Technology leadership and risk governance, without the full-time overhead.
I help growing companies run secure, well-governed technology operations — stepping in as a fractional CTO to lead infrastructure and IT strategy, or as a fractional GRC lead to build out risk, compliance, and third-party vendor programs.
Two disciplines. One accountable partner.
Engage me for ongoing fractional support or a defined-scope project — whichever matches where your organization is today.
IT & Infrastructure Leadership
Hands-on technology leadership for companies that need senior direction without a full-time executive hire.
- IT strategy, roadmap, and budget ownership
- Data center, cloud, and infrastructure operations oversight
- Business continuity & disaster recovery planning
- Vendor, MSP, and internal team management
- Capacity planning and system reliability (uptime, monitoring, redundancy)
- Technology due diligence for M&A and vendor consolidation
Governance, Risk & Compliance
Practical GRC programs built around recognized frameworks — sized to your team, not a Fortune 500 department.
- Third-party / vendor risk management program design
- SOC 2, ISO 27001, NIST 800-53 & NIST CSF control mapping
- Security questionnaires, SIG assessments & residual risk reporting
- Executive and board-level risk reporting
- Policy, process & procedure development
- GRC tooling: ServiceNow VRM, OneTrust, RiskRecon, BitSight
Built for accountability, not busywork
Framework-grounded
Every engagement maps to recognized standards — NIST 800-53, NIST CSF, FFIEC, PCI, ISO 27001, SOC 2 — so controls hold up to audit and stakeholder scrutiny.
Metrics over meetings
Programs are run against clear SLAs and measurable outcomes: risk closure rates, uptime targets, and backlog reduction — not status theater.
Executive-ready reporting
Risk and operational posture communicated in language business stakeholders and boards can act on, not just technical teams.
Experience
Track record leading IT operations and third-party risk programs at a global SaaS platform and a $1B+ financial institution.
Third-Party Risk Manager
Led combined US/India teams to close 100% of open vendor risk items within SLA; built Autodesk's third-party AI risk criteria and 3-year TPRM strategy; delivered quarterly risk reporting to the executive committee.
Associate Vice President, IT Service Delivery
Owned all data center operations and cybersecurity programs for a $1B+ credit union; maintained 99.99% uptime; managed six internal and external teams; built the credit union's first secure ACH transmission room and 24/7 incident response operation.
IT Service Delivery Manager & IT Operations Manager
Wrote the credit union's first disaster recovery plan, led a 50+ application data center migration, deployed its first Web Application Firewall, and migrated critical infrastructure from Windows Server 2003 to 2016.
Certifications
Ready to bring senior IT and GRC leadership in-house — fractionally?
I take on a limited number of clients at a time so every engagement gets real attention. Reach out to discuss scope, cadence, and fit.
What is Bakol?
Rabbinical scholars debate whether Avraham had a daughter, based on the line that he was "blessed in all things." The interpretation is fascinating to me and has always struck me with the curiosity, intelligence, and aliveness we can bring to the world to take a simple sentence and create justice with it.
Fortunately, I was blessed with two daughters who do not need abstract intelligence to be perceived or understood — and so I too feel "blessed in all things."
Further reading: judaism.stackexchange.com