Peter Boaz

Product Security & GRC

San Francisco Bay Area


Profile

Product security operator-builder with 10+ years in regulated environments. At ZEISS Medical Technology, I guide US R&D teams through threat modeling, vulnerability assessment, risk registers, and security deliverables at each product milestone. I chair a global program of 40 security engineers, own cybersecurity premarket readiness for the US portfolio's FDA 510(k) submissions, and build the security-assessment tooling my team runs on. Solo author of Graphletter, an open-source GRC product. JD, ISACA CRISC.


Experience

Product Security Officer Carl Zeiss Meditec, Inc. // Dublin, CA // June 2023 – Present

  • Guide US R&D security engineers through threat modeling, vulnerability assessment, risk registers, and the cybersecurity deliverables required at each development milestone.
  • Own cybersecurity premarket readiness for the US portfolio's FDA 510(k) submissions; contributed to a multi-year corrective action that strengthened 510(k) readiness.
  • Chair the global ZEISS Security Engineer program, coordinating 40 security engineers worldwide.
  • Built the security-assessment tooling my team runs on, now expanding into a full web application; its software-bill-of-materials module is in global production use.
  • Sponsor an AI threat-modeling pipeline that cut initial model drafting from one day to about 30 minutes.
  • Conduct HIPAA and PHI security assessments for medical devices and acquired products; support M&A cybersecurity due diligence.

Solutions Architect – Cloud Security & Compliance Optimizely // San Francisco, CA // Mar – Nov 2022

  • Articulated Optimizely's cloud-security posture to global enterprise customers, bridging security, legal, and commercial teams inside active sales cycles.
  • Delivered standardized security responses for enterprise RFPs and customer vendor-risk assessments, drawing on SOC 2 and ISO 27001 control documentation.

Data Protection & Privacy Consultant HewardMills // Remote // Feb 2020 – Mar 2022

  • Served as the privacy subject-matter expert for about 15 multinational clients that were establishing or improving privacy programs.
  • Conducted, reviewed, and prioritized data protection impact assessments; guided records-of-processing work and advised clients on GDPR and CCPA requirements.

Project Manager Tetra Tech // San Francisco, CA // Dec 2016 – Oct 2019

  • Managed international programs for government clients across jurisdictions, coordinating local partners to meet each contract's regulatory and technical requirements.

Projects

Graphletter // graphletter.com // 2022 – Present // MIT, released May 2026

  • Open-source GRC platform, built solo in TypeScript: uses LLMs to map organizational evidence against framework control objectives, including HIPAA, SOC 2, ISO 27001, and NIST.

BarPlaybook // barplaybook.com // 2023 – Present

  • Built and shipped the LLM essay-grading pipeline behind a bar-exam practice platform.

Certifications

Certified in Risk and Information Systems Control (CRISC) // ISACA // Oct 2025


Education

Juris Doctor University of California, College of the Law, San Francisco // 2015

  • Law Clerk, Liberty, Security and Technology Clinic. Supported litigation on cybercrime and surveillance, building a foundation in cybersecurity law and ethics.

Bachelor of Arts The George Washington University // Washington, DC // 2012