Enterprise architecture for cyber exposure decisions

Alfe Corona turns cyber exposure into clear risk decisions.

I help CISOs and enterprise teams identify which risks matter, who should resolve them, and what evidence proves they were controlled.

Proof
1,000+ vulnerabilities moved toward closure
Method
Signals, context, owners, evidence
Outcome
Clearer risk decisions

Start here

Choose the view that matches your role.

Same work, explained at the level you need. The flagship architecture is demonstrated against Atlas Meridian Bank, an entirely fictional synthetic enterprise, not a real institution.

Experience and credentials

Experience and results.

A summary of my experience, credentials, and selected results, with links to my résumé and portfolio for more detail.

10+ yearsCybersecurity, cloud, infrastructure, and enterprise technology
20+ professionalsLed and developed technical teams in high-accountability settings
99.6% inventory validityMeasured asset-control outcome from accountable enterprise operations
Selected experience

A career shaped across large-scale finance, technology, and national service.

Review résumé

Professional recommendations

What colleagues and leaders say.

Perspectives from people who have managed my work or collaborated with me.

Caryn Woodruff

Caryn Woodruff

Former direct manager

Alfe is a skilled security and compliance professional. He possesses excellent problem-solving and analytical skills and is able to effectively identify and mitigate potential risks and vulnerabilities.

LinkedIn

Ami Diaz, CRISC, CDPSE

Ami Diaz, CRISC, CDPSE

Former direct manager

His work is meticulous and conclusions are well-developed. He also shares insights and best practices with his peers. He was a great asset to the team.

LinkedIn

Ryan Inagaki

Ryan Inagaki

Former colleague

During his tenure, I was consistently impressed by his deep understanding of the industry's best practices and regulations.

LinkedIn

Joel Pichardo

Joel Pichardo

Cybersecurity peer

Alfe is the kind of cybersecurity expert you hope to have on your team.

LinkedIn

View recommendations on LinkedIn

Operator perspective

How I work when the problem is messy.

At a prior enterprise organization, leaders needed a fast view of unresolved vulnerability work across several remediation campaigns.

I combined dashboard views, ownership data, and frontline input, then narrowed the view to overdue work that was still open. Leaders gained an actionable starting point, while technical owners received tailored follow-up. I lead with composure, respect, transparent data, and explicit success criteria so people know what needs to happen and why.

Alfe Corona, enterprise cyber exposure architecture practitioner

Security leadership perspectives

CyberTainment TV

Short, direct perspectives for CISOs, security architects, and the leaders accountable for resilient security programs, grounded in operational experience rather than vendor messaging.

Watch the series on YouTube

Featured episode

Why Your Vulnerability Spreadsheet Is the Breach.

An operator's view of why exploitability, business context, and continuous validation matter more than compliance theater.Watch episode

Approach

Security work gets clearer when architecture, risk, and execution share the same map.

The strongest exposure programs make hard choices visible: which systems matter most, where the paths of exploitation concentrate, what ownership model will actually hold, and how to explain progress without hiding uncertainty.

Architecture over tool sprawl

Evidence before escalation

Business impact before severity theater

Controls that operators can sustain

Direct answers

The questions I hear most.

What is cyber exposure architecture?

Cyber exposure architecture is the enterprise security architecture discipline that connects assets, identities, vulnerabilities, controls, business criticality, and remediation ownership into one operating model. It helps leaders see how exposure becomes business risk and where control improvements should happen first.

How do organizations prioritize vulnerabilities by business risk?

Risk-based vulnerability prioritization blends exploitability, exposure path, asset importance, compensating controls, data sensitivity, and accountable ownership. The goal is not to chase every severity label equally, but to direct remediation toward the exposures most likely to create material business impact.

How does exposure control connect engineering, architecture, and executives?

Exposure control gives security engineers a defensible remediation path, gives enterprise architects a control and dependency map, and gives CISOs a clearer executive cyber risk reporting story. It turns technical findings into practical decisions about resilience, investment, and transformation.

What does evidence-gated closure mean?

A finding should not close just because a ticket says it is done. Evidence-gated closure means newer validation data must confirm the exposure is resolved or acceptably controlled; otherwise the work returns to remediation.

For an interactive proof point, review the Exposure Control portfolio for cyber exposure management and risk-based vulnerability prioritization.

Optional project walkthrough

Explore the project on your terms.

Start with the portfolio, then use ASTA to compare lifecycle decisions, validation gates, and closure evidence without leaving the public project boundary.

Optional, source-linked guide

Synthetic project reference

Connect

Start a conversation.

For collaboration, advisory conversations, speaking, architecture exchange, recruiting, or professional introductions, the preferred path is the relationship brief. It gathers useful context while keeping sensitive information out of the conversation.

Start Relationship Brief