Kevin Swaney

Principal Cybersecurity Engineer

Kevin Swaney is a principal cybersecurity engineer with 17 years in information security. His work centers on securing the tools people actually use: AI assistants, identity and access, and the governance that keeps both safe.

Connect on LinkedIn
Kevin Swaney, Principal Cybersecurity Engineer

About

I have spent 17 years in information security, most of it in security engineering and architecture. These days my focus is the security of AI tools in the workplace: controlled intake, data guardrails, identity for human and non-human accounts, and baselines that let people get the benefit without the exposure.

This site collects short technical notes on AI security, access control, and the fundamentals that still stop most incidents. For anything beyond that, LinkedIn is the best way to reach me.

Career highlights

Financial services, highly audited environments Career spent securing banks and FinTech firms operating under intense regulatory scrutiny. Deep hands-on leadership across NIST, ISO 27001, and PCI DSS compliance and audit remediation.
Offensive and defensive testing Led penetration tests and red team, blue team, and purple team exercises to validate defenses and sharpen response.
Data protection at scale Data management and data loss prevention programs, including CASB deployments with Netskope and Bitglass.
Enterprise security tooling Deployed CrowdStrike enterprise-wide. Deep operational experience with Palo Alto Cortex XSIAM, Palo Alto firewalls, Panorama, and GlobalProtect, plus Carbon Black. Worked alongside several MSSPs.
Identity overhauls Rebuilt IAM environments from the ground up: directory services, SSO, MFA, and conditional access done right.
Security awareness champion Built security awareness programs from scratch at financial institutions, partnering with HR to strengthen the human firewall and raise the security IQ of the workforce.
Cloud and DevSecOps Secured Microsoft, Google, and AWS environments. Hardened CI/CD pipelines and embedded security into infrastructure as code, shifting controls left without slowing delivery.
Vulnerability management programs Built vulnerability management programs from the ground up using Qualys and Nessus, covering ASPM and CSPM for application and cloud posture.
Microsoft Purview and SentinelOne Hands-on with Microsoft Purview for data governance and compliance, and SentinelOne for autonomous endpoint protection.

Education and credentials

Information Systems Security Professional, University of Georgia (2021) · Troy University (2015) · Palo Alto Networks Certified Engineer · CompTIA Security+

Writing

Notes

Controlled intake beats shadow AI People will use the tools that help them work. The security job is to make the approved path clear, fast, and safer than the workaround.
Identity is the control plane for AI agents Every agent needs an owner, a scope, a lifetime, and logs. If it can act, it needs identity discipline.
Keep less data Data you no longer keep cannot be breached or pasted into the wrong tool. Retention is a security control.