Open for consulting and new roles
Ulises, Agentic AI Security Architect

Ulises

Agentic AI Security Architect

Open to new opportunities

Hi, I am Ulises.

Agentic AI Security Architect|

I secure cloud environments and build the AI systems that run inside them. Six-plus years across enterprise and MSP environments: I have deployed the full Microsoft Defender suite, Endpoint, Identity, Cloud, Storage, and Office, stood up Sentinel from scratch, led incident response end to end, and architected multiple AI systems, from multi-provider agentic orchestration engines to AI-powered threat hunting.

A lot of that depth did not come from a classroom. I run my own custom labs and build my own projects, breaking and rebuilding systems until the concepts are second nature. That self-driven work is where much of what I know was actually earned.

Certified across the full Microsoft security and AI stack, more than a dozen credentials in all: Security+, SC-100, SC-200, and SC-900 on security; AZ-305 and AZ-104 on cloud and architecture; and a deep AI bench in AI-900, AI-102, AI-103, AB-100, AB-741, and the AI-500 Multi-Agent AI Solutions Expert beta, with AI-200 and CISSP next. If Microsoft makes it, I have probably deployed it, secured it, or automated it.

Cloud Security

Defender XDRSentinelCortex XDRSentinelOneQualysTenableKQLSOARZero TrustConditional AccessIntunePurviewDMARCDefender for CloudSecure ScoreEntra

AI / Agentic

Claude CodeSemantic KernelAzure AI FoundryRAGMCPCopilot StudioOllamaLM StudioDeepSeekKimiGeminiAntigravityHermesGrokNIST AI RMF

Blockchain

Web3 securitySmart contractsWallet securityOn-chain data pipelinesPrediction marketsMarket data APIs

Software Engineering

PythonPowerShellTypeScriptSQLDockerLinuxGitGitHub ActionsCI/CDREST APIsBash
Defender XDRSentinelIntunePurviewMulti-agent systemsModel routingRAG + MCPAir-gapped inferenceKQLMITRE ATT&CKAutonomous KQL agentsAdvanced HuntingWeb3 securitySmart contractsWalletsDeFiEntraConditional AccessPAMMFAPianoChessOceanCustom labsSOARForensicsContainmentRecoveryAzureAWSGoogle CloudM365NIST AI RMFISO 42001EU AI ActOWASP LLMCloud SecurityAgentic AIThreat HuntingBlockchainZero TrustPersonalIncident ResponseCloud PlatformsAI Governance10000111011100110010010001101011010000110010001111111111000000010111101001111111011100111110011100100000001011000001011101011000000100110001010001001111010111101100010101011010001101ULISES

Hover a node to explore each domain and its stack.

0+
Years in cloud security and AI
0+
Professional certifications
0+
Tools and platforms mastered

About

Who I am

I started in IT support and worked my way into the center of cloud security. Over six-plus years I have gone from resolving tickets to leading detection engineering, incident response, and Zero Trust programs, and now to architecting the agentic AI systems that security teams will run on.

What I care about is making systems real and durable, not just secure. I bring the same discipline to cloud security, identity, and operations that I bring to software engineering: controls and processes that are engineered, compliant, and repeatable, never one-off heroics. I build automation that is self-learning and self-healing, wrapped in security controls that stay tightly guarded, so the system improves itself and recovers on its own without ever loosening the guardrails.

In practice that means hunting with KQL mapped to MITRE ATT&CK, automating response so teams scale, hardening identity and cloud to Zero Trust, and designing AI governance so new technology gets adopted safely. I am equally at home on an incident bridge and in a strategy planning session, translating deep technical work into risk and business terms.

And it is not only for the enterprise. The same skills turn personal projects and everyday errands into automated, self-running systems, and build finance tools that help people actually earn. Whether you are a company hardening its stack or a person trying to save hours and make money, I build for both work and life.

Right now I am focused on the intersection that matters most: as AI gets more autonomy, the security of the system around it becomes the product. That is what I build.

At a glance

  • Cloud security and SOC operations
  • Agentic AI architecture and safety
  • AI solutions and cost-cutting consulting
  • Zero Trust and identity
  • AI governance for regulated fields
  • Remote, and open to relocation

Raised Microsoft Secure Score from 35% to the 80 to 85% band for multiple clients, with no outages and no major operational disruption.

Deployed the full Defender suite top to bottom: Endpoint, Identity, Cloud, Storage, and Office, rolled out through ringed pilot groups.

Architected and hardened cloud infrastructure across Azure, Microsoft 365, and AWS, with network segmentation, workload protection, and identity-aware access.

Built a Zero Trust identity program with Conditional Access, Identity Protection, self-service password reset, and token protection, and drove email to full DMARC enforcement.

Engineered a multi-provider agentic AI engine with air-gapped inference for high-sensitivity security data.

Authored the AI governance program, the policies and controls that keep AI safe, legal, and accountable, aligned to NIST AI RMF, ISO/IEC 42001, the EU AI Act, and HHS AI strategy.

Off the clock

Chess, lots of chess

Pattern recognition, calculated risk, thinking three moves ahead. It is the same muscle I use in threat hunting.

Piano

Discipline and precision with an output you can feel. The practice habit transfers to everything else I do.

Reading strategy

Robert Greene is my favorite author, The 48 Laws of Power especially. I read for how people and systems actually behave.

Building, not gaming

Surprisingly, no video games. My free compute goes into agentic AI side projects and market-data systems instead.

What I build for companies

AI solutions that pay for themselves

Merging AI and security is my specialty, but it is not the whole story. I design AI solutions for whatever eats a company's time and money, then wire in the backend security mindset most builders skip. The goal is always the same: cut costs with the minimum of effort, and ship something you can actually run.

Customer response automation

Agents that read incoming email, draft on-brand replies, resolve the routine ones automatically, and escalate the rest to a human with full context attached.

Cuts response time and support hours

Automatic detection and pager duty

Detectors over your logs, metrics, and alerts with severity-based paging: the right person gets woken up only when it matters, with the evidence already gathered.

Cuts alert fatigue and missed incidents

Revenue and market engines

Signal-grading systems that score opportunities, track their own accuracy, and earn influence from results. My PolyMind market intelligence platform is the working proof.

Cuts research hours, compounds edge

Back-office automation

Reports, intake, ticket triage, scheduling, knowledge bases: the repetitive paperwork layer of a business, automated with human approval exactly where it counts.

Cuts manual admin to near zero

Security copilots

KQL-writing hunt agents, alert triage assistants, and incident summarizers that let a small security team operate like a large one.

Cuts triage time and analyst burnout

AI strategy and new ideas

Not sure where AI fits your company? I map your workflows, find the highest-ROI target, and ship a working pilot fast. Consulting that ends in software, not slideware.

Cuts the guesswork out of AI adoption

The difference in my builds: every solution ships with the security backend baked in. Least privilege, logged actions, human gates on consequential steps, and sensitive data kept where it belongs. That is the gap between an AI demo and an AI system a company can trust in production.

How I work

Principles I build on

Secure by design

I build security in from the first line, not bolted on after the fact.

Compliant and auditable

Every control documented, approved, reversible, and mapped to a framework.

Automate the repeatable

SOAR playbooks, KQL libraries, and scripts so the team scales without burning out.

Translate to the business

I frame security in risk and regulatory terms that leaders can act on.

Capabilities

What I work with

AI models and their ecosystems

Claude (Anthropic)Claude CodeClaude CoworkOpenAI GPT and o-seriesAzure OpenAIGoogle GeminiAntigravityDeepSeekKimi (Moonshot)QwenLlamaMistralHermes (Nous Research)Grok (xAI)Phi (Microsoft)Microsoft CopilotCopilot StudioGitHub CopilotCursorOllamaLM Studio

Agentic engineering

Multi-agent orchestration (manager, engineer, reviewer, QA)Model routing by sensitivity, latency, and complexitySemantic KernelRAG pipelines and vector searchModel Context Protocol (MCP)Prompt engineering and structured outputsPrompt-injection defense and guardrailsAir-gapped local inferenceModel evaluation and calibrationAzure AI FoundryAI governance (NIST AI RMF, ISO 42001, EU AI Act)OWASP LLM Top 10 and MITRE ATLAS

Security and SOC

Microsoft Defender XDRDefender for EndpointDefender for IdentityDefender for CloudDefender for StorageDefender for Office 365Microsoft SentinelKQL threat huntingMITRE ATT&CK detection engineeringSOAR automation (Logic Apps playbooks)Attack surface reduction and EDR block modeSecure Score optimizationIncident responseThreat intel enrichmentMicrosoft Security CopilotSentinelOneCortex XDR (Palo Alto)QualysTenableKali Linux and Kali containersPhishing simulation programs

Identity and access

Microsoft EntraZero Trust architectureConditional AccessIdentity ProtectionToken protection and authentication strengthsBreak-glass account designActive Directory and GPOOktaCyberArkSailPointMFA and SSPR programsPrivileged access managementRBAC design

Data protection and compliance

Microsoft PurviewSensitivity labels and DLPHIPAA, SOC 2, and FISMA operationsEmail authentication (DMARC, DKIM, SPF)AI acceptable-use policyAudit readiness and evidenceChange management and CABDocumentation and runbook libraries

Cloud and infrastructure

AzureAWSGoogle CloudMicrosoft 365 and Exchange OnlineAzure Monitor and Log AnalyticsMicrosoft Graph APIIntune device managementWindows 365 Cloud PCSharePointG SuiteLinuxOracle and SSMSVeeam and Commvault (backup and recovery)

Microsoft admin centers (all of them)

Microsoft 365 Admin CenterExchange Admin CenterEntra Admin CenterAzure PortalPower Platform Admin CenterIntune Admin CenterMicrosoft Defender portalPurview compliance portalSharePoint Admin CenterTeams Admin CenterSecurity and compliance role scopingTenant-wide configuration and licensing

Network and monitoring

Fortinet firewallsPalo Alto firewallsCisco MerakiLogic MonitorVPN and DNS troubleshootingVNet segmentationDNS modernizationRemote support (Bomgar, ConnectWise, TeamViewer)

Engineering and operations

PythonPowerShellBash and shell scriptingTypeScript and JavaScriptNode.jsReact and Next.jsSQLPostgreSQL and pgvectorRedisPandas and NumPyFastAPIREST APIs and Microsoft GraphDockerInfrastructure as Code (Bicep and Terraform)Git and GitHubGitHub Actions (CI/CD)Azure DevOpsVercelPower Automate and Logic AppsPower BIJSON and YAMLVS CodeLinux administrationServiceNowZendeskJira and Azure BoardsITIL and change managementFive9 and Genesys

AI security and governance

Securing systems that act on their own

Securing AI is its own discipline. As systems gain autonomy, I make sure the controls around them are as strong as the models are capable, from the data boundary to the prompt surface to the governance program.

Treat models as untrusted

Agentic loops run with least privilege, human approval on consequential actions, and validated, structured outputs.

Keep sensitive data in-house

Data-sensitivity classification routes high-risk workloads to on-device, air-gapped inference, so regulated data never leaves the boundary.

Defend the prompt surface

Prompt-injection shields, tool permissioning, and egress secret masking on every agent that can take an action.

Govern by framework

Adoption guidance aligned to NIST AI RMF 1.0, ISO/IEC 42001, the EU AI Act, OWASP LLM Top 10, MITRE ATLAS, and HHS AI strategy.

Frameworks and standards I work within
NIST CSF 2.0NIST AI RMF 1.0ISO/IEC 42001EU AI ActHIPAASOC 2FISMAMITRE ATT&CKMITRE ATLASOWASP LLM Top 10Zero Trust
What each one means, and how I use it

Plain-language, no jargon. The frameworks above are the standards that keep AI safe, legal, and accountable. Here is what the core ones are and how they show up in my work.

NIST AI RMF 1.0

The US government playbook for managing AI risk. It splits the job into four plain steps: set the rules (Govern), understand each system (Map), test it (Measure), and fix what you find (Manage).

How I use it: I use it as the backbone of the program, so every AI system gets an owner, a risk rating, and a review before it goes live.
In practice: Built an AI system inventory, risk-rated each tool, and put a documented approval gate in front of any new deployment.

ISO/IEC 42001

The first international, certifiable standard for running AI responsibly. Think of it as the AI version of a quality stamp: proof the process is repeatable and auditable, not improvised.

How I use it: I structure the governance documents and controls to its clauses, so the program could stand up to a formal audit.
In practice: Authored the AI acceptable-use policy and mapped each control to a clause, so the evidence is ready for an auditor.

EU AI Act

Europe AI law. It sorts AI into risk tiers (banned, high risk, limited, minimal) and puts the strictest rules on high-risk uses like healthcare diagnosis.

How I use it: I map each AI use case to its tier, so we know which legal obligations apply before deployment, not after.
In practice: Sorted each use case into a risk tier and routed the high-risk, clinical ones through human-in-the-loop approval.

HHS AI strategy

The US health department direction for using AI safely in healthcare, the sector where this work actually lives.

How I use it: I keep adoption guidance aligned to it so the program fits a regulated, healthcare environment from day one.
In practice: Routed regulated data to on-device, air-gapped inference so protected health information never leaves the boundary.

OWASP LLM Top 10

The ten most common security risks specific to AI chat and agent apps, such as prompt injection and sensitive-data leakage.

How I use it: I design guardrails against each one: input filtering, least-privilege tools, and checks on what the model sends back.
In practice: Set up content filters and prompt-injection guardrails in Azure AI Foundry, and wrote Microsoft Purview DLP policies so sensitive data cannot leave in a model response.

MITRE ATLAS

A catalog of real attacks against AI systems, the AI counterpart to the well-known ATT&CK matrix that security teams already trust.

How I use it: I threat-model agents against it to find how an attacker would actually try to break them, then close those paths.
In practice: Threat-modeled agents against known AI attack techniques, then added tool permissioning and egress secret masking to shut the gaps.

Experience

My path so far

My experience is reserved for verified visitors

Enter your email and I will send you a 6-digit code.

Verification is automated end to end, and every request is logged and monitored.

Verify to view
Verify to view
Verify to view
Verify to view

Selected work

Projects

FeaturedAgentic AI, security, Azure

One of my three best builds, kept off the front page. Type the number below to open it.

Architecture in action

Two of these systems, wired end to end. Hover each stage to walk the pipeline the way I design it.

Sentinel SOAR pipeline

From raw telemetry to contained incident, with human gates on destructive actions

Hover or tap a stage to see what happens there.

Agentic AI triage engine

Multi-agent investigation with sensitivity-based routing and human approval

Hover or tap a stage to see what happens there.

Phishing and BEC response

From reported email to org-wide purge, blocked campaign, and smarter users

Hover or tap a stage to see what happens there.

Vulnerability management loop

Continuous discovery to verified remediation, reported in business terms

Hover or tap a stage to see what happens there.

Flagship deploymentEvery Defender domain, zero outages

Microsoft Defender Suite, Top to Bottom

An organization running near-default security needed the entire Microsoft Defender ecosystem stood up, without breaking clinical operations that cannot go down.

Rolled out Defender for Endpoint through ringed pilot groups (IT, early adopters, then production) so every control was validated before broad enforcement: zero outages, no major operational disruption.
Promoted the full attack surface reduction (ASR) rule set from audit to enforce, with tamper protection, cloud-delivered next-gen antivirus baselines, PUA blocking, and EDR in block mode.
Stood up Defender for Identity on domain controllers to surface credential theft, lateral movement, and domain dominance techniques the moment they start.
Hardened email with Defender for Office 365: Safe Links and Safe Attachments, detonation, impersonation and anti-phishing policies tuned to the org, priority account protection.
Governed the SaaS layer with Defender for Cloud Apps: OAuth consent phishing detection, anomalous data movement policies, and app governance over what touches the tenant.
Enabled Defender for Cloud across Azure workloads for posture management and workload protection, and Defender for Storage (plan 2) with on-upload malware scanning.
Built the vulnerability management program from nothing: Qualys and Tenable authenticated scanning stood up from scratch, findings fused with Defender Vulnerability Management, risk-ranked remediation, and mean-time-to-remediate metrics reported to leadership monthly.
Raised Microsoft Secure Score from 35% to the 80 to 85% band, each improvement shipped as a documented, approved, reversible change.
Built Microsoft Sentinel from scratch alongside it all: workspace design, data connectors, MITRE-mapped analytics rules, SOAR automation, and the entire device fleet feeding the pipeline.
Secure Score 35% to 85%Zero outagesDefender for EndpointDefender for IdentityDefender for Office 365Defender for Cloud AppsDefender for CloudDefender for Storage P2Qualys + TenableASRSentinelCIS benchmarks

BlackGate: Agentic Purple-Team Platform

Autonomous offensive testing is powerful, but reckless without hard limits on scope, isolation, and human control.

Impact
  • Runs a fleet of specialist agents across a full kill chain, with every action gated by a signed, fail-closed authorization scope so it only ever touches authorized targets.
  • Executes all tooling inside disposable, network-isolated Kali sandboxes with a one-way results channel; any state-changing action stops at a human approval gate.
  • Closes the purple-team loop by replaying validated techniques to test detection coverage and turning gaps into new Sentinel and Defender detection content.
MITRE ATT&CKPurple TeamZero TrustLangGraph orchestrationGo execution serviceNeo4j attack-path graphHuman-in-the-loop

Multi-Provider Agentic AI Orchestration Engine

Security teams wanted AI leverage without sending sensitive data to third-party models.

Impact
  • Routed workloads across cloud and on-device models by data-sensitivity class, keeping high-sensitivity security data on fully air-gapped inference.
  • Ran a manager, engineer, reviewer, and QA agent loop for multi-step alert correlation, triage, and remediation planning with minimal human intervention.
  • Standardized orchestration on Semantic Kernel with RAG over a live security knowledge base.
NIST AI RMFOWASP LLM Top 10MITRE ATLASSemantic KernelMulti-provider routingAir-gapped inference

Defender and Sentinel in a HIPAA and SOC 2 Environment

A compliance-driven organization needed audit-ready detection and response across a large fleet.

Impact
  • Rolled out the full Microsoft Defender ecosystem (Endpoint, Identity, Office 365, Cloud Apps, Cloud, Servers, Storage, and Containers) unified under Defender XDR, with alerts centralized into Microsoft Sentinel.
  • Designed workspaces, connectors, and analytics rules, and authored KQL detections that improved visibility and cut false positives.
  • Delivered audit-ready detection and response across multiple healthcare organizations, built around HIPAA, SOC 2, and FISMA controls.
HIPAASOC 2FISMAMITRE ATT&CKSentinelDefender for EndpointKQL

KQL Multi-Table Threat Hunting Orchestrator

Hunts were ad hoc; the team needed a repeatable capability across the full kill chain.

Impact
  • Built a reusable query library across DeviceNetworkEvents, DeviceProcessEvents, IdentityLogonEvents, EmailEvents, and CloudAppEvents.
  • Tagged every query to MITRE ATT&CK tactics and techniques for rapid hypothesis-driven hunts from initial access through exfiltration.
  • Documented findings in structured investigation reports covering IOC timelines, affected assets, and hardening recommendations.
MITRE ATT&CKDefender XDRAdvanced HuntingDetection engineering

Copilot Security and AI Governance Program

Leadership wanted Microsoft Copilot in clinical and operational workflows without leaking regulated data into AI surfaces.

Impact
  • Assessed the oversharing blast radius before rollout: SharePoint and OneDrive permissions, stale links, and sensitive sites Copilot could index.
  • Gated AI surfaces behind Conditional Access and sensitivity labels so prompts and grounding respect existing data boundaries.
  • Authored the organizational AI acceptable-use and governance guidance, aligned to NIST AI RMF, ISO/IEC 42001, the EU AI Act, and HHS AI strategy.
  • Extended detections to AI usage: anomalous prompt activity, shadow AI discovery, and Copilot audit events routed into Sentinel.
NIST AI RMFISO/IEC 42001HIPAAMicrosoft CopilotPurviewConditional Access

Sentinel SOAR Orchestration and Playbooks

Analyst time was burning on repetitive triage: enrichment, containment, and notification were all manual.

Impact
  • Built automation rules and Logic Apps playbooks that trigger on analytics: auto-enrich entities with threat intel, geolocation, and asset criticality before an analyst ever opens the incident.
  • Automated containment paths: disable compromised accounts, revoke sessions, isolate endpoints via Defender, all with approval gates for destructive actions.
  • Wired notifications and case flow: severity-based routing to Teams and email, auto-created tickets, and closure with documented outcomes.
  • Cut mean time to respond by removing the manual steps between detection and first action.
MITRE ATT&CKNIST CSF 2.0SentinelLogic AppsSOAR

Cloud PC Deployment for Healthcare

Clinical and engineering teams needed secure, compliant virtual desktops at scale.

Impact
  • Rolled out a scalable Windows 365 Cloud PC deployment for a healthcare organization, with per-group sizing tuned to each workload.
  • Architected role-based virtual networks with segmentation to enforce access controls and compliance.
Zero TrustRBACWindows 365VNet segmentation
See how I build

The code, in the open

A public, sanitized slice of how I build: governed, measured, and mapped to real security and AI governance frameworks. Enough to show the thinking, never the secrets.

AI eval harness with a hard safety and injection ship-gate
Default-deny agent guardrails (OWASP LLM01 and LLM02)
Log-odds signal fusion, de-vig, and Brier-scored calibration
Governance mapped to NIST AI RMF, ISO 42001, and MITRE
🔒 Private by design🧪 Synthetic data only📈 Live, verifiable results

Most of my repositories stay private. Live trading, client work, and anything with real tenants or credentials never goes public, for security and personal reasons.

Explore the showcase
Ulises, Agentic AI Security Architect

Want to learn more about me?

Visit my LinkedIn for the full professional profile, or browse the code showcase above. If you would like to learn more about the private work, please feel free to email me at ulisesghurtado@gmail.com.

View LinkedIn

Credentials

Certifications

Eleven certifications spanning security operations, architecture, AI, identity, and cloud, with a focused 2026 roadmap into offensive-aware architecture and advanced AI. Domains covered:

Security OperationsCybersecurity ArchitectureAI EngineeringIdentity and AccessCloud ArchitectureAI Governance
Earned
Security+
CompTIA Security+
CompTIA certified
Expired, open to renewing on request
SC-900
Security, Compliance, and Identity Fundamentals
Microsoft certified
Credential ID: 56E64857DE863DAA
SC-200
Security Operations Analyst
Microsoft certified
Expired, renewing soon
SC-100
Cybersecurity Architect Expert
Microsoft certified
Credential ID: 91E648GHAR863DAA
Scheduled soon
AZ-104
Azure Administrator Associate
Microsoft certified
July 2026
AI-900
Azure AI Fundamentals
Microsoft certified
Credential ID: EE8EEAC6A87AFA77
AI-102
Azure AI Engineer Associate
Microsoft certified
Credential ID: 3C42BF552D8C4AD7
AI-103
Azure AI Apps and Agents Developer Associate
Microsoft certified
Credential ID: 9DF77BD803E6940
AB-100
Agentic AI Business Solutions Architect
Microsoft certified
Credential ID: 4DF3367C1813B11D
AB-741
AI Transformation Leader
Microsoft certified
Credential ID: CE213C3CD43CCE3E
AZ-305
Azure Solutions Architect Expert
Microsoft certified
AI-500
Multi-Agent AI Solutions Expert
Microsoft certified
Beta exam taken, July 2026
AI-200
Azure AI Cloud Developer Associate
Microsoft certified
Pending, Aug 2026
CISSP
Information Systems Security Professional
ISC2 certified
Pending, Aug 2026
2026 roadmap
AI-300Sep 2026
Microsoft AI
SC-500Sep 2026
Microsoft Security
PenTest+Nov 2026
CompTIA PenTest+
Education
M.S. Artificial Intelligence
The University of Texas at Austin
Fall 2026 to Winter 2029
B.S. Computer Science
Boise State University
2021 to 2023
A.S. Computer Science and Information
College of Southern Idaho
2017 to 2021

Every certification is listed on my LinkedIn with its credential ID, so anything here can be checked against the source.

View my full profile on LinkedIn

Contact

Let us talk

I am open to conversations about agentic AI security, cloud security architecture, and roles where the two meet. If you are fully interested, please email me at ulisesghurtado@gmail.com.