Cybersecurity Architect Resume Nicolas Watkins Cybersecurity Architect (410) 555-0186 nicolas.watkins@protonmail.com linkedin.com/example/nicolaswatkins Columbia, MD 21044 STRENGTHS Architecture Translation Turned business requirements into secure blueprints; project teams gained clearer decisions and fewer late design surprises. Governance Leadership Chaired architecture reviews where residual risk, ownership, and compensating controls became visible before production release. Cloud Security Reviewed AWS and Azure environments during complex migrations; engineers relied on practical guidance for identity and configuration risks. AI Risk Review Built GenAI and agentic AI guardrails around data boundaries and MCP permissions; pilot teams gained confidence before deployment. Mentoring Guided engineers and architects through threat modeling, infrastructure reviews, and executive briefings; peers often sought help on difficult designs. SKILLS NIST CSF NIST SP 800-53 NIST SP 800-171 Zero Trust AWS Azure IAM Network Security Data Protection Application Security GenAI Security Agentic AI MCP Hardening Threat Modeling DevSecOps LANGUAGES English Native 40 Spanish Intermediate 20 MY CAREER 8.1 Years Senior Cybersecurity Architect at Pinecrest Consumer Finance (1.7 Years) Senior Security Architect at Blue Ridge Bankcard Services (2.2 Years) Security Architect at Northstar Public Benefits Systems (2.2 Years) Security Engineer at CivicShield Technology Services (1.9 Years) SUMMARY Senior Cybersecurity Architect with eight years securing consumer finance, public-sector, and regulated enterprise environments, including more than six years shaping security architecture and governance. Leads NIST-aligned architecture design, solution reviews, risk mitigation, and control mapping across AWS, Azure, on-premises, and hybrid platforms. Partners with engineering, infrastructure, compliance, risk, and product teams throughout system development lifecycles, turning business needs into practical security blueprints and reusable patterns. Recent work covers IAM, network security , data protection, application security , DevSecOps, infrastructure-as-code , GenAI, LLMs, agentic AI, and MCP hardening. Communicates technical risk clearly through governance boards, executive briefings, decision records, and audit evidence. Ready to help HarborPoint Lending Group strengthen secure innovation, regulatory alignment, and trusted lending services. EXPERIENCE Senior Cybersecurity Architect Pinecrest Consumer Finance January 2025 - Present Baltimore, MD Directs security architecture for lending platforms across cloud, on-premises, and hybrid environments . Chairs solution reviews, guides governance, mentors architecture teams, and translates regulatory duties into secure blueprints. Converted lending objectives into NIST-aligned blueprints for cloud, on-premises , and hybrid platforms. Chaired application and API reviews, documenting control gaps, residual risk, and compensating controls. Established Zero Trust patterns using NIST SP 800-207, AWS, Azure, and workload segmentation. Created GenAI reviews covering agent permissions, data boundaries, logging, and MCP hardening . Mapped controls to NIST, PCI DSS , ISO 27001 , and CMMC evidence requirements. Mentored five security engineers and two architects through threat modeling and DevSecOps reviews. Senior Security Architect Blue Ridge Bankcard Services September 2022 - December 2024 Tysons, VA Owned architecture assessments for payment, account servicing, and data exchange initiatives across multi-cloud, private cloud, and legacy environments. Guided governance decisions, secure delivery, and audit preparation. Assessed payment and account platforms across Azure , AWS, private cloud , and data centers. Produced reference architectures for privileged access, secrets, encryption, APIs, and workload isolation. Led STRIDE reviews for applications and vendors, resolving high-priority design weaknesses. Embedded SAST, composition analysis, container scanning, and Terraform checks into delivery pipelines. Standardized PCI DSS and ISO 27001 evidence through diagrams, data flows, and control mappings. Presented residual-risk recommendations to governance boards without weakening security requirements. Security Architect Northstar Public Benefits Systems May 2020 - August 2022 Richmond, VA Designed security patterns for benefits administration and financial disbursement services under strict privacy, access, and availability requirements. Supported architecture governance, cloud reviews, compliance assessments, and engineering remediation. Designed NIST -aligned patterns for IAM , encryption, logging, segmentation, and secure interfaces. Reviewed AWS landing zones and Azure subscriptions for configuration and key-management risks. Created intake and decision records guiding projects through planning, testing, and release. Mapped safeguards to NIST SP 800-53 and SP 800-171 for regulated assessments. Guided engineers through remediation involving excessive privileges, exposed storage, and insecure accounts. Preserved audit evidence that gave compliance teams clearer assessment support. Security Engineer CivicShield Technology Services May 2018 - April 2020 Alexandria, VA Supported security engineering for federal and regulated commercial clients, combining architecture analysis, control validation, identity reviews, network security , threat modeling, and compliance evidence management. Analyzed client designs against NIST CSF and SP 800-53 control requirements. Built AWS and Azure IAM checklists covering privileged roles and multifactor authentication. Validated firewalls, private connectivity, segmentation, endpoint telemetry, and centralized logging. Performed threat modeling with developers, converting findings into prioritized remediation tickets. Supported PCI DSS and CMMC readiness through evidence collection and control matrices. Created architecture diagrams and executive issue summaries for consistent project reviews. PROJECTS GenAI Security Governance Program 2026 Established review guardrails for LLM and agentic AI pilots, covering MCP hardening, tool permissions, prompt data boundaries, threat modeling, monitoring, and approval decisions. Zero Trust Architecture Reference Model 2024 Built reusable Zero Trust patterns across AWS, Azure, and hybrid services, connecting identity context, segmentation, workload authentication, and NIST SP 800-207 governance. LEADERSHIP & AWARDS Cybersecurity Excellence Award, Blue Ridge Bankcard Services, 2024 Architecture Governance Recognition, Northstar Public Benefits Systems, 2022 George Mason University Cyber Defense Scholarship, 2017 EDUCATION Bachelor's Degree in Cybersecurity George Mason University GPA: 3.7 2018 Fairfax, VA Coursework: Network security, digital forensics, secure software development, risk management CERTIFICATIONS CISSP 2023 AWS Certified Security - Specialty 2022 Microsoft Certified: Azure Security Engineer Associate 2021 TECHNICAL SKILLS NIST Frameworks: NIST CSF, NIST SP 800-53, NIST SP 800-171 Zero Trust Standards: NIST SP 800-207, Zero Trust Architecture, identity context Cloud Platforms: AWS, Microsoft Azure, private cloud Identity Security: IAM, multifactor authentication, privileged access Network Security: Firewalls, network segmentation, private connectivity Data Protection: Encryption, key management, data boundaries Application Security: API protection, SAST, software composition analysis DevSecOps Tools: Container scanning, Terraform checks, security gates AI Security: LLMs, GenAI, agentic AI AI Governance: MCP hardening, tool permissions, prompt boundaries Compliance Frameworks: PCI DSS, ISO 27001, CMMC Threat Modeling: STRIDE, data-flow analysis, attack-surface review Security Governance: Architecture review boards, decision records, control mapping SKILLS NIST CSF NIST SP 800-53 NIST SP 800-171 Zero Trust AWS Azure IAM Network Security Data Protection Application Security GenAI Security Agentic AI MCP Hardening Threat Modeling DevSecOps PROFESSIONAL AFFILIATIONS Mentor, Mid-Atlantic Cybersecurity Professionals Network, 2023 - Present Volunteer Reviewer, Maryland Cybersecurity Workforce Collaborative, 2021 - Present LANGUAGES English (Native) Spanish (Intermediate) ADDITIONAL INFORMATION Work Status : Authorized to work in United States. No sponsorship required. ADDITIONAL INFORMATION Work Status : Authorized to work in United States. No sponsorship required. REFERENCES AVAILABLE ON REQUEST
File
Styles Download Buy Log In
Bootstrap
>JP 1 1
PDF Footer and Margins Setup
The margins are applied to the document, and the footer shows up in the preview and the PDF

Footer Font Settings

Are you applying for a specific job
so we can tailor your resume to it?
Are you applying for a specific job
so we can tailor your cover letter to it?
Type your details as text to generate a personalized resumeType your details as text to generate a personalized cover letter
Website link found! Ready to create resume from:
Skip this Step
Drag the into the box to verify you're human.
Drop here

My Resumes

Displaying {number_of_files} files (out of {total_of_all_files} total)
NameFile TypeLast Modified:Description:

Rename File

Filename already exists!

Delete Files

Warning: This action is irreversible. Once you click submit, the files will be permanently deleted.

Heading text
Upload From Computer Upload
Select From Existing
LinkedIn
Drag & Drop files anywhere in this tab, or

Uploaded Files

DeleteNameLast Updated Use This File
Select this to use the file for generating your resume and cover letter. Only one source—uploaded file, selected file, or LinkedIn text—can be used.

My Files

Resumes or cover letters you create will appear here. No files available yet.
DeleteNameLast Updated Use This File
Select this to use the file for generating your resume and cover letter. Only one source—uploaded file, selected file, or LinkedIn text—can be used.

Add LinkedIn Profile PDF

You can download your LinkedIn profile as a PDF by opening linkedin.com in a web browser, clicking your profile photo, selecting the “More” or “Resources” button, and choosing “Save to PDF.” You can then attach the PDF using the Upload From Computer tab.

Paste Your LinkedIn Profile Text

If you have copied the LinkedIn profile text, paste it below. See how to copy your profile from LinkedIn

   
Select this to use the LinkedIn profile text for generating your resume and cover letter. Only one source—uploaded file, selected file, or LinkedIn text—can be used.
-->
Select this to use the LinkedIn profile text for generating your resume and cover letter. Only one source—uploaded file, selected file, or LinkedIn text—can be used.

Try these controls

<
>