A multi-year cybersecurity program — MFA, patching cadence, and endpoint hardening — across the field operations of a national multi-site retail and fuel operator with 800+ locations.
| Title | Enterprise Cybersecurity Program |
| Category | Enterprise Cybersecurity |
| Organization | A national multi-site retail and fuel operator (800+ locations) |
| Scale | 800+ distributed field locations |
| Role | Senior Project Manager III |
| Duration | Multi-year program |
The operating footprint was 800+ stores and fuel sites, each running point-of-sale, back-office, and corporate-managed endpoints behind inconsistent access controls. Multi-factor authentication rollout had stalled in the field. Patch cadence drifted quarter to quarter. Endpoint hardening standards existed on a slide deck but were not enforced at the site level, and reporting back to executive leadership was loose compared to what the threat surface demanded. As the footprint grew, the exposure window widened with it.
I program-managed the cybersecurity program and partnered with InfoSec leadership to align priorities, capacity, and budget. I directed the rollout of MFA, the patching cadence, and the endpoint hardening standards across the fleet, and I coordinated with Operations and Store Operations so that field rollouts did not collide with store-level activity. I designed the executive steering rhythm, oversaw the reporting cadence that surfaced exposure trends, and coordinated with Technology and Legal on the regulatory posture the program needed to hold. The work was governed, staffed, and measured — not a one-time project.
Governance ran on a regular cadence: a maintained risk register reviewed with executive leadership, vulnerability scoring that prioritized remediation by business impact, and remediation SLAs tied to severity bands. I coordinated with the CISO function, Operations, and field-site general managers so the program reflected the realities of distributed retail: weekend cutovers, regional variations, and the constraints of store-level bandwidth. Risk management meant deciding what to fix first, accepting residual risk in writing, and reviewing it quarterly — not running an endless backlog or letting the loudest voice set the schedule.
The systems did the heavy lifting. Multi-factor authentication was rolled out across 800+ locations on a phased schedule tied to operational risk. Patch management moved to a defined cadence with documented exceptions and a clear owner at the regional level. Endpoint hardening standards were written down, deployed through management tooling, and audited against a measurable baseline. I partnered with Procurement on the contract terms behind the tools so renewal cycles did not break the operating rhythm. The program was designed to outlast any single tool, vendor, or team — that was the point.
The program delivered a 40% reduction in threat exposure — measured across the MFA rollout, patching cadence, and endpoint hardening deployed across 800+ locations. The result came from disciplined program management and stakeholder alignment, not from a single product purchase or a one-time deployment.
If a distributed environment needs a cybersecurity program with real governance behind it, let's talk.
Book a Call →