AI governance & assurance · cybersecurity & GRC · product trust

Anupam Gupta

Trust, engineered for consequential technology.

I build governance, security, GRC, and assurance systems for organizations operating at the frontier of AI.

Current roleSenior Security Industry Specialist, Amazon
Industry contribution Lead Architect and Advisor, Cyber Future Foundation Explore RSAIF.AI
Anupam Gupta at a professional leadership event
Anupam Gupta Global AI governance, security and GRC leader

I turn frontier technology risk into systems people can operate.

My work sits between strategy and execution: aligning engineering, security, risk, privacy, legal, compliance, and executive stakeholders around AI and technology decisions that withstand scrutiny.

The objective is not more governance. It is evaluable systems, better judgment, clearer accountability, and durable trust.

01

AI Governance & Assurance

Establish lifecycle controls, accountable oversight, evidence, and assurance around commitments and standards.

02

AI Risk Engineering & Evaluation

Build model and system evaluation around testable scenarios, monitoring, technical evidence, and decision thresholds.

03

Product & Engineering Security

Bring architecture, identity, data access, threats, controls, and evidence into product decisions from the outset.

04

Enterprise GRC & Product Trust

Build scalable control and assurance systems that earn confidence from customers, regulators, and leaders.

05

Technology & AI Audit

Use technical depth, analytics, and automation to make independent assurance a source of decision signal.

06

Resilience, Data & Ecosystem Risk

Strengthen AI data, model supply chains, critical services, and external dependencies before disruption tests them.

Standards are inputs. Assurance is the system.

Across every domain, policy and risk become evaluation, controls, observable evidence, and decisions.

Risk thesisArchitectureEvaluationEvidenceDecision
01
AI governance & assurance

Govern and assure AI across its lifecycle.

Translate commitments into evaluable controls, system evidence, accountable oversight, and decisions across the AI lifecycle.

AccountabilityLifecycle controlsDecision evidence

What these capabilities produce.

Judgment shows up as outcomes, not just frameworks applied.

01

Operational assurance at product scale

At Amazon, I built repeatable trust mechanisms across global product regulation, security engineering, evidence, and resilience so emerging obligations become execution-ready.

Readiness under scrutiny
02

Applied architecture for responsible AI

At Cyber Future Foundation, I architected and advanced RSAIF MOSAIC as an operating framework supported by role-aware learning pathways and practitioner guidance.

Governance made actionable
03

Threat-informed independent assurance

Across regulated financial institutions, I brought engineering context, analytics, and risk judgment to assurance spanning cloud, identity, data, infrastructure, and resilience.

Evidence that informs decisions

Ideas earn trust when they can be heard.

Selected moments from conferences, panels, and practitioner sessions.

A career building trust where technology changes fastest.

The through-line: technical depth joined with executive judgment across engineering, governance, audit, and industry contribution.

2022 — Present

Amazon

Senior Security Industry Specialist

Expanded technical assurance into global product trust, working where regulation, security engineering, operational evidence, and resilience meet.

2024 — Present

Cyber Future Foundation

Lead Architect and Advisor

Made responsible and secure AI principles operational through RSAIF MOSAIC, practitioner learning pathways, and implementation guidance.

Explore the RSAIF ecosystem
2021 — 2022

Fidelity Investments

Senior IT Audit Analyst

Moved assurance closer to engineering by applying threat-informed thinking across identity, cloud, encryption, authentication, and DevSecOps.

2019 — 2021

Federal Home Loan Bank of Dallas

Senior IT Auditor

Expanded technology assurance across cloud, data, infrastructure, third parties, and resilience within a regulated financial environment.

Depth built through practice, research, and contribution.

AI & security credentials

  • Executive Introduction to Responsible and Secure AI for the Future (RSAIF)
  • Practitioner's Playbook for Responsible and Secure AI for the Future (RSAIF)
  • GIAC Security Leadership (GSLC)
  • Certified Information Systems Auditor (CISA)
  • Certified Data Privacy Solutions Engineer (CDPSE)
  • ISO/IEC 27001 Lead Implementer
  • ISO/IEC 27001 Lead Auditor

Risk & technology

  • Certified ISO 31000 Internal Controls Risk Analyst (CICRA)
  • Amazon Web Services (AWS): Security, Compliance, and Governance for AI Solutions
  • Cybersecurity Nexus (CSX) Cybersecurity Fundamentals Certificate (CSXF)
  • Microsoft Certified: Azure Fundamentals (AZ-900)
  • Certificate in Cybersecurity Systems (CCSS)

Recognition

  • SANS Security Leadership Gold Award
  • Marquis Who's Who
  • Esther R. Sawyer Research Award
    Internal Audit Foundation
  • Mark Salamasick IT Auditor Fellowship
    The University of Texas at Dallas
  • University of Delhi Gold Medalist

Education & research

  • Master of Science (MS), Information Technology and Management
    The University of Texas at Dallas
  • Bachelor of Science (BS), Computer Science
    University of Delhi
  • Research in social engineering and organizational governance

Open to thoughtful exchange

Let’s make trust operational.

I welcome thoughtful conversations with leaders navigating consequential questions in AI governance, security, GRC, and technology assurance, especially where exchanging perspective can help move the work forward.