Skip to content
View jdavis-cyber's full-sized avatar

Block or report jdavis-cyber

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
jdavis-cyber/README.md

Jerome Davis — Executive Architect | AI Governance & Strategy

I build the systems, govern the systems, and defend the evidence.

I work at the intersection of DoW/federal program execution, security · compliance · audit, and hands-on GenAI engineering — turning frameworks into enforced, testable controls and the evidence an assessor will actually accept.

  • Governance & compliance: ISO/IEC 42001 (AIMS) Lead Auditor · ISO/IEC 27001 Lead Auditor · ISO/IEC 27701 Lead Auditor · NIST AI RMF · CMMC · CPMAI · pursuing AIGP
  • Governance-as-code: fail-closed authority stores, phase gates, detective controls, auditor-ready evidence chains — wired into the runtime, not bolted on
  • Hands-on GenAI: agentic systems, multi-provider LLM orchestration, secure-by-design AI
  • Federal/DoW program execution: CPMAI lifecycle, ATO/RMF discipline, regulated delivery

Flagship — DoW AI PM Builder

dow-ai-pm-builder-template — a governed, provider-neutral AI software factory: 15 accountable agents with a Security & Compliance Officer in every phase gate, fail-closed authority state, and post-dispatch detective controls. The repository audits itself — a control matrix maps every mechanism to ISO/IEC 42001 and NIST AI RMF with per-row verification commands, a Statement of Applicability dispositions every Annex A control, and CI re-verifies the control set on every push. Clone it and run the validation gauntlet; the evidence chain is walkable without me in the room.


Writing

The Decisions That Come Before Scale — a free AI lifecycle playbook for regulated environments. It harmonizes CPMAI, ISO/IEC 42001, NIST AI RMF, NIST SP 800-53, and DoW frameworks into one operating model: governance phase gates, a full RACI, risk-and-control mappings, and continuous-compliance monitoring, so accountability is in place before AI scales past the point it can be managed cleanly. Free to download, no sign-up.


Portfolio

  • Lliam-GOV — a public, open security-as-code case study testing how far policy, runtime controls, and automated evidence can constrain a frontier-model-capable knowledge-work agent without eliminating useful capability. The repository publishes its self-assessed control baseline, phase evidence, limitations, and capability-preservation results.
  • Priora (private) — an AI lifecycle governance platform operationalizing the Decisions playbook.

Lliam-GOV is public and available for inspection. It is an independent research project—not a certification, authorization, or government endorsement.


Reach me through secondorderstrategy.com · open to Compliance / AI Governance leadership roles.

Pinned Loading

  1. dow-ai-pm-builder-template dow-ai-pm-builder-template Public

    DoW AI PM Builder Template — Discovery-First AI Software Factory with full DoD governance (CMMC 2.0, FedRAMP, ISO 42001, NIST RMF, ATO)

    Python

  2. decisions-before-scale decisions-before-scale Public

    A free AI lifecycle governance playbook for regulated environments — grounded in CPMAI, ISO/IEC 42001, NIST AI RMF, and DoW frameworks.

  3. lliam-gov lliam-gov Public

    An open security-as-code case study for a capable AI knowledge-work agent, exploring governance patterns for regulated environments.

    Python