Ramani Viswanathan

AI governance and security, proven the hard way.

I build AI systems. I break them. I govern them.

I run enterprise security and AI programs. I build and audit the systems behind them myself, including the assistant answering questions on this site.

Ramani Viswanathan headshot

What I Do

Delivery and risk run on different maps of the same organization. The program office tracks what is shipping, security operations tracks what is exposed, and neither sees what the other is missing until an audit or an incident forces them together. I build the layer that closes that gap before it does — then I break it, then I govern it.

Build

At Azuris Consulting I architected AIS, a converged security platform that fuses physical and cyber telemetry into one operational layer — live in production on real client telemetry, with tenant isolation enforced independently at the database and application layers. Its AI layer only narrates incidents the system has already decided; it never makes the call, and never gets write access to production.

Break

On my own time, separate from Azuris, I build and publish IEM-AIS — an adversarial testing tool that sends real prompts to real, live LLM endpoints, every test case grounded in the OWASP GenAI LLM Top 10 2026, fetched at runtime rather than bundled. I run it against this site’s own AI assistants as real targets, not a demo.

Govern

IEM is the evidence-assurance methodology underneath both of the above: one finding, one owner, one fix, then re-audit. I tested it against a real $57,000 security engagement I was personally accountable for, audited against seven PMI standards — the first audit found 10 gaps and a Reporting Integrity Score of 52.15 out of 100; a re-audit eight weeks later confirmed the fix, and caught a new $900 discrepancy already in front of the sponsor for a live funding decision.

Why one person does all three: governance written by people who have never shipped breaks on contact with production. I have deployed these systems, attacked them, and built the methodology for proving they are safe. That is not three skills. It is one loop, and it is the only way I trust AI governance to actually work.

Selected Programs

Underneath the building: enterprise PMO and program leadership for global clients — budgets, timelines, and stakeholders across time zones. The governance work above doesn’t just read well. It runs on this foundation.

Azuris Consulting

Converged Security Intelligence

Scope: Architected and shipped a multi-tenant platform converging physical security (video, access control) and network security telemetry into one operational layer, while standing up the delivery and governance function that had not previously existed. Now directing 20+ concurrent enterprise security implementations.

Constraint: No existing platform and no existing delivery function — every process and every system designed from nothing, while live security operations kept running underneath.

What I owned: The security model: four least-privilege database roles, each scoped to one code path so a compromised credential has bounded blast radius; forced row-level security on every application table; UI reads through security-invoker views only; tenant isolation enforced independently at the database and application layers. And the decision to scope the AI layer to narration over facts the system has already committed — five structured fields per signal, no raw payloads, no severity or grouping decisions, no write access to production. Narration runs after the incident transaction commits, so a slow model call can never hold a database connection against the pool the real-time webhook receiver depends on.

Outcome: Live in production on real client telemetry, in internal validation with Azuris staff ahead of client rollout.

Control weakness, stated

No separate architecture, QA, or release function existed; I performed all of them. That is a separation-of-duties gap, not a feature. Compensating controls: a written release gate, local-first validation, fresh-context adversarial review of anything touching schema or a webhook receiver, and a permanent decision log. The first thing I would do with a real engineering org is hand the security model to someone who did not write it.

Virtusa / Citi

$1B+ Technology Estate Transformation

Scope: Eight years as Associate Director, Program Management, across a $1B+ technology estate spanning five regions — $40M in portfolio programs, including two sequential enterprise programs I owned end to end: disaster recovery and operational resilience (2021–2024), then enterprise vulnerability and patch management across 12 applications (2024–2026).

Constraint: A mission-critical procurement platform was a chronic source of downtime, and disaster recovery for the estate ran on a 48-hour window with no governed testing program behind it.

What I owned: The decision to rebuild the procurement platform rather than patch it. I then ran the DR program end to end — recovery tiering, backup and recovery re-architecture, and progressive failover testing under formal go/no-go gates — and afterward took ownership of the vulnerability and patch management program and its 12-person team.

Outcome: Cut procurement downtime 66%. Brought demonstrated recovery time from 48 hours to 7 across 6 applications under live failover testing, converting DR into a governed annual program and closing 12 audit findings. Remediated 3,000+ vulnerabilities, 125+ critical, cutting time-to-remediate from 45 to 15 days and closing 75 more.

HCL / AstraZeneca

$700M Clinical IT Transition

Scope: In-sourced $700M in IT services across 26 categories into live systems.

Constraint: Live systems — a transition failure has clinical-trial consequences, not just downtime.

Outcome: Zero operational disruption. Backup and recovery redesigned underneath the transition to 95%+ success, cutting storage costs 35%.

HCL / Entergy

$11B Utility PMO & Infrastructure Modernization

Scope: Rebuilt PMO governance and operating structure for a $50M+ portfolio spanning infrastructure builds, upgrades, and consolidation projects — for a team of 5 portfolio managers and 45 project managers and technical staff.

Outcome: Modernized enterprise business intelligence and unified communications platforms for a 24% efficiency gain; delivered secure IT infrastructure for two new Transmission Operating Centers, reducing critical incident response time 12%.

How I Work

groups

Programs That Span Organizations

I convene teams outside my direct line of command and chair the gate-review forums that keep cross-functional programs shippable — work that has spanned five regions, and eight years of doing it at MD level at Citi.

sync_alt

Standing Up Operating Models From Zero

I have built a governance and delivery function from nothing twice — once for an energy utility, once for a converged-security firm — without a major operational disruption either time. What I leave behind is a method, not a folder of project files.

insights

Working at the Standards Edge

IEM-AIS tests against the live OWASP GenAI LLM Top 10 2026, fetched at runtime, not a static checklist. I am a volunteer reviewer on the PMBOK® Guide 8th Edition AI skills initiative, a volunteer on ISC2’s Certified in Cybersecurity exam development, and a published contributor to PMI’s Risk Management in Portfolios, Programs, and Projects practice guide. Contributor and reviewer roles, not authorship — work I do because I build production systems in the domains these standards govern.

Ask the AI

This assistant is one of the systems I built — and red-teamed. Try:

Open to AI governance, AI risk, and security program leadership roles — in financial services, healthcare, or anywhere AI systems are going into production under real regulatory pressure.

Get in Touch

Also

Writing: technical, architectural, projects, governance, AI related blogs, posts and publications.

Building Project LiftOff, a free, ungated CAPM preparation curriculum for aspiring project managers.

Connecting: a free space for project managers and mission-driven opportunities to find each other.

Measuring Where Delivery Data Breaks Down using IEM-PM Methodology.

Ramani Viswanathan

AI governance and security program leadership.

This site runs a custom, rate-limited LLM application I built and operate myself — see how it works.

© 2026 Ramani Viswanathan. All rights reserved.