Post Job Free
Sign in

Executive AI & Cybersecurity Architect (20+ yrs)

Location:
Montreal, QC, Canada
Posted:
May 26, 2026

Contact this candidate

Resume:

Bhushan Bhuvanagiri

Ph No: +1-514-***-****; E-mail: ***********************@*****.***

https://www.linkedin.com/in/bhushan-bhuvanagiri/

I architect, govern, and secure enterprise AI ecosystems—from third-party SaaS AI and internally built ML platforms systems. With 20+ years of cybersecurity architecture experience, I define secure AI patterns, human and machine (AI/agentic) identities, PAM, Secret Vaults, Directory Structure, ZeroTrust, Cybersecurity architecture, governance frameworks grounded in NIST AI RMF, EU AI Act, ISO42001 – AI Lead Auditor, CIS, PCI, HIPPA and more. I evaluate foundation models, Non-Human Identity (NHI), vector databases, and agent architectures for security posture and enterprise readiness, partnering with engineering, data science, legal, and compliance stakeholders to balance secure AI solutions with enterprise risk tolerance—delivering millions in cost savings deploying AI security programs across Fortune 500 environments.

Summary:

• Master’s degree in Information Systems Security from Concordia University; certifications include GIAC GWAPT, CRISC, CISM, AAISM (In-progress), AWS & Azure Security, Six Sigma Green Belt, and Qualys Certified.

• 20+ years of security architecture experience, including hands-on AI Security Architecture, AI security Governance, IAM, PAM, NHI, and zero-trust solutions across AWS, Azure, GCP, and Oracle OCI—grounded in NIST AI RMF, MITRE ATLAS, ISO 27001/42001, and more.

• Deep technical fluency across both cybersecurity and modern AI/ML ecosystems— standing up AI Security programs, privileged account Mgmt., evaluating third-party SaaS AI and internally developed ML platforms, assessing foundation models and agentic AI systems for data protection, enterprise readiness, and compliance.

• Cross-functional AI security leaders serve as trusted advisors to engineering, security, and platform teams—bridging emerging AI technologies with enterprise identity controls, authoring governance frameworks, and presenting architecture strategy to C-suite and Board-level stakeholders.

• Enterprise AI identity and security innovator with 3+ years designing secure identity patterns for agentic and autonomous AI systems—defining token-based access, secure API authorization, machine identity lifecycle, and privileged access controls for AI workloads that delivered $6.7M+ in cost savings

• Governance and compliance expertise ensuring adherence to PCI DSS, NIST AI RMF, EU AI Act, ISO 27001/42001, etc. with deep knowledge of IAM, Appsec, AI Security, Threat Modeling, and regulatory alignment for AI-driven environments.

• Proven achievements: Designed identity and security architecture for 100+ AI workloads; achieved 97% visibility, 80% SAST integration, and 45% DAST integration across regulated enterprise environments. TOOLS

Attack Frameworks: Kali, Samurai WTF, ELK Stack, Sourcefire Security Tools: Qualys/Nessus, Acunetix, Veracode, Wireshark, McAfee NSM, McAfee SIEM/IDS/IPS, FireEye NX, FireEye EX, ZAP, ELK Stack, Tanium, Symantec SEP, Rapid7, Algosec, Illumio, Trend Micro IWSS, Postman, Azure Defender EDR, Azure Sentinel, etc. SDLC Pipeline Stack: Gitlab, GitHub, bitbucket, Jenkins, Concourse, ADO etc. Security Management: Wiz, Prisma, Dome9, CrowdStrike, SentinelOne, AquaSec, Qualys Web Security: Cloudflare, Akamai, F5 Advanced WAF, Fastly, APIGEE, ModSecurity WAF Bhushan Bhuvanagiri

Ph No: +1-813-***-****; E-mail: ***********************@*****.*** https://www.linkedin.com/in/bhushan-bhuvanagiri/

PROFESSIONAL EXPERIENCE

iBovi Strategic Security INC, (Cybersecurity Consultant) Jun 2017 – Present PwnUS – Product Security Architect/Consultant

• Served as lead architect for integrating AI platforms within PwnUS —defining Attack vectors, AI training, configuring IAM, non-human identity (NHI), authentication and authorization models for AI workloads, and enforced traceability and auditability of all AI-driven actions aligned with MITRE ATLAS and NIST AI RMF.

• Designed secure-by-design reference architectures and governance patterns for agentic and autonomous AI systems—defining identity-aware threat models, access control boundaries (RBAC/ABAC), data flow controls, and residual risk scoring frameworks to ensure consistent outcome based on CVSS3.1 & 4 risk scoring.

• Architected and deployed production-grade GenAI agentic systems using N8N.io, Ollama, Zapier, and OpenAI—building enterprise-ready AI automation workflows for penetration testing, firewall management, and risk assessment while ensuring compliance with ISO 27001 and CIS benchmarks, delivering $2.3M+ in annual cost savings

• Architected scalable cloud-native AI security solutions covering containerized deployments, vector database security, and enterprise IAM integration—leveraging Oracle Cloud Guard, Azure Entra, and Prisma Cloud to enforce data protection and access governance for AI workloads

• Led end-to-end remediation lifecycle for AI infrastructure security findings, triaging vulnerabilities across MCP server environments, coordinating cross-functional patch deployments, and driving closure of high and critical findings within SLA, achieving a 40% reduction in mean time to remediate (MTTR).

• Evaluated third-party SaaS AI and ML platforms for security posture, data protection, and enterprise readiness—leading cross-functional implementation teams spanning engineering, compliance, and legal to integrate AI tools within enterprise risk Mgmt. Toyota Motors– Sr. Gen AI / Cloud Security Architect - Connected Technology (Vehicle Telematics)

• Served as the enterprise AI Security Architect at Toyota—owning end-to-end AI Security architecture for Connected Car Technologies across AWS, Azure, GCP, and OCI; designed identity lifecycle management for human and non-human identities using Entra.

• Architected and enforced security controls for Model Context Protocol (MCP) server deployments, identifying and remediating critical vulnerabilities including prompt injection, tool poisoning, and unauthorized data exfiltration risks, reducing attack surface by implementing least-privilege access policies and input/output validation frameworks.

• Built and owned Toyota’s enterprise AI identity and security governance program— defining reference architectures, standards, and patterns for AI/ML identity integration grounded in NIST AI RMF, MITRE ATLAS, EU AI Act and ISO 42001; established AI governance frameworks covering both internally developed and SaaS platforms.

• Authored AI security policies, identity governance standards, and access control guidelines for AI-powered applications within Toyota—defining model access boundaries, privileged access controls for AI systems, and secure API and token-based access patterns while ensuring regulatory alignment with emerging AI regulations.

• Defined accountability structures by reviewing and validating RACI matrices for all AI- powered applications—establishing traceability, auditability, and accountability of AI- Bhushan Bhuvanagiri

Ph No: +1-813-***-****; E-mail: ***********************@*****.*** https://www.linkedin.com/in/bhushan-bhuvanagiri/

driven actions across business, engineering, legal, and compliance stakeholders to support enterprise AI identity governance.

• Led deep-dive IAM and security architecture reviews of AI-powered applications and their API endpoint assessing OAuth2 integration patterns, agentic system identities, and data access boundaries to identify attack surfaces and ensure secure enterprise.

• Evaluated foundation model and AI system performance by gathering and analyzing key metrics including temperature, top-p sampling, token usage, throughput, TTFT, latency, error rates, and retry rates—using quantitative data to assess model accuracy, reliability, and robustness for enterprise-grade deployments.

• Conducted security assessments and threat modeling for MCP-based agentic AI systems, uncovering risks in tool call authorization, server-side request forgery (SSRF) vectors, and inter-agent trust boundaries, and delivering actionable remediation roadmaps aligned to OWASP and NIST frameworks.

• Performed adversarial attack analysis, AI explainability assessments, and AI vulnerability evaluations aligned with MITRE ATLAS—identifying model weaknesses, data poisoning risks, and prompt injection vectors to enforce secure AI deployment standards.

• Partnered with data science, legal, and compliance teams to conduct cross-functional AI risk assessments—evaluating third-party AI/ML vendors and SaaS AI platforms for integration readiness, identity governance alignment, regulatory compliance, and enterprise security posture across AWS, Azure, GCP, and OCI environments.

• Performed hands-on Application Security Testing across Connected Technologies applications on AWS, Azure, GCP, and OCI—conducting threat modeling, DAST scans and architecture security accreditation for all applications moving to production.

• Executed identity governance and access control reviews for all production changes across Vehicle Telematics applications—leveraging Azure Entra ID, and SailPoint IQ and NHI to enforce RBAC/ABAC access models etc.

• Developed and deployed GenAI-powered agentic workflows to automate firewall request processing across multi-layered Network Security Zones—enabling secure, governed communication authorization in a highly sensitive network environment and delivering

$1M USD in annual operational savings.

• Built a fully autonomous AI-driven workflow to calculate residual risk scores, classify every application for Threat Modeling eligibility, and generate Application Security Certificates—providing enterprise-wide visibility into application security posture and delivering $4.3M USD in annual savings.

• Evaluated, assessed, and validated all architecture changes for Vehicle Telematics— performing Cloud Architecture Security Accreditation for every application moving to production to ensure alignment with enterprise security standards and regulatory obligations.

• Established and operationalized enterprise AI identity governance frameworks ensuring compliance with OWASP, NIST AI RMF, ISO 27001/42001, and emerging AI regulations—serving as the SME bridging engineering, data science, and compliance stakeholders to enable safe AI adoption without increasing enterprise identity risk.

• Developed custom security controls and access policy queries using Dome9/Prisma Cloud to enforce consistent identity standards and least privilege principles across multi- cloud environments.

Bhushan Bhuvanagiri

Ph No: +1-813-***-****; E-mail: ***********************@*****.*** https://www.linkedin.com/in/bhushan-bhuvanagiri/

Berkshire Hathaway Energy (BHE) – Lead Cloud Security Architect Nov 2022 – Jun2024

• Designed and implemented cloud security architectures with a focus on hybrid cloud architecture patterns, data governance, and identity and access control to protect sensitive data across Oracle Cloud Infrastructure, Azure, and hybrid environments.

• Architected comprehensive cloud security strategies leveraging Oracle Cloud Guard to enforce API security, access governance, and cloud infrastructure protection across Oracle Fusion Apps and SaaS solutions—reducing threat exposure and improving system resilience.

• Conducted security audits, risk assessments, and threat modeling across multi-cloud environments—analyzing incidents, validating access controls, and generating GRC reports aligned to OWASP, COBIT, and NIST frameworks.

• Reviewed, validated, and enforced IAM access controls using Oracle IDCS, CyberArk PAM, and Conjur Secrets Manager—governing on-premises and cloud identity access rules, privileged account policies, and more.

• Managed various cybersecurity audits and assessments leveraging the capabilities of GCP, ensuring optimal safety protocols were met

• Responsible for performing SAST scans using Veracode, Fortify and Terraform Linters.

• Responsible for establishing integrations with AWS Pipelines and Azure DevOps.

• Responsible to perform DAST scans using Rapid7 insight Appsec on Jenkins and Azure DevOps and generate GRC reports using OWASP, COBIT & NIST framework.

• Responsible to setup, configure and run Cloud GRC using Prisma Cloud, WAAS, AWS WAF, Azure WAF, F5-ASM (WAF), API Gateway, Bluecoat Proxy, Skybox, OCI, Oracle Fusion Security, Hexagon Security and more.

• Responsible for performing Testing on Cloud facing Web apps written in Java or .NET frameworks and performing risk Assessment and Threat Modelling.

• Responsible to provide secure development practices for applications on Kubernetes platforms such as VMWare Tanzu, OpenShift, AWS EKS and more.

• Responsible to ensure security scans are remediated prior to Prod release in Cloud.

• Responsible to setup security automation using Cortex XSOAR with Prisma Cloud. Duke-Energy / USTech- Lead Application Security Architect Nov 2019 – Nov 2022

• Designed comprehensive security architecture strategies to reduce cyber risk, enhance system resilience, and enforce consistent access control standards across Duke Energy’s hybrid cloud enterprise environment.

• Built the Application Security Program from scratch—defining goals, scope, and a 3–5- year roadmap that established pipeline security, GRC reporting, and application risk governance across the enterprise.

• Built the Application Security Program from the ground up—defining a 3–5 year roadmap, governance framework, and risk-based strategy that established consistent security standards across a hybrid enterprise organization.

• Designed and operationalized SOAR automation on Cortex XSOAR—integrating Splunk, MS Power Automate, Checkmarx, McAfee, and Skybox to automate security workflows, reduce manual intervention, and deliver measurable risk reduction at scale.

• Defined security metrics, KPIs, KRIs, and threshold triggers—generating unified compliance and risk dashboards using Power BI and RSA Archer aligned to OWASP, NIST, and COBIT standards for executive reporting. Bhushan Bhuvanagiri

Ph No: +1-813-***-****; E-mail: ***********************@*****.*** https://www.linkedin.com/in/bhushan-bhuvanagiri/

• Performed threat modeling for every application, identifying attack vectors and access- control weaknesses—integrating SAST (Checkmarx, SonarQube) and DAST (Fortify, Rapid7) into CI/CD pipelines across Jenkins, Concourse, and Azure DevOps.

• Responsible for GRC while operating, maintaining and managing SAST products such as Checkmarx, SonarQube, Hexagon, SAP Secure Code, APIGEE, Skybox, etc.

• Responsible for performing manual testing and automated SCA testing using NexusIQ.

• Accountable to perform integrations with Jenkins, Concourse, Azure DevOps & AWS Pipeline security integration such as Checkmarx, SCA, Trivy, Aquasec, Github Advance Security, Burp Suite etc.

• Developed comprehensive threat detection systems using GCP, significantly reducing potential security risks

• Responsible for evaluating and performing POC on 3 rd

Party risk assessment on all third-

party libraries using SCA.

• Accountable and responsible to create custom reports using Power BI & demonstrate business value on SharePoint and use Fortify Web Scan for DAST scans.

• Accountable and responsible for generating unified reports using Power BI and RSA Archer based on the standards of OWASP, NIST & COBIT regulations.

• Responsible for ensuring penetration testing was performed on all apps prior to production.

• Responsible to re-architect, design, develop, operationalize & delivery of WAF Service using Signal Science.

• Developed SOAR use cases on Cortex XSOAR by integrating various 3 rd

party products

such as Splunk, MS Power Automate, Nexus, Checkmarx, Oracle OCI Security, Skybox, McAfee, Fastly, Hexagon Security etc.

• Responsible to define metrics, stats, KPI’s, KRI’s, threshold triggers and risk analysis.

• Accountable and responsible for performing threat modeling for each application & identify Attack vectors.

• Responsible for demonstrating business value by removing manual intervention and generating stats for the executives.

• Key Achievements:

o Over 97% visibility of all DevOps Pipelines within the Hybrid organization o Over 80% of all pipelines had SAST integrated within the pipeline. o Over 45% of all pipelines had DAST integrated within the pipeline. o Over 96% of all pipelines had consolidated reports using Power BI. SAP Labs - Lead Vulnerability Management & WAF Security Mar 2018 – Aug 2019

• Led the design, development, and delivery of a comprehensive Vulnerability Management program across AWS and Azure environments.

• Re-architected IAM with RSA and implemented MFA integration within Azure— strengthening identity lifecycle management, access governance, and authentication controls across cloud and on-premises environments.

• Conducted threat modeling, source code reviews, CVSS scoring, and risk assessments.

• Oversaw on-prem to cloud infrastructure migration and validated security across app and infra layers.

• Accountable and responsible for re-architect, design, develop, operationalize & delivery of WAF Service using Signal Science, AWS WAF & F5-ASM proxy. Bhushan Bhuvanagiri

Ph No: +1-813-***-****; E-mail: ***********************@*****.*** https://www.linkedin.com/in/bhushan-bhuvanagiri/

• Developed over 18 use cases of global WAF rules on high traffic financial websites using Signal Science / Fastly, F5-ASM proxy, Trend Micro and more.

• Responsible to develop WAF rules on Signal Science across AWS, Azure & on-prem.

• Responsible for all Web application security incidents and propose interim remediation solutions.

• Designed and managed F5 ASM and McAfee Web Gateway WAF solutions with custom rulesets.

• Defined and automated SOAR use cases using Demisto, integrated with ServiceNow, Slack, and other tools.

• Delivered security metrics, KPIs/KRIs, and compliance dashboards via Power BI. Morgan Stanley - Lead Internal Software based Vulnerability Management Apr 2017 – Mar 2018

• Built a service for managing non-patchable vulnerabilities and large-scale incidents.

• Assessed risks using CVSS v3; defined KPIs, KRIs, and remediation standards.

• Automated security testing via CI/CD; enhanced protocols using diverse programming languages.

• Reviewed source code and led remediation with BU stakeholders.

• Developed SOAR workflows triggered by Splunk, managed patchable and emergency fixes.

• Remediated critical identity infrastructure vulnerabilities across Kerberos, LDAP, Active Directory, and Windows environments—enforcing authentication standards and access controls to reduce enterprise identity risk.

• Reported metrics to leadership; documented plans in Archer/OpenPages.

• Led cross-unit meetings and effectively negotiated risk solutions.

• Navigated a high-complexity, high-threat enterprise environment at Morgan Stanley— developing repeatable processes for large-scale incident handling, cross-unit risk negotiation, and vulnerability remediation that built the foundation for scalable security operations.

Bombardier Aerospace, Montreal (Sr. Information Security Advisor) Jan 2012 – Jan 2017

• Led vulnerability management, application security, and incident response initiatives.

• Ensured Bombardier and industry compliance across projects and infrastructure.

• Developed identity and security requirements using LDAP, SAML 2.0, OAuth 2.0, WAF, Fortify, Qualys, and Splunk—designing federation and SSO integrations for cloud and on-premises applications in compliance with FAA, NIST, and ISO 27001.

• Performed threat modeling, risk assessments, and architecture/security reviews.

• Managed secure IAM integration for AWS and Azure cloud migration—designing identity lifecycle management, access control models, and federation patterns to ensure consistent identity enforcement across hybrid environments.

• Delivered FAA, CT, NIST & ISO compliance certifications.

• Led SOAR automation using Demisto with Qualys, ServiceNow, Splunk, and McAfee.

• Maintained F5 WAF policies and developed Python scripts for automation.

• Held monthly security meetings and promoted internal policy compliance.

• Automated SOAR incident response workflows using Demisto, integrating Qualys, ServiceNow, Splunk, and McAfee to streamline identity-related incident handling, access violation alerting, and compliance reporting.

Bhushan Bhuvanagiri

Ph No: +1-813-***-****; E-mail: ***********************@*****.*** https://www.linkedin.com/in/bhushan-bhuvanagiri/

HSBC, Vancouver (Sr. Security Consultant) Jan 2011 – Jan 2012

• Performed manual penetration testing and evaluated attack success rates on internal and external applications.

• Executed exploits and conducted risk assessments using CVSS v2 scoring.

• Conducted vulnerability and security assessments on web, mobile, API, and green screen applications at HSBC.

• Analyzed false positives and managed exclusion processes.

• Tested portal environments with J2EE, SSO, fraud management, virtual keyboards, and multi-factor authentication.

• Used tools like Web Inspect, Fortify, AppScan, Burp Suite, Rapid7, Nessus, and Qualys.

• Executed attacks including XSS, SQL injection, and parameter tampering.

• Managed client relationships and provided risk analysis with mitigation aligned to NIST, FIM, and MEI standards.

• Assessed SSO, MFA, and multi-factor authentication implementations within J2EE portal environments—testing identity and access controls including federated login flows, virtual keyboards, and fraud management for HSBC’s flagship banking applications. Aviva Solutions, Montréal (Java & .NET Developer / Security Engineer) Jan 2009 – Jul 2010

• Developed Java and .NET applications supporting Aviva’s Security Program aligned with company policies.

• Reviewed security threats and assessed severity from bulletins for Aviva products.

• Conducted threat analysis workshops and planned remediation per vendor release schedules.

• Performed manual penetration testing and ensured secure code design in SDLC.

• Created Secure Code Design standards, source code review services, and remediation plans.

• Reviewed security architecture and implemented multi-layered network defense and access controls.

• Led incident response activities include forensics, penetration testing, and vulnerability scans.

• Developed infrastructure and security policies per ISO27002 standards.

• Managed network security, firewall validation, and client relationships at senior levels.

• Designed and enforced multi-layered network defense, access controls, and identity governance policies per ISO 27002—supporting Aviva’s Security Program through secure application development and incident response across Java and .NET platforms. ISAIX Technologies, Montréal (Web application Pénétration Tester) Jan 2008 – Dec 2008

• Conducted manual penetration testing to ensure applications are free from common attacks.

• Researched, implemented, and deployed internal security tools for enhanced system visibility.

• Assessed vulnerabilities using CVSS standards and prioritized based on severity.

• Performed both automated and manual security testing across Web, Mobile, API, and standalone apps.

• Executed penetration testing on ISAIX’s web banking platform using tools like AppScan, Metasploit, Nessus, Acunetix, and more.

Bhushan Bhuvanagiri

Ph No: +1-813-***-****; E-mail: ***********************@*****.*** https://www.linkedin.com/in/bhushan-bhuvanagiri/

• Documented risks and delivered 3-level technical reports outlining vulnerabilities and proposed improvements.

• Delivered multi-level technical reports documenting vulnerability findings, risk assessments, and remediation recommendations—providing actionable guidance to management on identity and application security improvements. Auto TEC Embedded Solutions, India (Java Developer) Aug2004 – Dec 2006

• Developed app security requirements based on OWASP, COBIT, ISO27000, and CVSS.

• Conducted code reviews, security scans, and vulnerability assessments.

• Deployed secure 3-tier Java apps with LDAP/Active Directory integration.

• Implemented mitigative controls to address security threats.

• Collaborated with internal teams and third parties for vulnerability remediation.

• Built secure apps for banking, airline, and government sectors using Java, PHP, and .NET.

• Led GE Money web banking project with ISO27000 compliance and mainframe integration

• Gained foundational expertise in secure application development and identity integration across banking, airline, and government sectors—deploying LDAP/Active Directory- integrated Java applications and supporting ISO 27000 compliance for GE Money web banking.

EDUCATION

Master of Engineering (Information Systems Security) Jan 2007 – Dec 2008 Concordia University, Montreal, QC, Canada. GPA: 3.71



Contact this candidate