AI security / cloud defence

Secure systems that
can think and act.

Security architecture for LLM agents and the cloud systems around them—grounded in software engineering, identity, detection, and operational reality.

Security before autonomyControls at every boundaryEvidence over assumptions
01Focus

The agent is only one part of the attack surface.

The useful unit of security is the whole system: model, identity, data, tools, infrastructure, and the people operating it.

01MODEL → TOOL

Agentic systems security

Threat modelling and controls for systems that combine models, data, tools, memory, and autonomous action.

  • Trust boundaries
  • Identity and permissions
  • Data and prompt controls
  • Evaluation and guardrails
02DATA → MODEL

Secure AI platforms

Cloud foundations for training, fine-tuning, and serving models with governance built into the platform.

  • Azure and GCP architecture
  • MLOps security baselines
  • Workload identity
  • Telemetry and governance
03EVENT → SIGNAL

Detection engineering

Security operations that connect useful telemetry to detections, triage, and repeatable response.

  • SIEM architecture
  • Custom detection rules
  • MITRE ATT&CK mapping
  • Response playbooks
02Selected work

Current work, described without the theatre.

Representative architecture and engineering engagements. Client identities remain private; sectors and scope are shown as they appear in the underlying experience.

01

Cyber defence AI platform

2024—2026

Energy sector

Architecture for securely training, fine-tuning, and serving open-source LLMs, with identity controls across model APIs, data stores, and compute. Security telemetry feeds an AI-assisted threat-detection system.

LLM infrastructureAccess controlAI governance
Environment

Azure · Entra ID · Sentinel · Defender XDR · MLOps

02

Central SIEM architecture

2026—present

IP management

Target architecture for central log ingestion and threat detection, including custom rules, parsing, response playbooks, triage workflows, and onboarding runbooks for new sources.

SIEMDetection engineeringIncident operations
Environment

Google SecOps · Entra ID · Defender · Meraki · MongoDB Atlas

03

Multi-cloud security operations

2021—2024

Energy sector

Security frameworks for endpoints and digital identities, core SIEM infrastructure, Azure Active Directory assessments, and policies for interconnected cloud platforms.

Cloud securityIdentitySecurity operations
Environment

AWS · Azure · IAM · SIEM · Endpoint security

03Approach

Architecture first. Controls second. Evidence throughout.

A compact method for moving from a diagram to controls that can be operated, observed, and improved.

  1. 01

    Map the system

    Trace trust boundaries, data flows, identities, tool access, operators, and the assumptions between them.

    surface.map()
  2. 02

    Constrain the action

    Use scoped identity, policy, isolation, approvals, and bounded tool interfaces to limit what failure can reach.

    access.bound()
  3. 03

    Instrument the path

    Capture the signals needed to explain a decision, investigate an event, and improve detections over time.

    trace.observe()
  4. 04

    Test failure modes

    Exercise misuse, prompt injection, excessive agency, data leakage, and operational recovery before production does.

    failure.test()
04Background

Security built on an engineering foundation.

newman.ai draws on 16 years across software engineering, platform reliability, cloud architecture, and defence operations.

N/

Engineering depth

Company foundation

The company perspective is deliberately end-to-end: how software is built, how cloud platforms are operated, and how defenders see and contain failure. That is the same perspective applied to agentic systems.

16
years of experience
3
cloud platforms
5
engineering stages
Production software and platform engineeringCloud architecture and security operations
  1. 2010—2016

    Software engineering

    Microservices, web platforms, and technical team leadership.

  2. 2016—2018

    SRE & platform engineering

    Container infrastructure, CI/CD, staging, and runtime architecture.

  3. 2018—2021

    Multi-cloud architecture

    AWS, Azure, and GCP platforms, networking, automation, and governance.

  4. 2021—2024

    Cloud security architecture

    SOC, SIEM, identity, endpoints, governance, and security at scale.

  5. 2024—now

    AI & security engineering

    Secure LLM platforms, AI-assisted detection, SecOps, and AI governance.

Working set
PythonTypeScriptGoKubernetesTerraformAzureGCPAWSLangChainRAGVector databasesSIEMCSPMXDRMITRE ATT&CK

Start with context

Bring the architecture,
the threat model, or one hard question.

A useful first note includes what the system can access, what it can change, and what failure would matter most.

Write to [email protected] Direct email · technical context welcome