Skip to content

Cloud Security · AI Security · Product Security · GRC

Dr. Kasie Kelvin Awagu, Cybersecurity Executive and AI & Technology Leader

Cybersecurity Executive · AI & Technology Leader

I operate at the intersection of cybersecurity, artificial intelligence, and enterprise risk. I lead security and GRC programs, architect and build secure cloud and AI-driven systems, and then test them the way an attacker would, advising enterprises and high-growth teams from the boardroom to the build.

My work spans cloud security and compliance (SOC 2, ISO 27001, NIST CSF, NIST 800-53), product and application security (secure SDLC, static and dependency analysis, container security, vulnerability management), and AI security and engineering (NIST AI RMF, ISO 42001, OWASP LLM Top 10). The throughline is turning frameworks into programs that earn trust and hold up under scrutiny.

Credentials

PhDCISSPCISSP-ISSAPCCSPCISMC|CISOAIGP
15+
Years in security
PhD
Cyber Defense
10+
Pro certifications
Board
Level advisory
01About

A cybersecurity and technology leader who builds and secures modern cloud and AI-driven systems.

With 15+ years across enterprise security strategy, cloud compliance architecture, and the design of intelligent systems, I help organizations scale securely and operate with confidence, aligning SOC 2, ISO 27001, and NIST programs with the way modern teams actually build.

The practice stays technical. Application and product security, container and cloud-native hardening, vulnerability management, adversarial testing of the AI systems I help design, and the penetration testing that verifies the result. Strategy that has never met an implementation tends not to survive one.

A doctorate in cyber defense paired with deep industry experience means I bring both academic rigor and practical execution to every engagement, from board-level advisory to hands-on security and AI architecture.

02Expertise

Areas of security and AI expertise

Cloud Security & Compliance

Architecting secure cloud environments and turning compliance frameworks into living programs rather than point-in-time audits, so security scales with the business. Federal baselines where the work calls for them.

SOC 2ISO 27001NIST CSFNIST 800-53NIST 800-171CMMC

AI Security & Engineering

I build AI systems as well as govern them. Agentic architectures and LLM applications designed and shipped, then red-teamed for prompt injection, data leakage, and model abuse. The governance sits on top of systems I have actually built.

LLM App SecurityAgentic SystemsNIST AI RMFISO 42001EU AI Act

Product & Application Security

Securing software while it is being written rather than auditing it afterwards: static and dependency analysis, secrets scanning, and secure code review enforced in the pipeline, extended to container images and infrastructure-as-code across the delivery chain. Penetration testing verifies the result.

Secure SDLCSASTSCAContainer SecurityPenetration Testing

Security Leadership & GRC

Leading enterprise security, risk, and governance programs and advising boards, connecting strategy and enterprise architecture to measurable outcomes.

StrategyGRCEnterprise ArchitecturevCISO

Vulnerability & Third-Party Risk

Vulnerability management run as a program rather than a scanner licence, and structured assessment of the vendors and suppliers who quietly inherit your risk.

Vulnerability ManagementTPRMVendor Assessment

Security Engineering

The operational half of the discipline: detection engineering, security operations, and incident response built as one capability, so a problem is seen early and acted on rather than reconstructed after the fact.

Detection EngineeringSecurity OperationsIncident ResponseSIEM

Currently focused on building secure, intelligent systems and the governance that keeps them trustworthy, changing how organizations approach security, automation, and growth.

03Research

Credentials, research, and certifications

Education

PhD, Cyber Defense

Dakota State University

Dissertation: "Analyzing the Effectiveness of Information Security Compliance on Cloud-Based Small and Medium-Sized Enterprises (SMEs)". Beadle Scholar, Dakota State University.

MS, Cyber Defense

Dakota State University

Security & Leadership

CISSPCISSP-ISSAPCISMC|CISOCEH

Cloud & Compliance

CCSPAWS Security SpecialtyCMMC Registered Practitioner

AI & Privacy Governance

AIGPCDPSE

Core Domains

Cloud security & compliance · AI security & AI governance · product & application security · secure SDLC · cloud-native & container security · cybersecurity leadership & GRC · vulnerability management · third-party risk · security engineering & operations · enterprise architecture · threat modeling · penetration testing & validation.

Applied Expertise

Bridging cloud security compliance (SOC 2, ISO 27001, NIST CSF, NIST 800-53, and NIST 800-171 with CMMC readiness) with hands-on product and application security: static and dependency analysis enforced in the pipeline, container and infrastructure-as-code scanning, vulnerability management run as a measured program, and penetration testing to verify it. Alongside it, the design and adversarial testing of modern AI systems (NIST AI RMF, ISO 42001, EU AI Act, OWASP LLM Top 10), across enterprise environments and high-growth organizations.

Memberships & Communities

ISACA, Greater Houston ChapterISC2EC-CouncilIAPPCloud Security Alliance
04Practice

Security engineering, testing, and assurance

Secure Cloud Architecture

Reference architectures, identity and network segmentation, and guardrails written as code, so they hold without anyone having to remember to enforce them.

Infrastructure-as-CodeIAMPolicy-as-Code

AI & LLM Security Testing

Prompt injection, data exfiltration, and model abuse cases run against production systems. This is the practical half of the governance work.

OWASP LLM Top 10Agentic SystemsModel Abuse

Application & Product Security

Static analysis, dependency and secrets scanning, and secure code review wired into CI/CD as gates that block, not dashboards nobody opens. Security that ships with the release rather than trailing it.

SASTSCASecrets ScanningSecure Code ReviewCI/CD Gates

Cloud-Native & Container Security

Image and infrastructure-as-code scanning, registry and Kubernetes hardening, and runtime guardrails, so the workload is defended and not just the compliance boundary drawn around it.

ContainersKubernetesIaC ScanningRuntime

Vulnerability Management

The full lifecycle rather than a scan schedule: discovery, risk-based prioritization, remediation SLAs, and metrics that show whether exposure is actually shrinking.

PrioritizationRemediation SLAsMetrics

Security Engineering

Detection engineering, security operations, and incident response run as one practice rather than three handoffs. Logging pipelines, detection logic, and runbooks written to stay legible at 3am to whoever happens to be on call.

Detection-as-CodeSIEMSecurity OperationsIncident Response

Threat Modeling & Design Review

Attack-path review of systems while they are still on the whiteboard, before design decisions harden into things nobody wants to revisit.

STRIDEAttack Paths

Penetration Testing & Validation

Targeted testing across cloud, web, and network, and validation of third-party pentest reports to separate genuine exploitability from scanner noise before it reaches a remediation queue.

Cloud & WebPentest Validation
05Connect

Get in touch

Open to advisory, leadership, and collaboration at the intersection of security and intelligent systems.

Connect on LinkedIn
© 2026 Dr. Kasie Kelvin Awagu
LinkedIn

Building at the intersection of security, intelligence, and scale.