About

I'm the Product Security Officer at Carl Zeiss Meditec, Inc. I guide security engineers across the US R&D portfolio through threat modeling, vulnerability assessment, risk registers, and the security deliverables required at each product milestone.

My route into product security was indirect. I went to law school expecting to practice, then found that I cared more about how technical rules work in real organizations. Privacy consulting led to cloud security at Optimizely, and then to medical-device security at ZEISS in 2023. The legal training still helps. It made me careful about the difference between a rule on paper and a decision a team can actually use.

I chair the global ZEISS Security Engineer program, a monthly working group of 40 engineers. I also build the security-assessment tooling my team runs on. One shipped module enriches software bills of materials with the end-of-support data FDA review requires, and it is now used globally.

Outside ZEISS, I built Graphletter, an open-source GRC product that uses LLMs to compare organizational evidence with control objectives. BarPlaybook applies the same evaluation discipline to bar-exam essays. CRISC (ISACA, 2025). JD from UC Law SF, BA from George Washington. Based in the San Francisco Bay Area.

Domains

Product security governance
FDA cybersecurity review
IEC 81001-5-1
ANSI/AAMI SW96
HIPAA
Threat modeling
Vulnerability assessment
SBOM lifecycle management
Customer security assurance
M&A cybersecurity due diligence
Security tooling automation
TypeScript
Python
Node.js
PB

Peter Boaz

San Francisco, CA