Cloud Security · AI Security · Product Security · GRC
Dr. Kasie Kelvin Awagu, Cybersecurity Executive and AI & Technology Leader
Cybersecurity Executive · AI & Technology Leader
I operate at the intersection of cybersecurity, artificial intelligence, and enterprise risk. I lead security and GRC programs, architect and build secure cloud and AI-driven systems, and then test them the way an attacker would, advising enterprises and high-growth teams from the boardroom to the build.
My work spans cloud security and compliance (SOC 2, ISO 27001, NIST CSF, NIST 800-53), product and application security (secure SDLC, static and dependency analysis, container security, vulnerability management), and AI security and engineering (NIST AI RMF, ISO 42001, OWASP LLM Top 10). The throughline is turning frameworks into programs that earn trust and hold up under scrutiny.
Credentials
- 15+
- Years in security
- PhD
- Cyber Defense
- 10+
- Pro certifications
- Board
- Level advisory
A cybersecurity and technology leader who builds and secures modern cloud and AI-driven systems.
With 15+ years across enterprise security strategy, cloud compliance architecture, and the design of intelligent systems, I help organizations scale securely and operate with confidence, aligning SOC 2, ISO 27001, and NIST programs with the way modern teams actually build.
The practice stays technical. Application and product security, container and cloud-native hardening, vulnerability management, adversarial testing of the AI systems I help design, and the penetration testing that verifies the result. Strategy that has never met an implementation tends not to survive one.
A doctorate in cyber defense paired with deep industry experience means I bring both academic rigor and practical execution to every engagement, from board-level advisory to hands-on security and AI architecture.
Areas of security and AI expertise
Cloud Security & Compliance
Architecting secure cloud environments and turning compliance frameworks into living programs rather than point-in-time audits, so security scales with the business. Federal baselines where the work calls for them.
AI Security & Engineering
I build AI systems as well as govern them. Agentic architectures and LLM applications designed and shipped, then red-teamed for prompt injection, data leakage, and model abuse. The governance sits on top of systems I have actually built.
Product & Application Security
Securing software while it is being written rather than auditing it afterwards: static and dependency analysis, secrets scanning, and secure code review enforced in the pipeline, extended to container images and infrastructure-as-code across the delivery chain. Penetration testing verifies the result.
Security Leadership & GRC
Leading enterprise security, risk, and governance programs and advising boards, connecting strategy and enterprise architecture to measurable outcomes.
Vulnerability & Third-Party Risk
Vulnerability management run as a program rather than a scanner licence, and structured assessment of the vendors and suppliers who quietly inherit your risk.
Security Engineering
The operational half of the discipline: detection engineering, security operations, and incident response built as one capability, so a problem is seen early and acted on rather than reconstructed after the fact.
Currently focused on building secure, intelligent systems and the governance that keeps them trustworthy, changing how organizations approach security, automation, and growth.
Credentials, research, and certifications
Education
PhD, Cyber Defense
Dakota State University
Dissertation: "Analyzing the Effectiveness of Information Security Compliance on Cloud-Based Small and Medium-Sized Enterprises (SMEs)". Beadle Scholar, Dakota State University.
MS, Cyber Defense
Dakota State University
Security & Leadership
Cloud & Compliance
AI & Privacy Governance
Core Domains
Cloud security & compliance · AI security & AI governance · product & application security · secure SDLC · cloud-native & container security · cybersecurity leadership & GRC · vulnerability management · third-party risk · security engineering & operations · enterprise architecture · threat modeling · penetration testing & validation.
Applied Expertise
Bridging cloud security compliance (SOC 2, ISO 27001, NIST CSF, NIST 800-53, and NIST 800-171 with CMMC readiness) with hands-on product and application security: static and dependency analysis enforced in the pipeline, container and infrastructure-as-code scanning, vulnerability management run as a measured program, and penetration testing to verify it. Alongside it, the design and adversarial testing of modern AI systems (NIST AI RMF, ISO 42001, EU AI Act, OWASP LLM Top 10), across enterprise environments and high-growth organizations.
Memberships & Communities
Security engineering, testing, and assurance
Secure Cloud Architecture
Reference architectures, identity and network segmentation, and guardrails written as code, so they hold without anyone having to remember to enforce them.
AI & LLM Security Testing
Prompt injection, data exfiltration, and model abuse cases run against production systems. This is the practical half of the governance work.
Application & Product Security
Static analysis, dependency and secrets scanning, and secure code review wired into CI/CD as gates that block, not dashboards nobody opens. Security that ships with the release rather than trailing it.
Cloud-Native & Container Security
Image and infrastructure-as-code scanning, registry and Kubernetes hardening, and runtime guardrails, so the workload is defended and not just the compliance boundary drawn around it.
Vulnerability Management
The full lifecycle rather than a scan schedule: discovery, risk-based prioritization, remediation SLAs, and metrics that show whether exposure is actually shrinking.
Security Engineering
Detection engineering, security operations, and incident response run as one practice rather than three handoffs. Logging pipelines, detection logic, and runbooks written to stay legible at 3am to whoever happens to be on call.
Threat Modeling & Design Review
Attack-path review of systems while they are still on the whiteboard, before design decisions harden into things nobody wants to revisit.
Penetration Testing & Validation
Targeted testing across cloud, web, and network, and validation of third-party pentest reports to separate genuine exploitability from scanner noise before it reaches a remediation queue.
Get in touch
Open to advisory, leadership, and collaboration at the intersection of security and intelligent systems.