Cloud Security Architecture
Secure-by-design reference architectures, threat modeling, and security baselines across Azure & AWS environments.
Trusted advisor to CIOs & CISOs and founder of 365Architect. I turn complexity into clarity — architecting secure Azure & AWS migrations, identity, governance, and DevSecOps for finance, healthcare, retail, and government.
For two decades I've helped Fortune-class enterprises modernize legacy platforms and move to the cloud without trading away security. I work where the stakes are highest — finance, healthcare, retail, and government — partnering with leaders at organizations like Santander, Walmart, Publix, and F5.
My differentiator is simple: I fill the gap between security experts and technical architects. Most teams have one or the other; compliance and cloud migration break down in the space between them. I speak both languages and bridge that gap — from boardroom strategy down to the IaC pipeline.
Security-first thinking is in my DNA. I design secure-by-default systems that pass the hardest audits — HIPAA, PCI-DSS, ISO, NIST, FedRAMP — and still fuel innovation. And I pair that with a forward bet most consultancies haven't made yet: private, on-prem AI that keeps your intellectual property entirely your own.
Secure-by-design reference architectures, threat modeling, and security baselines across Azure & AWS environments.
Federated identity, SSO, MFA and Zero Trust. Entra ID / Azure AD P2, PIM/PAM, Okta, Auth0, PingFederate, ADFS.
Large-scale, low-disruption migration to Azure & AWS — landing zone design, networking, governance, and monitoring per Well-Architected.
Gap analysis & attestation against CSA CCM, ISO, NIST, SOC2, FedRAMP. Azure Policy, Blueprints, Purview, data governance.
Secure CI/CD pipelines and Infrastructure as Code that ship fast and stay compliant — Terraform, ARM, PowerShell automation.
On-prem AI for anomaly detection, semantic search and compliance classification — ML.NET, Azure AI, GraphRAG, vector search.
Fully private, on-premises AI ecosystems I designed and built — multi-model, zero-knowledge, and vendor-independent. Your IP never leaves your perimeter.
Multi-model local inference via Ollama — DeepSeek-Coder-V2, Qwen3-Coder-Next, and Kimi running entirely in-house.
Leiden community-detection pipeline on NVIDIA Blackwell that cut architectural discovery time by ~60%.
Optimized vector search and hybrid retrieval over a secure, self-hosted knowledge base.
Aider AI-pair-programming plus Whisper + TTS voice AI — automation without sending data off-site.
A global, systemically-important bank needed to harden its security posture and move regulated workloads to the cloud — without disrupting operations or failing audits.
Architected the cloud security and migration strategy; enforced governance through Azure Policy, Blueprints, and custom security baselines; ran SSP, SRCR, and ISAR reviews with gap analyses against CSA CCM, ISO, and NIST; and implemented identity and Zero-Trust controls.
A multi-billion-dollar pharmaceutical platform required modernization at massive scale, under strict HIPAA regulatory oversight.
Led a 55+ member cross-functional organization and 9 Agile Scrum teams to re-architect the platform with cloud-native, event-driven microservices — working alongside HIPAA auditors to guarantee full regulatory adherence.
Fragmented integrations across 37+ POS payment devices stretched delivery to months and blocked market expansion.
Built a microservices integration platform, the flagship E-Payment system, and the reusable Sicom.Framework — then drove PCI-DSS certification with third-party auditors.
40+ professional certifications across cloud, security, data, and architecture — most available to download below as PDFs, with 22 active Microsoft credentials independently verifiable on Microsoft Learn.
Modernizing systems, hardening your cloud, or navigating a compliance-heavy migration? I take on short- and long-term engagements (Corp-to-Corp or remote). Let's talk.