I build systems that act safe enough to run where mistakes matter most. First for cloud. Now for AI.

Twenty-plus years running infrastructure for Fortune 500 financial institutions. Right now: leading the infrastructure & cloud workstream of the largest U.S. bank merger to close in 2026, and building AI platforms on the Governed AI Autonomy framework — where an agent earns the right to act only once it is governed along four dimensions: controlled, observable, evaluable, and auditable. None of those are machine-learning research problems. They’re infrastructure, platform, and security disciplines — the same disciplines I’ve spent my career on.

✦ About

The work I’m doing right now.

Most of my career has centered on running large, regulated infrastructure — enterprise cloud, data center, and platform modernization at Fortune 500 financial institutions, with P&L accountability up to $30M and teams of 80+, currently through one of the largest U.S. bank mergers to close this decade. It’s the kind of environment where a mistake doesn’t show up in a retro. It shows up in an OCC exam.

$30M+Annual budget owned
80+Technology professionals led
$4.5MAnnualized savings delivered
6Engineering teams managed

The last two years taught me something the title never quite captured: how to turn an AI strategy slide into software that ships. I design and build production agentic AI systems, and I publish them openly — along with the evaluation harnesses — so the models can be independently tested rather than taken on trust.

That combination is the point. Infrastructure and security leaders already think in controls, blast radius, and audit evidence, which is exactly what AI autonomy in a regulated environment requires. I write about this as Governed AI Autonomy: an agent’s authority should be bounded by architecture, its activity visible in real time, its decisions reconstructable by an examiner, and its correctness measured rather than assumed.

Twenty years of technology leadership converge on one idea for me now: AI stops being a slide and becomes a system the moment someone insists it ships — and stays accountable for what it finds.

✦ Work

Case studies

Nura and Neo aren’t products. They’re reference implementations, published open at nuratrix.com to find out whether Governed AI Autonomy actually holds up against real infrastructure. The claims below are meant to be checked — the rules, the scoring weights, and the tool boundaries are all in the repo. If a control leaks, a score is wrong, or an agent acts outside its boundary, that’s the finding I want, and the issue tracker is where it belongs.

Nura - AWS AI Governance Platform

Multi-agent AI · Amazon Bedrock · Open reference implementation

Nine specialized agents — Security, Infrastructure, Compliance, Cost, Cost Anomaly, Incident, Network Security, Access Analyzer, and Backup/DR — under an Orchestrator on Amazon Bedrock. Built to test a single claim: that an agent can hold real authority over a cloud estate without an examiner losing the thread. Every boundary below is a design bet, and every one of them is inspectable.

  • Grounding is enforced, not requested. Every agent must call run_scan before it answers — never from training knowledge. The interesting test is whether you can get one to answer without scanning
  • The model judges; it never routes. Checker selection and compliance control-ID mapping are static configuration, so scans stay exhaustive and reproducible. Same account, same run, same finding set
  • Blast radius is architectural. LOW/MEDIUM findings receive written guidance on the finding record — no customer infrastructure is modified. HIGH/CRITICAL escalate to a human over SNS
  • 50+ machine-readable governance rules per domain (SEC-IAM-001: root account used → CRITICAL), cross-account scanning through least-privilege read-only roles, findings keyed in DynamoDB across accounts
  • Measured against the manual baseline it replaces: 2–3 hours per account per week of human security review, now continuous and auditable

Read the full case study →

Neo — Autonomous Vulnerability Management

Model Context Protocol · Risk Engine · Open reference implementation

An MCP-native vulnerability engine that unifies findings across AWS Inspector v2, Security Hub, Azure Defender, GCP Security Command Center, Nessus, Qualys, and Rapid7, then scores them with an explainable model instead of raw CVSS. Published specifically so the scoring can be argued with — a risk model nobody can inspect is just a number with confidence attached.

  • The formula is the argument. risk = likelihood (EPSS) × impact (CVSS) × exposure_factor × 100, with a hard override: CISA KEV on a public asset always scores P1. The weights are a judgment call — disagree with them against your own data, in the open
  • SLA tiers derived from the score, not assigned by hand — P1 (≥40, 24h), P2 (≥20, 7d), P3 (≥8, 30d), P4 (<8, maintenance window)
  • Reach is the tool list, not the prompt. The MCP server is the authority boundary: zero-write IAM, per-customer KMS isolation, structured audit records on every call, and a human review gate on every remediation PR
  • Runs credential-free in mock mode, so the whole scoring and escalation path can be exercised end to end before anyone points it at a real estate

Read the full case study →

✦ Writing

What I argue in public

✦ Experience

Where this happened

Feb 2026 – Present

Director, Platform Engineering

Fifth Third Bank (acquired Comerica Bank, Feb 2026) · Frisco, TX

Elected to lead platform engineering through the Fifth Third–Comerica integration — the largest U.S. bank merger to close in 2026 — consolidating infrastructure across a combined ~$294B estate.

Nov 2023 – Feb 2026

Senior Manager, VP, Infrastructure

Comerica Bank · Frisco, TX

Executive accountability for enterprise infrastructure strategy across a $75B commercial bank — 80+ technology professionals, $30M+ annual budget. Delivered $4.5M in annualized cost savings, migrated 80% of legacy workloads to AWS, and led SOX/OCC/Federal Reserve audit cycles to zero material findings.

Jun 2018 – Nov 2023

Vice President — Senior Architect

Bank of America · Plano, TX

Directed CEWS platform consolidation and founding-member work on the Cloud Technology Focus Group, establishing the AWS governance framework adopted across 40+ business units.

Apr 2013 – Jun 2018

Principal Cloud Architect

TantaComm · Middleton, WI

Drove the architecture and commercial launch of a multi-tenant SaaS contact center platform on Azure/AWS — 50+ enterprise clients at 99.95% SLA, $15M+ in new contracts as technical advisor to business development.

2004 – 2013

Earlier career

Solution Architect / Technical Lead, Enterprise Computing Services · Software Engineer, Hardware Resources Inc.

✦ Expertise

What I build with

  • AI & Autonomous Systems: Amazon Bedrock · Model Context Protocol (MCP) · Multi-Agent Orchestration · Agentic AI · EPSS Threat Intelligence · CISA KEV · Autonomous Risk Scoring · AI-Native SaaS Architecture
  • Cloud & Infrastructure: AWS (EC2, VPC, S3, RDS, Lambda, ECS/EKS, Inspector v2, Security Hub, EventBridge, SQS, Cognito, KMS, CloudFront, API Gateway) · Azure (Defender for Cloud, AKS) · GCP (Security Command Center) · Kubernetes · Terraform · Ansible
  • Security & Governance: Multi-Tenant Security Architecture · KMS Encryption · Cross-Account IAM · Zero Trust · SOX / OCC / Federal Reserve Board (FRB) · Vulnerability Management (Qualys) · Autonomous Compliance Automation
  • Development: Python · .NET / C# · React · Node.js · PowerShell · RESTful APIs · Microservices · CI/CD (GitHub Actions, Jenkins)

✦ Contact

Let’s talk about what’s next.

Frisco, TX · (337) 781-9716 · Prefer a quick overview first? Ask for my résumé.