1,500Day 365
D5Never commissioned a perimeter intrusion detection systemPartial credit already: I authored and submitted a FY2027 capital proposal for PIDS at my current property, so I have written the requirement and the business case. What I have not done is commission one. I would participate in the commissioning of at least one perimeter system in the region, at device level, against design intent.Day 180, or first commissioning
D6Never responded to an incident where the asset was model weightsBuild and run the physical leg of a joint physical/cyber tabletop with your security engineering team — I already write, host and present active shooter tabletops for executive leadership, so the exercise craft is there; the threat model is what I need. And be the junior voice in the room on the logical side until I have earned otherwise.Day 180
5.0

What this costs me

$5,500
Low estimate, out of my pocket
$16,000
High estimate, out of my pocket
$21,000
Salary I am leaving on your table in year one
4 of 6
Deficiencies I fund myself

Costs are my own estimates and will move. The point is not the exact figure — it is that closing my gaps is not a line item I am asking you to approve. Between the discounted salary and the training I fund myself, I am putting somewhere between $26,500 and $37,000 of my own money behind the claim that I can do this job. That is the strongest signal of confidence I am able to send you, and it is the reason I think this proposal is worth twenty minutes rather than a polite decline.

6.0

What I am not promising

Limitation of scope

I am not promising that a year of deliberate work makes me equivalent to someone who has run hyperscale physical security for a decade. It does not, and anyone who tells you otherwise is selling.

What I am promising is that the deficiency stops being a reason to worry about me — because it will be documented, dated and closed against evidence you can inspect — while the things I already bring that are hard to hire for are there from week one.

And that if I am wrong about that, you exercise the month-six off-ramp on Sheet 01 and it costs you nothing but the discounted salary you already paid.

Contents