Jonathan J.
Enterprise Security Architect | Cloud, IAM, Zero Trust & AI Security
Enterprise Security Architect and cybersecurity leader with 18+ years of experience designing secure, resilient systems across financial services, federal/defense environments, and cloud-native platforms. I help organizations turn complex security and regulatory requirements into practical architectures, implementation roadmaps, and technical controls that engineering teams can execute. My experience spans AWS, Azure, GCP, and OCI, with deep focus on: • Enterprise security architecture and architecture reviews • Zero Trust aligned with NIST SP 800-207 • IAM, PAM, RBAC, MFA, OAuth 2.0, OIDC, SAML, FIDO2, and PKI/TLS • Cloud and Kubernetes/OpenShift security • Encryption, HSM/KMS, secrets management, and credential lifecycle controls • AI security architecture, governance, threat modeling, and secure service access • API security, DevSecOps, secure SDLC, vulnerability management, and OWASP practices • Security monitoring, auditability, incident readiness, resilience, and disaster recovery • NIST 800-53, FedRAMP, PCI DSS, ISO 27001, FFIEC, CIS Controls, and DoD STIG alignment I have served as a technical authority for mission-critical financial platforms, led multi-cloud security transformation initiatives, established reusable security reference architectures, and partnered with executives, compliance teams, engineers, auditors, and security operations. Typical deliverables include current-state and gap assessments, threat models, security control mappings, HLDs/LLDs, reference architectures, prioritized findings, remediation roadmaps, implementation guidance, and validation plans. I bring both executive-level judgment and hands-on technical depth, communicating clearly with stakeholders while giving developers specific, actionable recommendations—not generic checklists.