John
AI developer
- Розглядає посади:
- AI developer, SEO specialist, Project manager, спеціаліст з кібербезпеки, офіцер
- Вік:
- 52 роки
- Місто проживання:
- Київ
- Готовий працювати:
- Київ, Львів
Контактна інформація
Прізвище, контакти та світлина доступні тільки для зареєстрованих роботодавців. Щоб отримати доступ до особистих даних кандидатів, увійдіть як роботодавець або зареєструйтеся.
Отримати контакти цього кандидата можна на сторінці https://www.work.ua/resumes/20353738/
Завантажений файл
Файл містить ще 1 сторінку
Версія для швидкого переглядуЦе резюме розміщено у вигляді файлу. Ця версія для швидкого перегляду може бути гіршою за оригінал резюме.
AI Engineer & Architect · AI Governance & Privacy by Design
Agent Systems · AI Memory · Voice · Multi-Model Orchestration · ISO 42001 · NIST AI RMF · EU AI Act
Kyiv, Ukraine — Remote · [
I build AI systems and govern them as one practice: the same controls that make an AI system reliable — deterministic
checks around every model call, a human approval gate on anything that ships, and an audit trail of what ran — are the
controls that make it governable. As an AI engineer I ship agent management systems and harnesses, persistent memory
and second-brain services, live voice and translation interfaces, CLI and headless-browser automation, and orchestration
across multiple language models. As an ISO 42001 and ISO 27001 Lead Auditor and Lead Implementer and EU GDPR
Practitioner, I engineer them to governed standards, built to run where data is sensitive and audited.
I make these systems reliable and affordable. I route work across providers and accounts (Anthropic Claude, OpenAI, xAI
Grok and local models) with automatic failover, run deterministic rules and quality checks before and after each model call,
keep a human approval gate on anything that ships, and cut token cost by assembling a fresh, minimal context for every run
instead of letting one grow.
Privacy, data use, access control and auditability are designed in from the start, aligned to ISO 42001, the NIST AI Risk
Management Framework and the EU AI Act. This comes from more than a decade securing billion-dollar, APRA-regulated
enterprises: the data-classification discipline becomes context minimisation, audit trails become memory provenance, and the
change-approval workflow becomes the human gate on anything an agent ships.
Availability. Based in Kyiv · open to remote roles in AI engineering and AI governance, and in cyber GRC, with teams in Europe, the
UK, Australia and the US. Special interest: agent infrastructure, AI memory, developer tools, voice-driven products, efficient
multi-model systems, and governed AI for regulated environments.
TECHNICAL STACK
Languages Python · JavaScript / Node.js · TypeScript · SQL · Bash
AI & LLMs Anthropic Claude · OpenAI GPT · xAI Grok · local / open models · multi-provider
routing · RAG · prompt & context engineering · agentic systems
AI Governance & Privacy ISO 42001 (AIMS) · NIST AI RMF · EU AI Act · GDPR · ISO 27001 · NIST CSF 2.0 · data
lineage & audit
Cyber GRC & Assurance ISO 27001 · SOCI · ASD Essential Eight · CPS 234/235 · AESCSF 2.0 · PCI DSS 4.0 · IEC
62443 · MITRE ATT&CK · FAIR
Regulatory Coverage EU AI Act · GDPR · NIS2 · DORA · US NIST AI RMF · CCPA / CPRA · HIPAA · SOC 2 · SEC Cyber ·
AU Privacy Act · SOCI · CPS 234/235
Protocols & Automation Model Context Protocol (MCP) · Chrome DevTools Protocol (CDP) · headless-browser
automation · CLI tooling · cron / launchd
Data & Runtime SQLite · PostgreSQL · Docker · Next.js · WebSocket · reportlab
CORE ENGINEERING & GOVERNANCE CAPABILITIES
Agent Systems & Orchestration AI Governance, Privacy & Security by Design
Agentic system design (LLMs plus tools) · Multi-agent fleet AI Management Systems to ISO 42001 (build & audit) · AI risk
control, many agents at once · Human-in-the-loop approval gates mapping: NIST AI RMF, EU AI Act · Privacy by design: data
on output · Pre-warmed worker pool, concurrency control, request minimisation, purpose limits · Access control, audit trails & data
queuing · Routing tier selected by task difficulty · Automatic lineage · Human oversight and approval as release controls ·
provider / account failover Model governance and secure-by-design delivery
Memory, Retrieval & Context Model Routing, Cost & Quality
Persistent-memory / second-brain service for agents · Recall with Model routing across providers and accounts · Automatic failover
provenance, supersede and history · Retrieval-augmented for reliability · Cost control via routing + token efficiency ·
generation (RAG) · Token-efficiency & context-window Deterministic-first (rules / scripts before a model) · Independent
engineering · Fresh-context assembly (packs, tiered file adversarial verification of results · Human approval as a reliability
abstracts) · Prompt & context engineering control
Dr John Mackenzie · AI Engineer & Architect Page 1
Dr John Mackenzie AI Engineer & Architect · AI Governance & Privacy by Design
Voice & Multimodal Interfaces CLI & Browser Automation
Live voice and translation interface · Per-language spoken CLI tooling and build pipelines · Headless-browser automation
playback (Listen) · Two-way real-time translation · Voice-driven (Chrome DevTools Protocol) · Capture and extraction pipelines ·
interaction design Scheduling automation (cron / launchd)
Regulated Sectors & Domains
Banking, finance & superannuation (APRA-regulated) · Critical
infrastructure — power, water, gas (SOCI) · Resources & energy
— oil, gas, METS · Federal & state government · Aged care,
community services & waste management
SELECTED AI SYSTEMS
Multi-Model Orchestration Harness
Routes AI work across several model providers and accounts, with automatic failover when one errors.
Built. A routing layer that selects a model for each task, holds a pre-warmed pool of sessions with concurrency control and
request queuing, and fails over to another provider or account the moment a call errors.
Stack. Python · Node.js · Anthropic Claude · OpenAI · xAI Grok · local models · deterministic pre-checks ·
MCP
Impact. Fails over automatically, so one provider's outage does not stop the work; routing each task to a fit-for-purpose model
rather than the most expensive one controls cost, and every routing decision is logged for audit.
Persistent Memory Service for AI Agents
A shared long-term memory that agents write to and recall from across sessions.
Built. Recall, provenance tracking, supersede (replace an old fact with a corrected one) and full history, all exposed to agents
over the Model Context Protocol (MCP).
Stack. Python · SQLite · MCP server · provenance & version history
Impact. Agents keep grounded context between sessions and can trace every fact to its source, so the record stays auditable.
Agent Management & Human-Approval System
A fleet controller that runs many agents and holds their output behind a human sign-off.
Built. Launches and tracks many agents at once, sends their work through deterministic checks and a human approval gate,
then writes status back to a record store.
Stack. Node.js · Python · human-in-the-loop gates · record-store write-back · CDP capture
Impact. Autonomous agents do the work while a person still approves anything that leaves the system — reliable and controlled
for sensitive settings.
Live Voice & Translation Interface
A voice interface with per-language spoken playback and two-way real-time translation.
Built. A live interface that speaks output for each language on demand and translates both directions between two speakers.
Stack. JavaScript / Web · browser speech & translation · real-time two-way flow
Impact. People who speak different languages talk and each hears the other in their own language, without stopping to swap
tools; speech is used only to translate and play back — purpose-limited by design.
Context-Engineering & Token-Efficiency Toolchain
A developer toolchain that assembles a fresh, minimal working context per run instead of letting context pile up.
Built. Tooling that builds a clean context from packs and tiered file summaries, plus CLI and headless-browser automation for
capture, extraction and build steps.
Stack. Node.js · Python · CLI · Chrome DevTools Protocol · tiered file abstracts
Impact. Each run starts lean, which cuts wasted tokens and keeps long, multi-step sessions affordable — and puts less data in
each prompt, a privacy gain from minimising context.
System names generalised; several are private client or internal tools. Live products and research at jmactech.com.
AI GOVERNANCE, PRIVACY & ASSURANCE
Dr John Mackenzie · AI Engineer & Architect Page 2
Dr John Mackenzie AI Engineer & Architect · AI Governance & Privacy by Design
AI Management Systems. Build and audit AI Management Systems to ISO 42001 as Lead Auditor and Lead Implementer; map AI
systems to the NIST AI Risk Management Framework and classify them against the EU AI Act — risk tier, human oversight,
transparency and record-keeping.
Privacy & Data Protection. Privacy by design engineered into the systems above: data minimisation, purpose limitation, access
control and audit trails — aligned to EU GDPR, US privacy law (CCPA / CPRA, HIPAA) and the Australian Privacy Act 1988. EU
GDPR Practitioner.
Regulated-Enterprise Track Record. More than a decade of cyber GRC for 14+ billion-dollar enterprises (10 ASX-listed, >$1 trillion
combined), APRA-regulated and to Big 4 audit standard — the enterprise control discipline that now underwrites the governance built
into the AI systems above.
Assurance & Security Frameworks. ISO 27001, NIST CSF 2.0, ASD Essential Eight, CPS 234/235 and MITRE ATT&CK, applied
so AI systems are defensible, auditable and safe to operate in sensitive settings.
CYBER GRC, RISK & ASSURANCE
A Decade Of Regulated-Enterprise GRC. More than a decade delivering cyber governance, risk and compliance to 14+
billion-dollar enterprises — 10 ASX-listed, >$1 trillion combined value — across IT and operational technology, to Big 4 auditor and
APRA standard. Risk assessments covered assets with more than $300 billion in funds under management. This is the enterprise
control discipline I now engineer directly into AI systems.
APRA Financial Services — CPS 234 & CPS 235. Directed enterprise-wide cyber risk for APRA-regulated financial-services firms
— Insignia, Affinia, Count, AMP, RI Finance and Centrepoint. Built and led their security frameworks to CPS 234 and CPS 235:
enterprise risk assessments, identity and privileged access management (IAM/PAM), data classification, supply-chain risk and
information-security controls.
Critical Infrastructure & OT/ICS — SOCI. Ran the NT Power & Water security uplift across 11 operational-technology and ICT
domains under SOCI — AESCSF v1 and v2, NIST CSF, ISO 27001 and ISO 31000. Covered identity and privileged access, asset
management, supply chain, privacy, PCI DSS 4.0 and OT threat monitoring for power, water and gas systems.
Frameworks & Standards In Practice. SOCI · ASD Essential Eight · ISM · AESCSF 2.0 · CPS 234/235 · NIST CSF 2.0 · ISO 27001
· ISO 31000 · PCI DSS 4.0 · IEC/ISA 62443 · FAIR · MITRE ATT&CK — applied in live enterprise and critical-infrastructure
programmes, not just held as certifications.
Assurance, Audit & Certification. Lead Auditor across ISO 27001, ISO 9001, ISO 22301, ISO 20000 and ISO 42001 — running
management-system audits, gap assessments and ISMS implementations through to certification. Internal audit restructured around
catastrophic risk and weak signals, with board-level assurance reporting and traceable governance decisions. The same audit and
evidence discipline now governs how I build and sign off AI systems.
Regulatory Coverage — EU, US & Australia. AI: the EU AI Act and the US NIST AI Risk Management Framework — risk tiering,
human oversight, transparency and record-keeping. Privacy: EU GDPR, the US regime (CCPA / CPRA, HIPAA, GLBA) and the
Australian Privacy Act 1988 / OAIC. Cyber and operational resilience: EU NIS2 and DORA, US NIST CSF 2.0, SOC 2 and the SEC
cyber-disclosure rules, and Australian SOCI, APRA CPS 234/235 and the ASD Essential Eight. I map and classify AI and data
systems against whichever regime applies — the same privacy-by-design discipline now built into the AI systems above.
Client Base. NT Power & Water · Insignia · Affinia · Count · AMP · RI Finance · Centrepoint · JJ's Waste · Ozcare · Uniting Care ·
Department of Corporate & Digital Services · various Federal and State government agencies.
EXPERIENCE
Founder & AI Engineer 2015 – Present
JMacTech — AI Systems, Secure-AI & SaaS
■ Build and ship AI systems end to end: multi-model orchestration harnesses, a persistent-memory service over MCP, an
agent-management system with human-approval gates, a live voice and translation interface, and a token-efficiency
toolchain (see Selected AI Systems).
■ Engineer privacy, access control, auditability and model governance into these systems, aligned to ISO 42001 (AIMS), the
NIST AI Risk Management Framework and the EU AI Act — so they are safe to run on sensitive, regulated data.
■ Run deterministic rules and quality checks before and after each model call, with a human approval gate on anything that
ships; route across providers and accounts with automatic failover for reliability and cost control.
■ Design, build and ship AI-built SaaS and internal platforms — full lifecycle from architecture to deployment.
Dr John Mackenzie · AI Engineer & Architect Page 3
Dr John Mackenzie AI Engineer & Architect · AI Governance & Privacy by Design
■ Advised on the AI architecture and implementation strategy for a billion-dollar global consulting firm (31 countries, 1,600
staff, 16,000 business clients) operating under strict regulatory and data constraints.
■ Author research on AI governance and deliver ISO 42001 / AI training globally through JMacLearning.
Senior GRC / Cyber Consultant 2012 – Present
Digital Enterprises
■ Delivered cybersecurity strategy to 14+ billion-dollar enterprises (10 ASX-listed, >$1 trillion combined) across IT and
operational technology; risk assessments on assets with >$300 billion funds under management, to Big 4 auditor and
APRA requirements.
■ Built GRC programmes combining ISO 27001, NIST CSF 2.0 and the ASD Essential Eight — the same access-control,
data-classification and auditability controls I now design into AI systems.
■ Ran the NT Power & Water security uplift across 11 OT and ICT domains under SOCI (AESCSF v1/v2, NIST CSF, ISO
27001/31000): identity and privileged access, asset management, supply chain, privacy, PCI DSS 4.0 and
operational-technology threat monitoring.
■ Directed IAM/PAM, supply-chain risk, data classification and OT/ICS uplift for APRA-regulated financial-services and
critical-infrastructure clients across power, water and gas.
Head of Cyber & Risk 2022 – 2023
Security In Depth
■ Directed enterprise-wide cyber risk for APRA-regulated financial-services firms — Insignia, Affinia, Count, AMP, RI
Finance and Centrepoint — building and leading their security frameworks to CPS 234/235, ISM, NIST CSF 2.0 and ISO
27001, lifting posture and compliance readiness.
■ Managed internal teams and external consultants across all client entities.
Commonwealth Business Advisor 2015 – 2017
Australian Federal Government — AusIndustry / Dept. of Industry
■ Commonwealth-appointed Business Advisor across two national Growth Sectors — Mining, Equipment, Technology &
Services (METS) and Oil, Gas & Energy Resources — advising resources and mining-services firms on capability, growth,
innovation and technology adoption.
■ Supply-chain facilitator to the INPEX ~$50B construction programme and the Jemena ~$800M pipeline: supplier capability,
qualification and integration into tier-one project supply chains.
Commercial Lending Manager 1991 – 2009
Major Australian Banks
■ Originated, structured and managed a commercial lending portfolio exceeding $500 million across corporate, SME and
commercial-property sectors, within APRA-regulated environments.
■ Deep credit-risk, financial-analysis and regulatory-compliance expertise — the foundation that now informs advisory work
with APRA-regulated entities on CPS 234, CPS 235 and cyber governance.
Across banking, resources and government, three decades in audited, high-consequence environments shape how I engineer AI for
sensitive data — the same instinct for evidence, approval and traceability, now applied to models and agents.
RESEARCH & AUTHORSHIP
Books. Black Snow: Boardrooms Playing Billion Dollar Chinese Whispers · Hacked! Why You? · Black Snow: Banking & Finance
(forthcoming)
Frameworks. Six independent research papers establishing original cyber-risk and governance methodologies:
■ Cyber Cube Theory — reframes serious cyber incidents as governance failures — board oversight, control reality, assurance
quality, AI, suppliers and evidence combined into cyber defensibility.
■ A General Theory of Organisational Cyber Risk — cyber risk as a survivability problem in a tail-dominant environment.
■ Sequence Matters — Non-Commutative Operators — the order of cyber interventions changes the risk outcome.
■ The Cyber Butterfly Effect — small tolerated weaknesses propagate into disproportionate harm.
■ Advocatus — board-level challenge architecture — structured dissent, proportional proof, traceable governance decisions.
■ Black Snow–Informed Internal Audit — audit restructured around catastrophic risk, weak signals, sequencing and assurance
distortion.
Dr John Mackenzie · AI Engineer & Architect Page 4
Dr John Mackenzie AI Engineer & Architect · AI Governance & Privacy by Design
Full list at jmactech.com/research.
EDUCATION & CERTIFICATIONS
Academic. Doctorate of Computer Science (EMIT) · Doctorate of Business Administration (Cyber) — Candidate · MBA (AIM
Business School) — Candidate · Graduate Diploma of Strategic Leadership · Graduate Certificate in Commerce (Finance)
AI & Machine Learning. ISO 42001 AIMS — Lead Auditor / Lead Implementer / Internal Auditor / Foundation · AI Risk Manager
(AIRMPC) · AI Agent Manager (AIAM) · AI Project Manager (AIPMFP) · AI Prompt Engineering (APEPC) · Generative AI (GAIPC) · AI
Professional (CAIPC) · AI Expert (CAIEC) · AI & Law
ISO Management Systems. ISO 27001:2022 ISMS — Lead Auditor / Lead Implementer / Internal Auditor / Foundation · ISO
9001:2015 QMS — Lead Auditor · ISO 22301:2019 BCMS — Lead Auditor / Internal Auditor / Foundation · ISO 20000:2011 SMS —
Lead Auditor / Internal Auditor / Foundation
Cyber, GRC & Privacy. GRCP · GRCA · Certified GRC Auditor · Integrated Audit · Data Privacy · Lead Cyber (LCSPC) · Foundation
Cyber (CSFPC) · Ethical Hacking (CEHPC) · EU GDPR Foundation & Practitioner · MITRE ATT&CK Fundamentals
Technical & Professional. Blockchain (BCPC) · Big Data (BDPC) · DevOps (DEPC / DAPC) · Advanced Diploma — IT / IT Cyber
Security / Business Cyber Security · Advanced Diploma — Leadership & Management · Diploma — Leadership & Management / HR
/ Quality Auditing · Cert IV Training & Assessment · NLP Practitioner
90+ completed qualifications across AI, cybersecurity, ISO, GRC, business and data & law. Full training register available on request.
RECOGNITION & MEMBERSHIPS
Recognition. Australian Government Baseline Security Clearance (current) · 2022 ADF Cyber Gap Program Graduate · Finalist, NT
Cyber Security Practitioner of the Year (2020, 2021) · Finalist, NT Cyber Security Business of the Year (2021).
Memberships. Australian Computer Society · Australian Information Security Association · Australian Institute of Directors · OCEG
GRC · Australian Risk Policy Institute · Australasian Cyber Law Institute · Institute of Strategic Risk Management · Association of
Data Scientists.
Dr John Mackenzie · AI Engineer & Architect Page 5
Інші резюме цього кандидата
Розглядає посади: GRC Cybersecurity manager, Продукт-менеджер, Інженер з продажу, ще 7 посад
200 000 грн
Київ, Дистанційно
Середня спеціальна освіта
- AI Developer/Architect & GRC Cybersecurity Manager, Digital Enterprises, 13 років 10 місяців
Схожі кандидати
-
AI-креатор
40000 грн, Київ, Дистанційно -
Front-end програміст
Київ, Дистанційно -
AI creator
Львів, Дистанційно -
Python-програміст
Львів, Дистанційно -
Ai креатор
Київ, Дистанційно -
Backend програміст
Київ, Львів , ще 2 міста