Skip to content
+1 212 882 1455

Selectively available for executive advisory

Shimon Wright

Applied AI Product Builder · Forward Deployed Engineering · 26 Years in the FieldI build AI enabled products from real operational problems: 3 systems in production, 7 in development. Each one is designed from 26 years embedded in high friction environments, including Indonesian swamps, ships at sea, remote mines in Oman, and datacenters wired into Mozambique mining operations, where cybersecurity, service delivery, and GRC failures had consequences.

/01Applied AI Products/02Cybersecurity & GRC/03Service Delivery
$17B+pipeline assured
139firms led as Interim CISO
37,000+restaurants transformed
99.9%uptime, regulated biopharma
Applied AI ProductsCybersecurity & GRCService Delivery
§ 01/ Projects

Live applied-AI systems,shipped & fit for use.

My projects represent solutions I built directly from real-world field experience accumulated across 26 years in technology. Each project was shaped by operational pain, delivery challenges, risk patterns, or recurring inefficiencies I encountered throughout my career.

Project
Blind Truth Commons
Role
Architect & Builder
Year
2026
Status
Live · Developing

An MSP-internal delivery-assurance, certification-readiness and early-warning platform that finds structural delivery risk before the client does, closing the gap between green-status reporting and the fragmented evidence behind obligations, owners, controls and risk.

Problem

Providers sell maturity, governance and delivery confidence, but once an account moves into operations the proof is scattered across SOWs, RACI, risk registers, minutes and status reports. Dashboards stay green while weak signals are normalized until they become escalations, disputes or margin leakage.

Solution

Blind Truth Commons is an evidence-graph assurance layer: it ingests account packets, extracts obligations and deliverables with cited source spans, maps them to Service Critical Success Factors, detects risk emissions, monitors critical-path health, and routes material findings into human review, producing an explainable Delivery Assurance State.

Capabilities

MSP-internal assuranceVersioned packet ingestionGrounded AI extractionEvidence graphService CSF matrixRisk-emission detectionCritical-path monitoringTiered human reviewInternal / shareable reports

Governance & Compliance

AI Governance & Assurance

EU AI ActNIST AI RMFNIST GenAI Profile (600-1)ISO/IEC 42001ISO/IEC 23894

LLM / AI Security

OWASP LLM Top 10MITRE ATLAS

Information Security

SOC 2 Type IIISO/IEC 27001NIST CSF 2.0NIST SP 800-53

Privacy & Data Protection

GDPRISO/IEC 27701 (PIMS)CCPA / CPRACOPPA (minors' data)
§ 02/ Capabilities

Three disciplines.One operating model.

01

Applied AI Engineering

From problem framing to shipped product: architecture, prototyping, and end-to-end secure delivery.

  • 01Product discovery & problem framing: operational pain to product definition, MVP wedge, acceptance criteria
  • 02Agentic workflow & multi-agent system design: orchestration, tool-use, human checkpoints
  • 03LLM application architecture: retrieval (RAG), structured extraction, evaluation & confidence scoring
  • 04Rapid AI prototyping: field problem to deployed solution
  • 05Full-stack product delivery: Next.js, React, TypeScript, Supabase/Postgres, Vercel; three systems in production
  • 06Operational instrumentation & analytics: dashboards, said-vs-done metrics, decision-support views
  • 07Human-in-the-loop AI design: oversight, approval gates, evidence preservation
  • 08Enterprise AI adoption & governance-by-design: CoE and paved-road patterns; NIST AI RMF / EU AI Act readiness
02

Cybersecurity & GRC

The enterprise depth behind the builds

  • 01Secure-by-design product & platform architecture
  • 02CISO and embedded security leadership
  • 03Enterprise deal risk and board level cyber assurance
  • 04Audit, assurance & control governance: ISO 27001, NIST CSF
  • 05Incident response and on-the-ground crisis command
  • 06External cyber risk and security rating remediation
03

Service Delivery

The enterprise depth behind the builds

  • 01Transition, transformation & migration governance
  • 02Global ITSM and 24×7 operations
  • 03SLA recovery and cost optimization programs
  • 04Incident, change, problem & configuration management
  • 05Embedded, distributed team & remote-field leadership
  • 06Executive and client governance reporting
§ 03/ Engagements

Experience, throughmultiple lenses.

The field record behind the products: environments I was trusted to operate inside.

14Selected engagements
3Capability areas
12Industries
2000-26Career span
14 / 14 shown
  1. Founded a field-to-product studio translating 26+ years of cybersecurity, service delivery, GRC and transformation experience into a portfolio of 10 AI, data and workflow applications, spanning federated incident response, audit automation, deal intelligence, service-delivery assurance and governed execution.

    10applications built
    26+years translated
    Fieldto product
    Applied AICybersecurityService Delivery
  2. Advised Group-level cybersecurity and deal-risk governance across enterprise pursuits, M&A and high-value contracts, turning fragmented commercial, legal, delivery and security evidence into executive-ready risk decisions.

    85+risk reviews
    $17B+contract value
    35%cycle-time cut
    CybersecurityService Delivery
  3. Ran Capgemini’s external cyber-risk function, driving public security ratings upward and clearing score issues that were blocking major deals and renewals through a governed validation, remediation and evidence lifecycle.

    730→740BitSight rating
    80→100SecurityScorecard
    E2Efinding lifecycle
    CybersecurityService Delivery
  4. Led global cybersecurity, GRC and audit/assurance for a major QSR digital-retail account covering 23 delivery locations within a ~37,000+ site estate. Authored the enterprise security plan, stood up the GRC operating model, and commanded crisis response.

    37,000+sites transformed
    €560Mexposure avoided
    23sites audited / yr
    CybersecurityService Delivery
  5. Delivered secure-by-design strategy for connected-vehicle systems, including telematics, firmware, OTA pipelines, ECU and in-vehicle networks, and third-party components, aligned to ISO/SAE 21434, ENISA and Auto-ISAC practices.

    ISO/SAE21434 alignment
    OTAfirmware & ECU security
    Auto-ISACpractices applied
    Cybersecurity
  6. Governed cybersecurity and operations across vessel and shoreside environments, covering payment and guest-data protection, cloud/IoT exposure, and ship-to-shore continuity for globally distributed maritime operations.

    Fleetship + shoreside
    15security / ops team
    IoTcloud & guest data
    CybersecurityService Delivery
  7. Client-badged Interim CISO for a federated network of ~139 member firms across 130 countries, building the global incident-response and threat-flash model (later the basis for GIRP) across firms with shared brand exposure but uneven security maturity.

    139member firms
    130countries
    ~50%faster response
    CybersecurityService Delivery
  8. Security and test-governance lead for a data-center transformation into a managed model, building the Pathfinder validation process, RACI and tracking dashboard, and governing SAT/UAT, DR validation and go-live across migration waves.

    Pathfindervalidation process
    SAT/UAT& DR validation
    Azuresecurity plan
    CybersecurityService Delivery
  9. Led delivery for regulated biopharma data-center hosting, reshaping configuration management and promote-to-production discipline, aligning incident priority to business impact, and hardening secure-hosting hygiene with CyberArk, ArcSight and Splunk.

    124delivery team
    MTTRreduced via SIEM
    Configmgmt redesign
    Service DeliveryCybersecurity
  10. Ran regional hosting and service delivery across ~15 countries for remote metals, mining, port and logistics operations, from Indonesian swamp sites to the Port of Nacala, where a technical failure meant stalled ore, demurrage exposure and SLA penalties.

    15countries
    $40K/hrloss avoided
    ~$500KSLA penalties recovered
    Service Delivery
  11. Delivered NERC CIP critical-infrastructure remediation for a utility energy-market environment, standing up the CIP-defined access points (Cisco ASA), switching and management tooling across primary and backup data centers, with as-built security documentation.

    NERC CIPSCADA remediation
    ASA 5540CIP access points
    CiscoWorksLMS / NCM
    Cybersecurity
  12. Provided security architecture and engineering for new EDS technology offerings before launch, running Design- and Build-Phase Security Assessments, engineering multi-context Cisco ASA firewalls and PCI-DSS SSL VPN, and turning SOW, SLA and scan evidence into implementation-ready guidance.

    PCI DSSSSL VPN engineered
    ASAmulti-context active/active
    DPSA/BPSAdesign & build reviews
    Cybersecurity
  13. Ran retail enterprise infrastructure across Windows, Unix and Exchange, piloting Active Directory, engineering an NLB Terminal Server / thin-client estate of 172 Wyse appliances, and standing up secure Solaris DNS/FTP on BIND.

    172Wyse thin clients
    ADpilot & scripting
    BINDsecure DNS / FTP
    Service DeliveryCybersecurity
  14. Managed service desk and end-user operations for ~1,100 retail users across New York, Virginia and North Carolina, including Tier 1/2 escalation and SLAs, while expanding into Unix, DNS and Exchange administration, patching and secure remote access.

    1,100users supported
    3states covered
    Tier 1/2escalation & SLA
    Service Delivery
§ 04/ Let's Work Together

Available to lead,advise, build &transform.

© 2026 · Shimon Wright
LDN --:--:--NYC --:--:--