I build the systems, govern the systems, and defend the evidence.
I work at the intersection of DoW/federal program execution, security · compliance · audit, and hands-on GenAI engineering — turning frameworks into enforced, testable controls and the evidence an assessor will actually accept.
- Governance & compliance: ISO/IEC 42001 (AIMS) Lead Auditor · ISO/IEC 27001 Lead Auditor · ISO/IEC 27701 Lead Auditor · NIST AI RMF · CMMC · CPMAI · pursuing AIGP
- Governance-as-code: fail-closed authority stores, phase gates, detective controls, auditor-ready evidence chains — wired into the runtime, not bolted on
- Hands-on GenAI: agentic systems, multi-provider LLM orchestration, secure-by-design AI
- Federal/DoW program execution: CPMAI lifecycle, ATO/RMF discipline, regulated delivery
dow-ai-pm-builder-template — a governed, provider-neutral AI software factory: 15 accountable agents with a Security & Compliance Officer in every phase gate, fail-closed authority state, and post-dispatch detective controls. The repository audits itself — a control matrix maps every mechanism to ISO/IEC 42001 and NIST AI RMF with per-row verification commands, a Statement of Applicability dispositions every Annex A control, and CI re-verifies the control set on every push. Clone it and run the validation gauntlet; the evidence chain is walkable without me in the room.
The Decisions That Come Before Scale — a free AI lifecycle playbook for regulated environments. It harmonizes CPMAI, ISO/IEC 42001, NIST AI RMF, NIST SP 800-53, and DoW frameworks into one operating model: governance phase gates, a full RACI, risk-and-control mappings, and continuous-compliance monitoring, so accountability is in place before AI scales past the point it can be managed cleanly. Free to download, no sign-up.
- Lliam-GOV — a public, open security-as-code case study testing how far policy, runtime controls, and automated evidence can constrain a frontier-model-capable knowledge-work agent without eliminating useful capability. The repository publishes its self-assessed control baseline, phase evidence, limitations, and capability-preservation results.
- Priora (private) — an AI lifecycle governance platform operationalizing the Decisions playbook.
Lliam-GOV is public and available for inspection. It is an independent research project—not a certification, authorization, or government endorsement.
Reach me through secondorderstrategy.com · open to Compliance / AI Governance leadership roles.



