Independent consulting practice

Security that ships with the software, not after it.

I help cloud-first engineering organizations build secure-by-default delivery — threat modeling, DevSecOps pipelines, and automated compliance evidence — without slowing the teams down.

Claremont, NC · Remote across the US

20+
Years in engineering leadership
10
Current AWS certifications
3
AWS professional & specialty certs
1
Issued US patent

Six ways engagements usually start

  • Secure SDLC architecture

    A development lifecycle where the secure path is the fast path, so teams follow it because it's easier — not because it's mandated.

    • Threat modeling practice teams actually run
    • Secure coding standards and review gates
    • Automated security testing in the build
    • Reference architectures and golden paths
  • DevSecOps & pipeline integration

    Security controls embedded directly in CI/CD, tuned so the signal is real and the noise doesn't train people to click past it.

    • CI/CD security integration end to end
    • Policy-as-code enforcement
    • SBOM generation and management
    • Secrets lifecycle and rotation
  • Cloud & platform security

    AWS architecture reviewed and hardened against how it will actually be operated, not against a checklist.

    • AWS security architecture review
    • API and perimeter security
    • Container hardening
    • Infrastructure-as-code security
  • Compliance evidence automation

    Audit evidence collected as a by-product of delivery, so compliance stops being a quarterly fire drill.

    • Automated evidence collection
    • Executive dashboards and reporting
    • Vulnerability management SLAs
    • OKRs for security posture
  • Developer enablement

    Toolchains and training that make the security team a multiplier rather than a queue engineering waits in.

    • Secure-by-default toolchains
    • Golden paths for common patterns
    • OWASP and secure coding training
    • Internal platform product ownership
  • Fractional leadership

    Hands-on technical leadership for organizations that need the judgment of a principal engineer without a full-time hire.

    • Vulnerability management and risk reduction
    • Incident response readiness
    • Executive-level technical reporting
    • Cross-functional program leadership

How I work

Most security programs fail on adoption, not on design. The controls are correct, the documentation exists, and engineering routes around all of it because the secure path costs them a week. I start from what delivery already looks like and make the safe route the cheap one.

That means working inside your pipelines and your architecture rather than alongside them — and leaving behind reference implementations, not slide decks. The measure of an engagement is whether the practice survives after I've gone.

Selected experience

Two decades across cloud platforms, data infrastructure, and secure delivery — from petabyte-scale ingest at Oracle to solutions architecture at AWS.

  1. 2023–2025

    Extacom LtdCo-Founder & Partner

    Founded an SDVOSB for federal contracts; negotiated two SBA Mentor-Protégé agreements and achieved AWS Partner status.

  2. 2021–2024

    NCS PearsonPrincipal Cloud Engineer

    Architected and institutionalized secure SDLC practice across a ~50-engineer platform organization.

  3. 2020–2021

    SambaSafetyPrincipal Site Reliability Engineer

    SME to executive technology leadership on reliability, cost optimization, and platform strategy.

  4. 2019–2020

    CSGSoftware Architect

    Led the cross-functional refactor toward microservices and containers with end-to-end automation.

  5. 2018–2019

    Amazon Web ServicesSolutions Architect

    Worldwide Public Sector K-12 EdTech; machine learning specialist and architecture reviewer.

  6. 2015–2017

    OracleConsulting Member of Technical Staff

    Oracle Data Cloud — canonical data models for a petabyte-scale ingest and processing platform.

Ten current AWS certifications, a patent, and two degrees

Certifications

  • AWS Certified Solutions Architect – Professional
  • AWS Certified DevOps Engineer – Professional
  • AWS Certified Security – Specialty
  • AWS Certified Machine Learning Engineer – Associate
  • AWS Certified Data Engineer – Associate
  • AWS Certified Developer – Associate
  • AWS Certified Solutions Architect – Associate
  • AWS Certified SysOps Administrator – Associate
  • AWS Certified AI Practitioner
  • AWS Certified Cloud Practitioner

Education

  • Executive Education, Organizational Leadership — University of Denver
  • M.S. Computer Information Systems, Beta Gamma Sigma — Missouri State University
  • B.S. Computer Information Systems, Finley Fellow — University of Northern Colorado

Patent

Methods and Systems for Network-Based Analysis, Intervention, and AnonymizationUS 10,366,251 B2

Let's talk about the work

If you're carrying security debt into a platform migration, preparing for an audit, or trying to make a security program stick with engineering — that's the conversation I want to have.

jim@wyatt.expert