AI Governance & Assurance
Establish lifecycle controls, accountable oversight, evidence, and assurance around commitments and standards.
AI governance & assurance · cybersecurity & GRC · product trust
Trust, engineered for consequential technology.
I build governance, security, GRC, and assurance systems for organizations operating at the frontier of AI.
My work sits between strategy and execution: aligning engineering, security, risk, privacy, legal, compliance, and executive stakeholders around AI and technology decisions that withstand scrutiny.
The objective is not more governance. It is evaluable systems, better judgment, clearer accountability, and durable trust.
Establish lifecycle controls, accountable oversight, evidence, and assurance around commitments and standards.
Build model and system evaluation around testable scenarios, monitoring, technical evidence, and decision thresholds.
Bring architecture, identity, data access, threats, controls, and evidence into product decisions from the outset.
Build scalable control and assurance systems that earn confidence from customers, regulators, and leaders.
Use technical depth, analytics, and automation to make independent assurance a source of decision signal.
Strengthen AI data, model supply chains, critical services, and external dependencies before disruption tests them.
Across every domain, policy and risk become evaluation, controls, observable evidence, and decisions.
Translate commitments into evaluable controls, system evidence, accountable oversight, and decisions across the AI lifecycle.
Judgment shows up as outcomes, not just frameworks applied.
At Amazon, I built repeatable trust mechanisms across global product regulation, security engineering, evidence, and resilience so emerging obligations become execution-ready.
At Cyber Future Foundation, I architected and advanced RSAIF MOSAIC as an operating framework, learning pathway, and source of practitioner guidance.
Across regulated financial institutions, I brought engineering context, analytics, and risk judgment to assurance spanning cloud, identity, data, infrastructure, and resilience.
Selected moments from conferences, panels, and practitioner sessions.
The through-line: technical depth joined with executive judgment across engineering, governance, audit, and industry contribution.
Expanded technical assurance into global product trust, working where regulation, security engineering, operational evidence, and resilience meet.
Made responsible and secure AI principles operational through RSAIF MOSAIC, practitioner learning pathways, and implementation guidance.
Explore the RSAIF ecosystemMoved assurance closer to engineering by applying threat-informed thinking across identity, cloud, encryption, authentication, and DevSecOps.
Expanded technology assurance across cloud, data, infrastructure, third parties, and resilience within a regulated financial environment.
Leadership conversations
I am interested in global leadership mandates across AI assurance, product trust, AI security, risk engineering, technology audit, and governance.