Blue Goat CyberBlue Goat CyberSMMedical Device Cybersecurity
    K
    Leadership

    Meet the team guiding you to FDA cybersecurity success.

    Decades of combined experience in medical device cybersecurity, FDA premarket strategy, and offensive security - applied to every engagement we take.

    Founder & CEO

    Christian Espinosa

    • FDA premarket cybersecurity strategy
    • 510(k), De Novo, PMA, IDE submissions
    • SDVOSB leadership

    Christian Espinosa is the Founder and CEO of Blue Goat Cyber, where he helps medical device manufacturers make MedTech cybersecurity and FDA premarket cybersecurity requirements clear, fast, and effective - without slowing innovation. A U.S. Air Force Academy graduate and veteran with decades of cybersecurity experience across defense, critical infrastructure, and MedTech, Christian is known for a practical, risk-based approach that turns complex expectations into execution-ready plans for engineering, QA, and regulatory teams.

    Before launching Blue Goat Cyber, Christian built Alpine Security (founded in 2014) and sold the company in 2020. Not long after that exit, a serious health scare involving life-threatening blood clots made the mission intensely personal - reinforcing how much patients depend on medical technology working safely, reliably, and securely. In 2022, he founded Blue Goat Cyber to help manufacturers build security in from the start and move through FDA review with confidence. Under his leadership, Blue Goat has supported 250+ FDA medical device submissions and no client has failed to clear due to cybersecurity.

    Christian and the Blue Goat team support the full lifecycle of device cybersecurity - from secure product development and architecture reviews to threat modeling, cybersecurity risk management, and submission-ready evidence packages that hold up in FDA review. Their work commonly supports 510(k), PMA, and De Novo pathways, helping teams align technical controls to intended use, document security risk controls, and respond efficiently to cybersecurity questions during review.

    Outside of work, Christian is an endurance athlete who has completed 24 Ironmans and climbed 2 of the 7 Summits. He's also working toward competing in Formula 4 racing and has traveled to 80+ countries - pursuits that mirror his belief in preparation, discipline, and calm under pressure.

    CTO

    Myles Kellerman

    • Medical device & IoMT penetration testing
    • Threat modeling & SBOM/vulnerability analysis
    • FDA-aligned security evidence & testing automation

    Myles Kellerman is the Chief Technology Officer at Blue Goat Cyber, where he leads the technical side of the firm's medical device and IoMT cybersecurity practice. His teams run device penetration testing, threat modeling, SBOM and vulnerability analysis, and application and infrastructure security assessments aligned with FDA Section 524B, the Feb 3, 2026 premarket cybersecurity guidance, AAMI SW96, and IEC 81001-5-1.

    Myles works hands-on across Class II and Class III programs - infusion, imaging, surgical robotics, wearables, connected diagnostics, and hospital-connected IoMT - focusing on how real-world attack paths map to patient safety and to the security risk file the FDA expects to see. He owns the internal tooling and testing automation that keep evidence packages consistent from one submission to the next, so engineering and regulatory teams get the same submission-grade artifacts regardless of team or timeline.

    Before Blue Goat Cyber, Myles served as a Principal Consultant on Cerberus Sentinel's Penetration Testing Team and led social engineering and penetration testing at Alpine Security. Earlier in his career, he was a founding member of the Mobility Air Forces Distributed Training Center (MAF DTC) at Scott Air Force Base and supported aircraft and embedded system cybersecurity for major defense contractors across commercial programs and Special Access Programs (SAPs) - safety-critical, life-dependent systems that closely mirror the rigor MedTech now demands.

    Headshot of Jordan John, VP, Regulatory Affairs & Compliance at Blue Goat Cyber

    VP, Regulatory Affairs & Compliance

    Jordan John

    • FDA premarket & postmarket regulatory strategy
    • Section 524B & eSTAR submission alignment
    • Cybersecurity evidence in the regulatory file

    Jordan John is the Vice President of Regulatory Affairs & Compliance at Blue Goat Cyber, where he owns the regulatory and compliance lane across FDA premarket and postmarket medical device submissions. He aligns cybersecurity evidence with FDA Section 524B, the Feb 3, 2026 premarket cybersecurity guidance, and eSTAR structure so every package holds together end-to-end for CDRH review.

    Jordan partners with engineering, quality, and regulatory teams to translate cybersecurity expectations into concrete artifacts - threat models, SBOMs, security risk assessments, architecture views, and pen test evidence - that map cleanly to AAMI SW96, AAMI TIR57/97, IEC 81001-5-1, and ISO 14971. His focus is a submission-ready package the whole product team can defend on first review.

    A frequent speaker on FDA cybersecurity strategy, Jordan has presented sessions such as "Compliance Without Chaos: Mastering FDA Cybersecurity" and co-hosted the Med Device Cyber Podcast webinar on the five key FDA cybersecurity standards.

    VP, Strategic Partnerships

    Melissa Espinosa

    • Channel & partner ecosystem for MedTech
    • Clinical-risk lens on device cybersecurity partnerships
    • Regulatory, QMS, and technology partner alliances

    Melissa Espinosa is the Vice President of Strategic Partnerships at Blue Goat Cyber, where she leads the development and growth of the company's channel and partner networks across MedTech consulting, regulatory, and technology firms. Her clinical background as a cardiac stepdown nurse is not a footnote - it is the lens through which she evaluates every partnership: does this relationship help manufacturers ship devices that are safer at the bedside, or does it just move paperwork?

    That clinical perspective is a direct buyer benefit for medical device manufacturers. Melissa understands how a paused infusion pump, a delayed alarm, or a compromised telemetry stream translates into real patient harm, so she pushes Blue Goat's partner ecosystem - regulatory consultants, QMS providers, distributors, and technology vendors - toward joint offerings that shorten time to FDA clearance without pushing risk onto the care team. For clients, that means a partner network that speaks both languages: FDA Section 524B and the clinical workflow it is meant to protect.

    Outside of work, Melissa is a long-distance runner and traveler - pursuits that mirror the endurance, curiosity, and cross-cultural relationship-building she brings to Blue Goat's partner strategy.

    VP, Sales

    Kristy Kennedy

    • MedTech commercial strategy & scoping
    • 510(k), De Novo, PMA engagement fit
    • Long-term device manufacturer partnerships

    Kristy Kennedy is a commercial leader focused on medical devices and life sciences, with 25+ years spent helping MedTech manufacturers bring regulated products to market. She has led sales, business development, and go-to-market strategy for device and diagnostic launches, and built long-term partnerships with hospital systems, distributors, and OEM channels that ship real product into clinical environments.

    At Blue Goat Cyber, Kristy uses that MedTech-native background to help device manufacturers - from pre-submission startups to established Class II and Class III OEMs - scope cybersecurity engagements that fit their FDA pathway (510(k), De Novo, PMA), their product timeline, and their regulatory strategy. Her focus is right-sizing the work: enough evidence to clear review under Section 524B and the Feb 3, 2026 premarket guidance, without pulling engineering off the release critical path.

    Headshot of Michelle Hughes, Director of Project Management at Blue Goat Cyber

    Director of Project Management

    Michelle Hughes

    • MedTech cybersecurity program delivery
    • Cross-functional coordination (engineering, QA, regulatory)
    • eSTAR-ready submission packaging

    Michelle Hughes is the Director of Project Management at Blue Goat Cyber, where she drives complex MedTech cybersecurity engagements from kickoff through FDA clearance. She coordinates technical, QA, and regulatory workstreams so threat models, SBOMs, penetration tests, and submission packages move in lockstep with the manufacturer's product and regulatory calendar.

    Michelle's focus is a predictable delivery rhythm: senior practitioners on every meeting, submission-grade artifacts formatted to eSTAR structure, and clear checkpoints that keep engineering, quality, and regulatory teams aligned without surprises.

    Headshot of Sarah Beach, Senior Project Manager at Blue Goat Cyber

    Senior Project Manager

    Sarah Beach

    • End-to-end engagement delivery
    • FDA interaction cadence
    • Client communication & timeline ownership

    Sarah Beach is a Senior Project Manager at Blue Goat Cyber, owning engagement timelines, deliverables, and FDA interactions end-to-end. She keeps threat models, penetration tests, SBOMs, and submission packages on rails so engineering and regulatory teams stay aligned without surprises.

    Sarah partners closely with clients through discovery, kickoff, delivery, and submission - translating FDA Section 524B and Feb 3, 2026 premarket guidance expectations into a delivery plan the whole product team can act on.

    Looking for company background, milestones, and values? Read about Blue Goat Cyber.

    Ready when you are

    Get FDA cleared without the cybersecurity headaches.

    30-minute strategy session. No cost, no commitment - just answers from people who've shipped 250+ FDA submissions.