Available for advisory & architecture engagements

Kim Go

Technology Executive · Enterprise & Solutions Architect · AI and Cybersecurity Leader

Twenty-five years building and securing systems that have to work — from hands-on software engineering through senior engineering leadership to C-level technology strategy. I design production AI, multi-cloud architecture, and security and compliance programmes, then translate the hard parts into decisions a board can actually make.

25+Years in software, cloud and security
C-LevelProduct, web and engineering leadership
4 CloudsAWS, Azure, GCP and OCI in production
PatentedNamed inventor, U.S. Patent 11,244,357
Services

What I’m engaged to do

Most engagements fall into one of six areas. They overlap more often than not — an AI system that handles regulated data is an architecture problem, a security problem and a governance problem at the same time.

AI & LLM Systems Engineering

Production AI, not prototypes: retrieval pipelines, agentic tool-calling, natural-language querying over real data, and the evaluation harness that tells you when a release has quietly got worse.

  • RAG pipelines
  • Agentic function calling
  • Text-to-SQL
  • Vector search
  • Multi-model routing
  • MCP servers & AI gateways
  • Drift monitoring

Cloud Architecture & Modernisation

Legacy estates moved to cloud-native without a big-bang rewrite, and over-provisioned estates right-sized. Serverless and containers where they earn their keep, not everywhere by default.

  • AWS
  • Azure
  • GCP
  • Oracle OCI
  • Serverless
  • Microservices
  • Containerisation
  • Cost right-sizing

Cybersecurity & Compliance

Defending web applications and APIs against automated and human attackers, and getting organisations audit-ready in regulated sectors — mapped to the framework the auditor will actually use.

  • WAF & bot mitigation
  • IAM & Zero Trust
  • Encryption
  • SOC 2
  • ISO 27001
  • NIST CSF
  • HIPAA
  • PCI DSS 4.0
  • FFIEC

Enterprise Architecture & Integration

Making systems that were never designed to talk to each other work together reliably — ERP and CRM modernisation, API and multi-tier design, and high-volume data exchange that fails loudly instead of silently.

  • TOGAF ADM
  • REST API design
  • ERP/CRM modernisation
  • Oracle Fusion & EBS
  • SAP
  • NetSuite
  • Dynamics 365
  • EDI 850/855/810/940
  • ETL

AI Governance & Risk

A defensible boundary between what a model may do on its own and what a human signs off. I use a tiered-autonomy model that classifies every automated action, so the human-in-the-loop line is explicit and auditable rather than assumed.

  • Tiered autonomy (T1/T2/T3)
  • Human-in-the-loop design
  • Model lifecycle & MLOps
  • Release gating on measured accuracy
  • Audit trails

Executive Technology Advisory

For leaders who need an independent read on a build-versus-buy call, a vendor claim, a modernisation roadmap or an architecture already in flight — explained in business terms, with the trade-offs stated plainly.

  • Architecture decision leadership
  • Modernisation roadmaps
  • Vendor & platform evaluation
  • RFP authoring
  • Board-level communication
  • Engineering KPIs
How I work

Engineering fluency, executive translation

I still write the code. That is the point — advice about an architecture is worth more from someone who has had to operate one at three in the morning.

Understand before proposing

Scoping, requirements across departments, and an honest inventory of what already exists. Most failed modernisations were mis-scoped, not mis-built.

Prove it on the real thing

Pilots validated against actual business scenarios and real data, not a demo path. Problems surface while they are still cheap.

Measure what matters

Releases gated on measured accuracy and output quality, not just uptime. A system that is up and wrong is not working.

Hand over properly

Runbooks and documentation so your team owns the system afterwards. The goal is to make myself unnecessary.

Technical depth

Where the hands-on experience sits

Not a tool list for its own sake — these are the areas where I can design, build, review and debug rather than only advise.

AI & Machine Learning

  • RAG and hybrid vector search
  • Agentic systems & tool calling
  • Text-to-SQL and NL analytics
  • Embeddings & semantic retrieval
  • MCP servers and AI gateways
  • Model governance & drift detection

Cloud Platforms

  • AWS — Lambda, Bedrock, Kinesis, Step Functions, Aurora, DynamoDB, API Gateway, CloudFront
  • Azure — OpenAI, AI Search, Functions, Data Factory, Front Door
  • GCP — Vertex AI, BigQuery
  • Oracle OCI — Cloud Guard, Security Zones

Security & Governance

  • WAF, bot mitigation, DDoS posture
  • IAM, Zero Trust, encryption & KMS
  • Penetration testing & forensics
  • SIEM, CSPM and CNAPP tooling
  • GRC programmes and audit readiness

Engineering

  • Python, C/C++, TypeScript & JavaScript
  • Node.js, PHP, .NET, SQL
  • React and Angular front ends
  • Docker, ECS and Kubernetes
  • CI/CD automation

Data & Analytics

  • ETL and large-scale data movement
  • Databricks, Snowflake, Redshift
  • Oracle, PostgreSQL, MySQL, MSSQL
  • Power BI, Tableau, Splunk, DataDog

Enterprise Systems

  • Oracle Fusion Cloud & E-Business Suite
  • SAP, NetSuite, Dynamics 365, Epicor
  • Salesforce, HubSpot, ServiceNow
  • Shopify, Magento, WordPress, Drupal
  • EDI and enterprise data exchange
Credentials

Formal qualifications

TOGAF 9 CertifiedEnterprise Architect
AWS Certified SecuritySpecialty
AWS Certified AI PractitionerApplied AI on AWS
AWS Certified Cloud PractitionerCloud foundations
U.S. Government ClearanceConfidential
U.S. Patent 11,244,357Named inventor — rules-based content targeting
Contact

Let’s talk about the problem

Whether it is an AI system you need built properly, an architecture you want a second opinion on, or a compliance deadline you have to hit — start with the problem and we will work out whether I am the right person for it.