About
I'm the Product Security Officer at Carl Zeiss Meditec, Inc. I guide security engineers across the US R&D portfolio through threat modeling, vulnerability assessment, risk registers, and the security deliverables required at each product milestone.
My route into product security was indirect. I went to law school expecting to practice, then found that I cared more about how technical rules work in real organizations. Privacy consulting led to cloud security at Optimizely, and then to medical-device security at ZEISS in 2023. The legal training still helps. It made me careful about the difference between a rule on paper and a decision a team can actually use.
I chair the global ZEISS Security Engineer program, a monthly working group of 40 engineers. I also build the security-assessment tooling my team runs on. One shipped module enriches software bills of materials with the end-of-support data FDA review requires, and it is now used globally.
Outside ZEISS, I built Graphletter, an open-source GRC product that uses LLMs to compare organizational evidence with control objectives. BarPlaybook applies the same evaluation discipline to bar-exam essays. CRISC (ISACA, 2025). JD from UC Law SF, BA from George Washington. Based in the San Francisco Bay Area.
Domains
Peter Boaz
San Francisco, CA