
Ulises
Agentic AI Security Architect
Hi, I am Ulises.
Agentic AI Security Architect|
I secure cloud environments and build the AI systems that run inside them. Six-plus years across enterprise and MSP environments: I have deployed the full Microsoft Defender suite, Endpoint, Identity, Cloud, Storage, and Office, stood up Sentinel from scratch, led incident response end to end, and architected multiple AI systems, from multi-provider agentic orchestration engines to AI-powered threat hunting.
Certified across the full Microsoft security and AI stack, eleven credentials from Security+ and SC-100 to AI-102, AI-103, and AZ-305, with CISSP next. If Microsoft makes it, I have probably deployed it, secured it, or automated it.
Cloud Security
AI / Agentic
Blockchain
Software Engineering
Hover a node to explore each domain and its stack.
About
Who I am
I started in IT support and worked my way into the center of cloud security. Over six-plus years I have gone from resolving tickets to leading detection engineering, incident response, and Zero Trust programs, and now to architecting the agentic AI systems that security teams will run on.
What I care about is making security real and durable: controls that are engineered, compliant, and repeatable, not one-off heroics. I hunt with KQL mapped to MITRE ATT&CK, automate response so the team scales, and design AI governance so new technology gets adopted safely. I am equally at home on an incident bridge and in a strategy planning session, translating deep technical work into risk and business terms.
Right now I am focused on the intersection that matters most: as AI gets more autonomy, the security of the system around it becomes the product. That is what I build.
At a glance
- Cloud security and SOC operations
- Agentic AI architecture and safety
- AI solutions and cost-cutting consulting
- Zero Trust and identity
- AI governance for regulated fields
- Remote, and open to relocation
Raised Microsoft Secure Score from 35% to the 80 to 85% band for multiple clients, with no outages and no major operational disruption.
Deployed the full Defender suite top to bottom: Endpoint, Identity, Cloud, Storage, and Office, rolled out through ringed pilot groups.
Built Microsoft Sentinel from scratch and onboarded entire device fleets into Defender in HIPAA and SOC 2 environments.
Advanced identity to Zero Trust and email to full DMARC enforcement, closing a long-standing spoofing and BEC exposure.
Engineered a multi-provider agentic AI engine with air-gapped inference for high-sensitivity security data.
Authored organizational AI governance aligned to NIST AI RMF, ISO/IEC 42001, the EU AI Act, and HHS AI strategy.
Off the clock
Chess, lots of chess
Pattern recognition, calculated risk, thinking three moves ahead. It is the same muscle I use in threat hunting.
Piano
Discipline and precision with an output you can feel. The practice habit transfers to everything else I do.
Reading strategy
Robert Greene is my favorite author, The 48 Laws of Power especially. I read for how people and systems actually behave.
Building, not gaming
Surprisingly, no video games. My free compute goes into agentic AI side projects and market-data systems instead.
What I build for companies
AI solutions that pay for themselves
Merging AI and security is my specialty, but it is not the whole story. I design AI solutions for whatever eats a company's time and money, then wire in the backend security mindset most builders skip. The goal is always the same: cut costs with the minimum of effort, and ship something you can actually run.
Customer response automation
Agents that read incoming email, draft on-brand replies, resolve the routine ones automatically, and escalate the rest to a human with full context attached.
Cuts response time and support hours
Automatic detection and pager duty
Detectors over your logs, metrics, and alerts with severity-based paging: the right person gets woken up only when it matters, with the evidence already gathered.
Cuts alert fatigue and missed incidents
Revenue and market engines
Signal-grading systems that score opportunities, track their own accuracy, and earn influence from results. My PolyMind market intelligence platform is the working proof.
Cuts research hours, compounds edge
Back-office automation
Reports, intake, ticket triage, scheduling, knowledge bases: the repetitive paperwork layer of a business, automated with human approval exactly where it counts.
Cuts manual admin to near zero
Security copilots
KQL-writing hunt agents, alert triage assistants, and incident summarizers that let a small security team operate like a large one.
Cuts triage time and analyst burnout
AI strategy and new ideas
Not sure where AI fits your company? I map your workflows, find the highest-ROI target, and ship a working pilot fast. Consulting that ends in software, not slideware.
Cuts the guesswork out of AI adoption
The difference in my builds: every solution ships with the security backend baked in. Least privilege, logged actions, human gates on consequential steps, and sensitive data kept where it belongs. That is the gap between an AI demo and an AI system a company can trust in production.
How I work
Principles I build on
Secure by design
I build security in from the first line, not bolted on after the fact.
Compliant and auditable
Every control documented, approved, reversible, and mapped to a framework.
Automate the repeatable
SOAR playbooks, KQL libraries, and scripts so the team scales without burning out.
Translate to the business
I frame security in risk and regulatory terms that leaders can act on.
Capabilities
What I work with
AI models and their ecosystems
Agentic engineering
Security and SOC
Identity and access
Data protection and compliance
Cloud and infrastructure
Microsoft admin centers (all of them)
Network and monitoring
Engineering and operations
AI security and governance
Securing systems that act on their own
Securing AI is its own discipline. As systems gain autonomy, I make sure the controls around them are as strong as the models are capable, from the data boundary to the prompt surface to the governance program.
Treat models as untrusted
Agentic loops run with least privilege, human approval on consequential actions, and validated, structured outputs.
Keep sensitive data in-house
Data-sensitivity classification routes high-risk workloads to on-device, air-gapped inference, so regulated data never leaves the boundary.
Defend the prompt surface
Prompt-injection shields, tool permissioning, and egress secret masking on every agent that can take an action.
Govern by framework
Adoption guidance aligned to NIST AI RMF 1.0, ISO/IEC 42001, the EU AI Act, OWASP LLM Top 10, MITRE ATLAS, and HHS AI strategy.
Experience
My path so far
My experience is reserved for verified visitors
Enter your email and I will send you a 6-digit code.
Verification is automated end to end, and every request is logged and monitored.
Selected work
Projects
PolyMind Intelligence Atlas
A self-learning, multi-model intelligence platform. A weighted-consensus panel votes, an outcome ledger grades every prediction with Brier scoring, and influence is re-earned from calibration. Backed by a pgvector memory brain, agentic-safety controls, a defense-in-depth stack, and a full Azure AI Foundry reference architecture.
Architecture in action
Two of these systems, wired end to end. Hover each stage to walk the pipeline the way I design it.
Sentinel SOAR pipeline
From raw telemetry to contained incident, with human gates on destructive actions
Hover or tap a stage to see what happens there.
Agentic AI triage engine
Multi-agent investigation with sensitivity-based routing and human approval
Hover or tap a stage to see what happens there.
Phishing and BEC response
From reported email to org-wide purge, blocked campaign, and smarter users
Hover or tap a stage to see what happens there.
Vulnerability management loop
Continuous discovery to verified remediation, reported in business terms
Hover or tap a stage to see what happens there.
Microsoft Defender Suite, Top to Bottom
An organization running near-default security needed the entire Microsoft Defender ecosystem stood up, without breaking clinical operations that cannot go down.
Multi-Provider Agentic AI Orchestration Engine
Security teams wanted AI leverage without sending sensitive data to third-party models.
- Routed workloads across cloud and on-device models by data-sensitivity class, keeping high-sensitivity security data on fully air-gapped inference.
- Ran a manager, engineer, reviewer, and QA agent loop for multi-step alert correlation, triage, and remediation planning with minimal human intervention.
- Standardized orchestration on Semantic Kernel with RAG over a live security knowledge base.
Defender and Sentinel in a HIPAA and SOC 2 Environment
A compliance-driven organization needed audit-ready detection and response across a large fleet.
- Deployed Sentinel and Defender for Endpoint across the full device fleet with baseline policies, ASR rules, and EDR settings.
- Designed workspaces, connectors, and analytics rules, and authored KQL detections that improved visibility and cut false positives.
- Built the program around HIPAA, SOC 2, and FISMA controls for audit readiness.
KQL Multi-Table Threat Hunting Orchestrator
Hunts were ad hoc; the team needed a repeatable capability across the full kill chain.
- Built a reusable query library across DeviceNetworkEvents, DeviceProcessEvents, IdentityLogonEvents, EmailEvents, and CloudAppEvents.
- Tagged every query to MITRE ATT&CK tactics and techniques for rapid hypothesis-driven hunts from initial access through exfiltration.
- Documented findings in structured investigation reports covering IOC timelines, affected assets, and hardening recommendations.
Copilot Security and AI Governance Program
Leadership wanted Microsoft Copilot in clinical and operational workflows without leaking regulated data into AI surfaces.
- Assessed the oversharing blast radius before rollout: SharePoint and OneDrive permissions, stale links, and sensitive sites Copilot could index.
- Gated AI surfaces behind Conditional Access and sensitivity labels so prompts and grounding respect existing data boundaries.
- Authored the organizational AI acceptable-use and governance guidance, aligned to NIST AI RMF, ISO/IEC 42001, the EU AI Act, and HHS AI strategy.
- Extended detections to AI usage: anomalous prompt activity, shadow AI discovery, and Copilot audit events routed into Sentinel.
Sentinel SOAR Orchestration and Playbooks
Analyst time was burning on repetitive triage: enrichment, containment, and notification were all manual.
- Built automation rules and Logic Apps playbooks that trigger on analytics: auto-enrich entities with threat intel, geolocation, and asset criticality before an analyst ever opens the incident.
- Automated containment paths: disable compromised accounts, revoke sessions, isolate endpoints via Defender, all with approval gates for destructive actions.
- Wired notifications and case flow: severity-based routing to Teams and email, auto-created tickets, and closure with documented outcomes.
- Cut mean time to respond by removing the manual steps between detection and first action.
Cloud PC Environment for 500+ Users
Clinical and engineering teams needed secure, compliant virtual desktops at scale.
- Designed and deployed Windows 365 for 500+ users with per-group sizing tuned to each workload.
- Segmented access with role-based virtual networks to enforce controls and compliance.
The code, in the open
A public, sanitized slice of how I build: governed, measured, and mapped to the frameworks leadership actually asks about. Enough to show the thinking, never the secrets.
Most of my repositories stay private. Live trading, client work, and anything with real tenants or credentials never goes public, for security and personal reasons.

Want to learn more about me?
Visit my LinkedIn for the full professional profile, or browse the code showcase above. If you would like to learn more about the private work, please feel free to email me at ulisesghurtado@gmail.com.
Credentials
Certifications
Eleven certifications spanning security operations, architecture, AI, identity, and cloud, with a focused 2026 roadmap into offensive-aware architecture and advanced AI. Domains covered:
Contact
Let us talk
I am open to conversations about agentic AI security, cloud security architecture, and roles where the two meet. If you are fully interested, please email me at ulisesghurtado@gmail.com.