I am an architect. Not in the sense of having a corner office and strong opinions about open-plan layouts, but in the sense that I build risk and resilience infrastructure from the ground up, in environments where it does not yet exist, under conditions that do not always make this easy. This has been the pattern across every role I have held.
I work at the intersection of risk strategy, technology, and organizational behaviour. My domain is the space between what an organization thinks its risk exposure is and what it actually is. That gap is almost always larger than anyone is comfortable admitting, and closing it requires a combination of methodology, systems thinking, and the willingness to say things that are inconvenient to hear. I have developed proprietary frameworks and published methodology in this space. I have also spent considerable time explaining to people why their existing frameworks are measuring the wrong things. Both activities are necessary.
My work spans enterprise risk, ICT risk, operational resilience, business continuity, crisis management, geopolitical risk, and governance. I move between strategic design and operational execution without losing the thread. I develop methodology, translate complex risk signals for executive and board-level audiences, and build the kind of frameworks that are meant to be used rather than filed. I regularly advise at C-suite level. The title has not always matched the level of the work. I have found this more motivating than frustrating.
I think in systems. I stay until the thing works. I have solved problems that had been stalled for years, not because I am uniquely gifted, but because I ask different questions and do not stop when the first answer is inconvenient.