Shimon Wright
Applied AI Product Builder · Forward Deployed Engineering · 26 Years in the FieldI build AI enabled products from real operational problems: 3 systems in production, 7 in development. Each one is designed from 26 years embedded in high friction environments, including Indonesian swamps, ships at sea, remote mines in Oman, and datacenters wired into Mozambique mining operations, where cybersecurity, service delivery, and GRC failures had consequences.
Live applied-AI systems,shipped & fit for use.
My projects represent solutions I built directly from real-world field experience accumulated across 26 years in technology. Each project was shaped by operational pain, delivery challenges, risk patterns, or recurring inefficiencies I encountered throughout my career.
- Project
- Goal Digger
- Role
- Architect & Builder
- Year
- 2026
- Status
- Live · Production
The Goal Positioning System for an organization: an applied-AI execution-intelligence platform, built end-to-end and shipped live, that turns the intelligence already flowing through everyday dialogue into a structured, visual, OKR-aligned map of where every goal stands.
Context → Response
Observed inside enterprise execution and transformation programs; designed, built, and shipped independently.
Problem
Conversations are full of execution intelligence: decisions, risks, assumptions, dependencies, ownership and strategic intent. It isn't missing; it stays trapped in people's heads and scattered across dialogue, lost or disconnected before it becomes structured execution.
Solution
Like a GPS rather than a recorder, Goal Digger captures that intelligence as it's spoken and maps it against the objectives and key results set during onboarding, producing a live, visual view of where each goal stands, who owns what, what's at risk and what to do next. Meetings and calls are just one input channel, not the product's identity.
Capabilities
Governance & Compliance
AI Governance & Assurance
LLM / AI Security
Information Security
Privacy & Data Protection
Three disciplines.One operating model.
Applied AI Engineering
From problem framing to shipped product: architecture, prototyping, and end-to-end secure delivery.
- 01Product discovery & problem framing: operational pain to product definition, MVP wedge, acceptance criteria
- 02Agentic workflow & multi-agent system design: orchestration, tool-use, human checkpoints
- 03LLM application architecture: retrieval (RAG), structured extraction, evaluation & confidence scoring
- 04Rapid AI prototyping: field problem to deployed solution
- 05Full-stack product delivery: Next.js, React, TypeScript, Supabase/Postgres, Vercel; three systems in production
- 06Operational instrumentation & analytics: dashboards, said-vs-done metrics, decision-support views
- 07Human-in-the-loop AI design: oversight, approval gates, evidence preservation
- 08Enterprise AI adoption & governance-by-design: CoE and paved-road patterns; NIST AI RMF / EU AI Act readiness
Cybersecurity & GRC
The enterprise depth behind the builds
- 01Secure-by-design product & platform architecture
- 02CISO and embedded security leadership
- 03Enterprise deal risk and board level cyber assurance
- 04Audit, assurance & control governance: ISO 27001, NIST CSF
- 05Incident response and on-the-ground crisis command
- 06External cyber risk and security rating remediation
Service Delivery
The enterprise depth behind the builds
- 01Transition, transformation & migration governance
- 02Global ITSM and 24×7 operations
- 03SLA recovery and cost optimization programs
- 04Incident, change, problem & configuration management
- 05Embedded, distributed team & remote-field leadership
- 06Executive and client governance reporting
Experience, throughmultiple lenses.
The field record behind the products: environments I was trusted to operate inside.
Founded a field-to-product studio translating 26+ years of cybersecurity, service delivery, GRC and transformation experience into a portfolio of 10 AI, data and workflow applications, spanning federated incident response, audit automation, deal intelligence, service-delivery assurance and governed execution.
10applications built26+years translatedFieldto productApplied AICybersecurityService DeliveryAdvised Group-level cybersecurity and deal-risk governance across enterprise pursuits, M&A and high-value contracts, turning fragmented commercial, legal, delivery and security evidence into executive-ready risk decisions.
85+risk reviews$17B+contract value35%cycle-time cutCybersecurityService DeliveryRan Capgemini’s external cyber-risk function, driving public security ratings upward and clearing score issues that were blocking major deals and renewals through a governed validation, remediation and evidence lifecycle.
730→740BitSight rating80→100SecurityScorecardE2Efinding lifecycleCybersecurityService DeliveryLed global cybersecurity, GRC and audit/assurance for a major QSR digital-retail account covering 23 delivery locations within a ~37,000+ site estate. Authored the enterprise security plan, stood up the GRC operating model, and commanded crisis response.
37,000+sites transformed€560Mexposure avoided23sites audited / yrCybersecurityService DeliveryDelivered secure-by-design strategy for connected-vehicle systems, including telematics, firmware, OTA pipelines, ECU and in-vehicle networks, and third-party components, aligned to ISO/SAE 21434, ENISA and Auto-ISAC practices.
ISO/SAE21434 alignmentOTAfirmware & ECU securityAuto-ISACpractices appliedCybersecurityGoverned cybersecurity and operations across vessel and shoreside environments, covering payment and guest-data protection, cloud/IoT exposure, and ship-to-shore continuity for globally distributed maritime operations.
Fleetship + shoreside15security / ops teamIoTcloud & guest dataCybersecurityService DeliveryClient-badged Interim CISO for a federated network of ~139 member firms across 130 countries, building the global incident-response and threat-flash model (later the basis for GIRP) across firms with shared brand exposure but uneven security maturity.
139member firms130countries~50%faster responseCybersecurityService DeliverySecurity and test-governance lead for a data-center transformation into a managed model, building the Pathfinder validation process, RACI and tracking dashboard, and governing SAT/UAT, DR validation and go-live across migration waves.
Pathfindervalidation processSAT/UAT& DR validationAzuresecurity planCybersecurityService DeliveryLed delivery for regulated biopharma data-center hosting, reshaping configuration management and promote-to-production discipline, aligning incident priority to business impact, and hardening secure-hosting hygiene with CyberArk, ArcSight and Splunk.
124delivery teamMTTRreduced via SIEMConfigmgmt redesignService DeliveryCybersecurityRan regional hosting and service delivery across ~15 countries for remote metals, mining, port and logistics operations, from Indonesian swamp sites to the Port of Nacala, where a technical failure meant stalled ore, demurrage exposure and SLA penalties.
15countries$40K/hrloss avoided~$500KSLA penalties recoveredService DeliveryDelivered NERC CIP critical-infrastructure remediation for a utility energy-market environment, standing up the CIP-defined access points (Cisco ASA), switching and management tooling across primary and backup data centers, with as-built security documentation.
NERC CIPSCADA remediationASA 5540CIP access pointsCiscoWorksLMS / NCMCybersecurityProvided security architecture and engineering for new EDS technology offerings before launch, running Design- and Build-Phase Security Assessments, engineering multi-context Cisco ASA firewalls and PCI-DSS SSL VPN, and turning SOW, SLA and scan evidence into implementation-ready guidance.
PCI DSSSSL VPN engineeredASAmulti-context active/activeDPSA/BPSAdesign & build reviewsCybersecurityRan retail enterprise infrastructure across Windows, Unix and Exchange, piloting Active Directory, engineering an NLB Terminal Server / thin-client estate of 172 Wyse appliances, and standing up secure Solaris DNS/FTP on BIND.
172Wyse thin clientsADpilot & scriptingBINDsecure DNS / FTPService DeliveryCybersecurityManaged service desk and end-user operations for ~1,100 retail users across New York, Virginia and North Carolina, including Tier 1/2 escalation and SLAs, while expanding into Unix, DNS and Exchange administration, patching and secure remote access.
1,100users supported3states coveredTier 1/2escalation & SLAService Delivery
Available to lead,advise, build &transform.
Currently open to principal AI product architect, solutions architect, and forward-deployed engineering roles. If your team has a hard operational problem, I'd like to hear it. Selectively available for executive advisory.