What I do
I design security architectures for regulated environments — cloud-native, Zero Trust, AI governance — where the cost of getting it wrong is measured in regulatory sanctions and reputational damage, not just technical debt.
My foundation is engineering. I started writing code in 1981, which means I've been thinking about how systems break for longer than most security frameworks have existed — and I approach risk as a systems problem rather than a compliance exercise.
My path into security came through software. I built full-stack applications and custom security tooling before security frameworks as we know them today existed — which means when I design a control, I already understand the system it has to live inside.
For the past decade, my focus has been financial services — banks, payment systems, regulated platforms — where security architecture has to satisfy regulators, survive audits, and still let the product move.
I've been writing about technology and the open web, online and at Island in the Net, since 1999. Thinking in public over two decades forces a kind of intellectual honesty that doesn't survive in slide decks.
Work Experience
Lead Cybersecurity Architect / Vice President
- Collaborate on security architecture strategy across cloud and on-premises financial platforms, aligning cybersecurity objectives with business and risk requirements
- Partner with Cybersecurity, Engineering, and Technology teams to integrate security into SDLC, DevOps, and Agile environments
Security Solutions Architect
- Security architecture assessments, threat modelling, and risk assessment for on-premises and cloud applications
- Evaluated risk to information assets against industry standards and regulatory requirements
Senior Security Architect
- In-depth reviews of on-premises applications against corporate security policy and regulatory requirements
- Threat models anticipating attack vectors, prioritised by business impact
Principal Security Consultant
My own independent security architecture practice. Senior security architecture, risk assessment, and compliance leadership for financial services, fintech, and government clients. Every engagement principal-led — no junior staff, no subcontractors.
- Led a remote team of senior security architects across the US and Mexico
- Security assessments spanning hardware, applications, networks, and data systems
- Frameworks and policy work aligned to GDPR, ISO 27001, FINRA, FFIEC, NYDFS, and SOX
- Reported directly to the Director of Information Security
- Conducted cybersecurity architecture assessments of applications, including threat assessments
- Recommended architectural changes to mitigate identified threats and risks
- Frameworks and policy work aligned to GDPR, ISO 27001, FINRA, FFIEC, NYDFS, and SOX
- Cross functional collaboration to build an internal security controls framework drawing on NIST CSF, COBIT, and CIS Critical Security Controls
- Led the redesign of application security architecture for online payments to achieve PCI DSS compliance
- Broader security policy work, partnering directly with the Director of Security
- Reported directly to the Director of Information Security
- Authored security hardening standards for Linux and Windows
- Reorganised the vulnerability management programme: the existing process relied on a junior technician who could operate the scanning tool but not triage results for application and server teams — built the triage process and wrote the vulnerability programme guidelines
- Created the incident response programme from scratch; ran Secure SDLC training and incident-readiness tabletop exercises
- Established separation of duties between teams
- Guided the organisation through PCI DSS audits to successful certification
Senior Security Advisor
- Strategic and technical leadership for BMS's enterprise information security programme in a global, regulated environment
- Served as Vulnerability Manager — inherited EVA (Enterprise Vulnerability Assessment) from a predecessor: a Perl/CGI scanning tool built on Nmap and Nessus, running on Solaris with a PostgreSQL backend
- Designed EVA's database access model so only the Solaris host itself could reach the PostgreSQL backend — isolation enforced at the data layer, not just the network
- Renamed and enhanced EVA with a JavaScript/AJAX interface and LDAP-based IAM integration, later refactoring it to PHP
- Built EDEM (Enterprise Detection and Monitoring), a custom web-based vulnerability scanner, from scratch (Perl, CGI, JavaScript, MySQL) — designed and normalised the full database schema and data model
- Built a CMDB compliance application for risk assessment
- Stood up Snort for intrusion detection and deployed an enterprise SIEM; when that project was shelved, built a Bash/Perl log collection and indexing pipeline so the forensics team could search effectively
- Served on the Incident Response team during active breaches and enterprise-level operational issues that impacted security
- Created an AWS account in 2008 and wrote an early whitepaper in 2010 on PKI and digital signatures for DRM
- Policy and governance work aligned to HIPAA, SOX, and FDA requirements; IAM initiatives and security awareness training
Full-Stack Web Developer & IT Systems Consultant
- Full-stack web applications — Linux, Apache, Perl, PHP, JavaScript, HTML, Java, C — built and secured on UNIX/Linux (Solaris, BSD) servers
- Designed and normalised the database schema for a multi-user online training platform built in PHP and JavaScript (2001–2002)
- ETL workflows and enterprise data integration; automation via Perl and shell scripting
Web Application Developer
- Perl CGI scripting for press release publishing and an online job-posting/application system
Web Developer
- Perl CGI for dynamic content, form processing, and server-side logic on Bloomberg's Energy desk
- Independently designed and built a server-side templating system and templating language — predating widely adopted templating frameworks
Associate, Member Technical Staff
- C programming for very-low-bit-rate video encoding — videophone and early MPEG-4 applications
Functional Range
"Lead Cybersecurity Architect" is the title on the org chart. It doesn't capture everything underneath it. The functional roles below are work I have actually done.
Education & certifications
Education
- M.S.E., Electrical Engineering: SystemsConcentration: Information Theory · University of Michigan — Rackham Graduate School
- BE, Electrical and Electronics EngineeringGeorgia Institute of Technology
- BA, PhysicsDrew University
Certifications
- CISSPCertified Information Systems Security Professional · certified since 2004, current cycle to Oct 2028
- CCSPCertified Cloud Security Professional · certified since 2021, current cycle to Sep 2027
- ISSAPInformation Systems Security Architecture Professional · current cycle to Oct 2028
- CRISCCertified in Risk and Information Systems Control · expired May 31, 2022
- AWS Certified Cloud Practitionerissued Apr 2024, valid to Apr 2027
- AWS Certified AI Practitionerissued Dec 2024, valid to Dec 2027
- AWS Certified AI Practitioner — Early Adopter
- ITIL v3Information Technology Infrastructure Library
Writing
Get in touch
Prefer email? Click below to reveal an address rather than have it sit in plain text for every scraper on the internet.
LinkedIn: linkedin.com/in/khurt-williams
Writing: islandinthenet.com