AI governance & assurance · cybersecurity & GRC · product trust

Anupam Gupta

Trust, engineered for consequential technology.

I build governance, security, GRC, and assurance systems for organizations operating at the frontier of AI.

Current leadershipSenior Security Industry Specialist, Amazon
Industry contribution Lead Architect and Advisor, Cyber Future Foundation Explore RSAIF.AI
Anupam Gupta at a professional leadership event
Anupam Gupta Global AI governance, security and GRC leader

I turn frontier technology risk into systems people can operate.

My work sits between strategy and execution: aligning engineering, security, risk, privacy, legal, compliance, and executive stakeholders around AI and technology decisions that withstand scrutiny.

The objective is not more governance. It is evaluable systems, better judgment, clearer accountability, and durable trust.

01

AI Governance & Assurance

Establish lifecycle controls, accountable oversight, evidence, and assurance around commitments and standards.

02

AI Risk Engineering & Evaluation

Build model and system evaluation around testable scenarios, monitoring, technical evidence, and decision thresholds.

03

Product & Engineering Security

Bring architecture, identity, data access, threats, controls, and evidence into product decisions from the outset.

04

Enterprise GRC & Product Trust

Build scalable control and assurance systems that earn confidence from customers, regulators, and leaders.

05

Technology & AI Audit

Use technical depth, analytics, and automation to make independent assurance a source of decision signal.

06

Resilience, Data & Ecosystem Risk

Strengthen AI data, model supply chains, critical services, and external dependencies before disruption tests them.

Standards are inputs. Assurance is the system.

Across every domain, policy and risk become evaluation, controls, observable evidence, and decisions.

Risk thesisArchitectureEvaluationEvidenceDecision
01
AI governance & assurance

Govern and assure AI across its lifecycle.

Translate commitments into evaluable controls, system evidence, accountable oversight, and decisions across the AI lifecycle.

AccountabilityLifecycle controlsDecision evidence

What these capabilities produce.

Judgment shows up as outcomes, not just frameworks applied.

01

Operational assurance at product scale

At Amazon, I built repeatable trust mechanisms across global product regulation, security engineering, evidence, and resilience so emerging obligations become execution-ready.

Readiness under scrutiny
02

Applied architecture for responsible AI

At Cyber Future Foundation, I architected and advanced RSAIF MOSAIC as an operating framework, learning pathway, and source of practitioner guidance.

Governance made actionable
03

Threat-informed independent assurance

Across regulated financial institutions, I brought engineering context, analytics, and risk judgment to assurance spanning cloud, identity, data, infrastructure, and resilience.

Evidence that informs decisions

Ideas earn trust when they can be heard.

Selected moments from conferences, panels, and practitioner sessions.

A career building trust where technology changes fastest.

The through-line: technical depth joined with executive judgment across engineering, governance, audit, and industry contribution.

2022 — Present

Amazon

Senior Security Industry Specialist

Expanded technical assurance into global product trust, working where regulation, security engineering, operational evidence, and resilience meet.

2024 — Present

Cyber Future Foundation

Lead Architect and Advisor

Made responsible and secure AI principles operational through RSAIF MOSAIC, practitioner learning pathways, and implementation guidance.

Explore the RSAIF ecosystem
2021 — 2022

Fidelity Investments

Senior IT Audit Analyst

Moved assurance closer to engineering by applying threat-informed thinking across identity, cloud, encryption, authentication, and DevSecOps.

2019 — 2021

Federal Home Loan Bank of Dallas

Senior IT Auditor

Expanded technology assurance across cloud, data, infrastructure, third parties, and resilience within a regulated financial environment.

Depth built through practice, research, and contribution.

AI & security credentials

  • Executive Introduction to RSAIF
  • Practitioner's Playbook for RSAIF
  • GIAC Security Leadership (GSLC)
  • CISA
  • CDPSE
  • ISO 27001 Lead Implementer
  • ISO 27001 Lead Auditor

Risk & technology

  • Certified ISO 31000 Internal Controls Risk Analyst
  • AWS Security Compliance and Governance for AI Solutions
  • CSX Cybersecurity Fundamentals Certificate (CSXF)
  • Microsoft Certified: Azure Fundamentals
  • Certificate in Cybersecurity Systems (CCSS)

Recognition

  • SANS Security Leadership Gold Award
  • Marquis Who's Who
  • Esther R. Sawyer Research Award
  • Mark Salamasick IT Auditor Fellowship
  • Gold Medalist

Education & research

  • MS, Information Technology & Management
    The University of Texas at Dallas
  • BS, Computer Science
    University of Delhi
  • Research in social engineering and organizational governance

Leadership conversations

Advanced AI needs leaders who can make trust operational.

I am interested in global leadership mandates across AI assurance, product trust, AI security, risk engineering, technology audit, and governance.