Peter Boaz
Product Security & GRC
San Francisco Bay Area
Profile
Product security operator-builder with 10+ years in regulated environments. At ZEISS Medical Technology, I guide US R&D teams through threat modeling, vulnerability assessment, risk registers, and security deliverables at each product milestone. I chair a global program of 40 security engineers, own cybersecurity premarket readiness for the US portfolio's FDA 510(k) submissions, and build the security-assessment tooling my team runs on. Solo author of Graphletter, an open-source GRC product. JD, ISACA CRISC.
Experience
Product Security Officer Carl Zeiss Meditec, Inc. // Dublin, CA // June 2023 – Present
- Guide US R&D security engineers through threat modeling, vulnerability assessment, risk registers, and the cybersecurity deliverables required at each development milestone.
- Own cybersecurity premarket readiness for the US portfolio's FDA 510(k) submissions; contributed to a multi-year corrective action that strengthened 510(k) readiness.
- Chair the global ZEISS Security Engineer program, coordinating 40 security engineers worldwide.
- Built the security-assessment tooling my team runs on, now expanding into a full web application; its software-bill-of-materials module is in global production use.
- Sponsor an AI threat-modeling pipeline that cut initial model drafting from one day to about 30 minutes.
- Conduct HIPAA and PHI security assessments for medical devices and acquired products; support M&A cybersecurity due diligence.
Solutions Architect – Cloud Security & Compliance Optimizely // San Francisco, CA // Mar – Nov 2022
- Articulated Optimizely's cloud-security posture to global enterprise customers, bridging security, legal, and commercial teams inside active sales cycles.
- Delivered standardized security responses for enterprise RFPs and customer vendor-risk assessments, drawing on SOC 2 and ISO 27001 control documentation.
Data Protection & Privacy Consultant HewardMills // Remote // Feb 2020 – Mar 2022
- Served as the privacy subject-matter expert for about 15 multinational clients that were establishing or improving privacy programs.
- Conducted, reviewed, and prioritized data protection impact assessments; guided records-of-processing work and advised clients on GDPR and CCPA requirements.
Project Manager Tetra Tech // San Francisco, CA // Dec 2016 – Oct 2019
- Managed international programs for government clients across jurisdictions, coordinating local partners to meet each contract's regulatory and technical requirements.
Projects
Graphletter // graphletter.com // 2022 – Present // MIT, released May 2026
- Open-source GRC platform, built solo in TypeScript: uses LLMs to map organizational evidence against framework control objectives, including HIPAA, SOC 2, ISO 27001, and NIST.
BarPlaybook // barplaybook.com // 2023 – Present
- Built and shipped the LLM essay-grading pipeline behind a bar-exam practice platform.
Certifications
Certified in Risk and Information Systems Control (CRISC) // ISACA // Oct 2025
Education
Juris Doctor University of California, College of the Law, San Francisco // 2015
- Law Clerk, Liberty, Security and Technology Clinic. Supported litigation on cybercrime and surveillance, building a foundation in cybersecurity law and ethics.
Bachelor of Arts The George Washington University // Washington, DC // 2012