Kinda Chic to Prioritize with Proof
In 2014, I graduated from the University of Texas and moved to San Francisco. The tech bubble was at its peak, but my resume up to that point was working in the kids' section at Nordstrom, interning at a cosmetics company over the summer, and being a self-proclaimed professional daughter — a role I still hold, and am now raising the next generation into.
But I mention this because people ask me a lot about how I got into the security space, usually somewhere in the middle of a conversation about cyber risk, vulnerability management, quantification, or the fact that I've worn lots of hats across product, solution architecture, sales, and marketing. I actually went to school for chemical engineering and I can assure you I didn’t know what a vulnerability was back then. That changed the day a recruiter put an entry-level role in front of me at a startup called Risk I/O — later known as Kenna Security. I started learning how to talk about risk, and if you believe in chaos theory, you'll appreciate that this post is the end (and a beginning) of a chain of events that started 12 years ago.
I couldn't be more excited to announce I'm joining Empirical Security as Director of Growth — working with many of the very same people who got me started on this journey over a decade ago.
The technical chops here speak for themselves through the people behind it, so I'll add my own angle instead. I've spent years working alongside security teams, helping them figure out why one finding or control mattered more than another. And almost everyone was starting from the same broken place: a score that was never designed to know anything about the organization looking at it. A 7.5 out of 10 looks the same whether it was exploited yesterday or never at all — whether you're a hospital or a hotel chain, whether that exposure is wide open to the internet or buried three layers behind controls nobody's touched in years.
And the exposures keep growing. Thanks, AI. But volume was never the real problem. The question was never who can fix the most — it's who can fix what actually matters. That's the whole premise Empirical is built on, and it's exactly what this industry needs.
But no technology means much without the right people behind it — most enterprise security leaders have learned that one the hard way. So why Empirical? The technology solves a problem I watched go unsolved for a decade, and I want to be a part of the answer. And the people behind it are some of the smartest, most genuine people I know — people I've already spent years trusting. Win-win, as they say.
2014 me is very excited to see what 2026 me is up to!