Jian Wang

CEO

New York, New York, United States22 yrs 11 mos experience
Highly StableAI Enabled

Key Highlights

  • 20+ years of experience in security leadership.
  • Expertise in AI/ML security and architecture governance.
  • Proven track record in building security programs from scratch.
Stackforce AI infers this person is a Security Architect specializing in AI Security and Identity Management in the SaaS industry.

Contact

Skills

Core Skills

Ai SecurityArchitecture GovernanceIdentity & Access ManagementPrivileged Access ManagementPenetration TestingSecurity Consulting

Other Skills

Agentic AI Threat ModelingAgent Identity & AuthorizationSecurity Risk AssessmentIdentity & Access Management (IAM)PAMIdentity GovernanceIAMWorkflow AutomationTechnical EngineeringProblem SolvingSecurity Methodologycyber leadershipStrategic RoadmapsTalent ManagementBudget Management

About

Security leader in McKinsey & Company with 20+ years of experience, spanning AI/ML security, security-by-design, architecture governance, Identity access and management, DevSecOps, cloud security, penetration testing and vulnerability management. Proven track record of building program/platform from ground up, driving cross-functional initiatives, influencing senior stakeholders, and embedding security-by-design across engineering teams. Expertise include establishing Architecture governance capability and operations, DevSecOps, Enterprise Identity & Privilege Access Management (IAM/PAM) program and operations , and building an internal penetration testing capability. Contributor to industry standards including OWASP AIVVS. My passion is enabling engineering teams to build secure systems without friction—making security an enabler, not a blocker. Key Areas of Impact: Architecture Governance: Built and led governance operations that integrated security-by-design across the product lifecycle and global engineering teams. Advanced AI Security: Actively contributing to industry standards (OWASP) for Agentic AI security and establishing guardrails for AI/ML security governance. Identity & Access Management (IAM/PAM): Directed the strategy and delivery for a platform supporting 500,000+ identities and 8,000+ privileged accounts DevSecOps & Automation: Operationalized policy-as-code into CI/CD pipelines to enforce security standards at scale , reducing manual oversight while strengthening enterprise-wide security compliance Offensive Security: Built and owned internal penetration testing capabilities from the ground up to ensure proactive risk identification.

Experience

22 yrs 11 mos
Total Experience
7 yrs 7 mos
Average Tenure
--
Current Experience

Mckinsey & company

2 roles

Principal Enterprise Security Architect on AI Security & Zero-Trust Architecture

Promoted

Jan 2021Feb 2026 · 5 yrs 1 mo · New York City Metropolitan Area

  • Agentic & AI Security and Cloud Security Architecture
  • Developed Firm-wide AI and agentic application guidelines, aligning security with industry best practices (OWASP Top 10 for LLMs, MITRE ATT&CK).
  • Conducted in-depth analysis of 90+ AI applications, defining consistent security architecture patterns and guardrails across engineering teams.
  • Performed security architecture reviews ensuring Zero Trust, IAM, and API security were embedded in agent design and integrated with firm systems.
  • Integrated security requirements into product lifecycles (AISecOps) and vendor assessments, improving enterprise-wide LLM adoption.
  • Identified security gaps in agentic AI applications and partnered with engineering leadership to develop a roadmap for mitigation
  • Delivered AI security training sessions for developers and architects, covering input validation, output handling, authentication, authorization, and monitoring best practices.
  • Designed end to end agent workload identity federation model based and full stack output validation framework
  • . Experienced AI RMF, ISO42001, AI Safety planning and measurement, AI red teaming and AI incident response
  • Contributed as a reviewer/contributor to the OWASP AI/Agent Top 10 Risk Project.
  • Architecture Governance and Standards
  • Designed and implemented enterprise Architecture Governance processes, integrating with product security risk assessments and procurement.
  • Led governance reviews for 120+ solutions and changes, identifying 50+ security and compliance gaps and driving remediation planning.
  • Managed relationships with 30+ stakeholders
  • Directed architecture governance strategic planning and frameworks, defining OKRs and roadmaps to strengthen security and risk posture.
  • Delivered data-driven insights and recommendations to executive leadership through monthly and quarterly reviews.
  • Led a team of 7 architecture governance coaches, ensuring consistent review and compliance with enterprise standards
Agentic AI Threat ModelingAgent Identity & AuthorizationAI SecurityArchitecture Governance

Senior Security Architect on IAM and Enterprise Security

Jul 2007Jan 2021 · 13 yrs 6 mos · New York City Metropolitan Area

  • Enterprise Identity & Privilege Access Management (2007-2021)
  • Architected the Firm’s identity governance platform supporting 500K+ identities, 13+ lifecycle processes, and 10+ critical system integrations.
  • Designed enterprise RBAC/ABAC/PABC authorization framework for human and non-human identities.
  • Integrated Okta, AD, Entra, and IGA for unified lifecycle and entitlement management.
  • Modernized IAM process in partnership with HR, Finance, Legal, Workstation, Support, Helpdesk, Audit, and Engineering.
  • Led privileged access program managing 8,000+ admin accounts, integrating workflow, vault system, AD, Unix/Windows, databases, and network devices.
  • Cut privileged access approval time from 4+ weeks to 5 minutes through workflow automation.
  • Eliminated 800+ unnecessary privileged accounts and reduced orphan accounts and unused service accounts by 90%.
  • Led platform architecture, strategic planning, roadmap, vendor selection, contract negotiation, and outcome-based delivery, ensuring alignment with enterprise security goals.
  • Built strong cross-functional alignment with 20+ global teams, influencing senior stakeholders on identity modernization and privilege reduction
  • Mentored and guided junior architects, engineers, and developers, supporting professional development and building a high-performing IAM team.
  • Knowledge of OAuth2.0, OIDC, SAML, SCIM
  • Application Security & Penetration Testing (2007-2014)
  • Built McKinsey’s internal penetration testing capability and application security framework.
  • Performed threat modeling for high-value systems and drove remediation efforts.
  • Led major audit finding remediation, strengthening compliance posture.
  • Recommended new security technologies to leadership to support long-term strategy.
Identity & Access Management (IAM)PAMIdentity & Access ManagementPrivileged Access Management

Ey

Senior Consultant

Feb 2006Jul 2007 · 1 yr 5 mos · New York City Metropolitan Area

  • Conducted penetration testing and code review for bank and financial services
  • Developed penetration testing methodology, processes and customized penetration testing tool
  • Communicated the test results to clients and provided guidance and recommendations for remediations
  • Engaged security community like OWASP for research
  • Coached junior team members to improve skills.
Technical EngineeringProblem SolvingPenetration TestingSecurity Consulting

Gosecure. inc

Security Analyst

Mar 2003Feb 2006 · 2 yrs 11 mos · Canada

  • Conducted penetration testing on phones, applications, devices and firewalls for public and private sectors.
  • Developed security awareness training (google hacking) class for customer
  • Developed penetration testing methodology, processes and customized penetration testing tool
  • Communicated the test results to clients and provided guidance and recommendations for remediation
Technical EngineeringProblem Solving

Education

Concordia University

Master's degree — Computer Science

Stackforce found 100+ more professionals with Ai Security & Architecture Governance

Explore similar profiles based on matching skills and experience