Peter K. Boucher
Sandy Springs, GA 30350 | pkboucher@hotmail.com |
LinkedIn: linkedin.com/in/peterboucher

EXECUTIVE SUMMARY

Strategic cybersecurity architecture leader with 25+ years of success driving secure-by-design initiatives, threat modeling, and resilient hybrid-cloud solutions across global enterprises and startups. Trusted advisor to product and engineering teams, translating security principles into actionable architecture spanning AWS, Azure, and GCP. Proven expertise in Zero Trust, DevSecOps, secure multi-cloud design, and mentoring high-performing security architects.

CORE COMPETENCIES

Security Architecture: Secure-by-Design, Zero Trust, Multi-Cloud, CIAM, Container Security
Architecture Governance: SSDLC, Risk Management, DevSecOps, Threat Modeling
Regulatory & Frameworks: NIST 800-53, ISO 27001, SOC 2, FFIEC, GLBA, GDPR, HIPAA
IAM & Cryptography: PKI, Secrets Management, OAuth2, OIDC, SAML, TLS, KMS
Emerging Technologies: GenAI Security, OWASP LLM Top 10, AWS, Azure, GCP, API Security
Leadership & Advisory: Architecture Mentorship, Engineering Enablement, Incident Response Support

PROFESSIONAL EXPERIENCE

Deloitte Consulting LLP — Atlanta, GA

DC Product Architecture Lead, Deloitte Certified Chief Architect | June 2015 – June 2025

- Directed security architecture and GRC strategy for Deloitte’s Innovation & Technology portfolio, impacting 30+ SaaS platforms.
- Led cybersecurity architecture of ACA-1095B, a Deloitte Tax product handling Federal Tax Information (FTI); implemented FIPS 140-2 encryption, role-based access, audit logging, and incident response in compliance with IRS 1075, exceeding NIST 800-53 and SOC 2 requirements.
- Designed and deployed the Samba Security IAM platform; led enterprise transition to CIAM for consistent access management.
- Enabled SOC 2 and HIPAA compliance by embedding SSDLC 2.0 practices across product teams.
- Provided real-time consultation to product and engineering teams on architectural decisions, secure coding, and DevSecOps pipelines, significantly reducing delivery risk and vulnerability volume.
- Led threat modeling workshops, architecture reviews, and security control designs for enterprise tools and customer-facing platforms, aligning with NIST, SOC 2, and HIPAA standards.
- Evangelized AI/ML security by extending SSDLC practices to MLOps pipelines and delivering thought leadership on the OWASP Top 10 for LLMs.

First Data Corporation — Atlanta, GA

Director of Security Architecture, Global Cyber Security Solutions | July 2012 – June 2015

- Directed platform security for TransArmor, tokenization, and PCI DSS compliance efforts.
- Consulted with sales and compliance on secure architectures for client solutions.
- Certified ISA in order to guide First Data’s PCI audit readiness.
- Led cyber due diligence and security integration for M&A activities including Clover.
- Spearheaded cryptographic remediation initiatives, replacing vulnerable SSL/TLS stacks with modern cipher suites across distributed environments.

Panoptic Security, Inc. — Sandy, UT

Founder & Chief Security Architect | Jan 2008 – July 2012

- Founded ExpertPCI SaaS platform; scaled product using Java, Spring MVC, and MySQL.
- Acted as CISO, leading secure SDLC initiatives and client compliance advisory.
- Certified QSA; led PCI assessments and risk consulting for national clients.
- Supported successful acquisition by Sysnet, balancing technical and shareholder interests.

Senforce Technologies, Inc. — Salt Lake City, UT

Security Architect | Jan 2001 – Jan 2008

- Designed encryption and endpoint security modules for enterprise data protection.
- Led iNAC team building posture enforcement and network quarantine solutions.
- Directed Common Criteria EAL 4+ certification and authored U.S. patent applications.

Earlier Roles:

Held senior security roles at Novell, SRI International, Arca Systems, and Gemini Computers. Designed cryptographic controls, contributed to MLS and B1/A1 systems, and led secure DBMS research for DoD.

EDUCATION

Georgia Institute of Technology — MS, Computer Science

University of California, Santa Cruz — BA, Computer & Information Sciences

CERTIFICATIONS

CISSP (ISC²), 2014 – Present
Deloitte Certified Chief Architect, 2022 – Present
AWS Certified AI Practitioner, 2025 – Present
AWS Security Specialty 2025 – Present
PCI Qualified Security Assessor (QSA), 2010 – 2012, and Internal Security Assessor (ISA), 2013 – 2015
Additional Certifications: https://www.credly.com/users/peter-boucher.713bbf05

ADDITIONAL INFORMATION

Patents & Publications: Inventor on 8 U.S. patents; author of 6 peer-reviewed publications. Full list available on request.