← Scott Baker Data Agency

Scott Baker — Résumé

SCOTT BAKER

Phoenix, AZ, USA · scott@scottbakerdata.agency · scottbakerdata.agency · Open to Remote AWS Certified Solutions Architect – Associate · Databricks Certified Associate Developer Verify AWS Credential: credly.com/badges/0957ca40-e7ba-4984-99b8-444e8de58a18 Verify Databricks Credential: credentials.databricks.com/embed/96e65e17-56d5-4682-a8f4-c9e77b2a7251


PROFESSIONAL SUMMARY

Senior AI Governance, Risk & Compliance professional with 12+ years of enterprise security, vulnerability management, and regulatory compliance across highly regulated environments (Healthcare, Cloud Services, Distributed Systems). Hands-on record executing formal HITRUST audit remediation, enforcing HIPAA data-privacy baselines, and hardening multi-cloud architectures (AWS, GCP). Bridges hard engineering execution and executive risk registers, and applies emerging AI regulatory frameworks (NIST AI RMF 1.0, ISO/IEC 42001, EU AI Act) so enterprise generative-AI workloads, RAG pipelines, and data flows stay secure, auditable, and continuously compliant.


CORE COMPETENCIES


CERTIFICATIONS


PROFESSIONAL EXPERIENCE

AI Governance & Cloud Security — Independent Technical R&D | Phoenix, AZ (Remote)

December 2022 – Present * AI Governance capstone (healthcare data exchange): Built a simulated enterprise HealthTech interoperability platform on GCP with inline PII/PHI tokenization and redaction (Model Armor) before LLM inference — preventing model data leakage and demonstrating continuous HIPAA-aligned generative-AI controls. * Automated compliance & risk monitoring: Configured GCP Security Command Center evaluations against CIS Google Cloud Foundations Benchmarks and NIST CSF 2.0; enforced least-privilege IAM, VPC Service Controls, and CMEK to remediate simulated SOC 2 Type II findings. * AI framework application: Mapped enterprise generative-AI use cases to NIST AI RMF 1.0, ISO/IEC 42001, and the EU AI Act (risk classification, documentation, human-oversight and monitoring controls).

Senior IT Analyst & Security Administrator | Ultra Clean Technologies

June 2019 – August 2022 * Governed enterprise EDR (CrowdStrike) across a global fleet; administered CyberArk PAM to enforce zero-trust credential security. * Engineered automated OS imaging and patch-management schedules (SCCM), maintaining baseline configuration audits and neutralizing zero-day exposure.

Desktop & Systems Support Engineer | Cognizant (TJ Maxx Project)

April 2018 – June 2019 * Led rapid remediation during mission-critical outages (network, Hyper-V), restoring 24/7 retail application uptime. * Authored SOPs and remediation documentation, enforcing procedural compliance across Tier 1/2 support.

Information Security & Compliance Analyst | CIOX Health, Inc. (now Datavant)

April 2014 – October 2017 * HITRUST policy architecture & audit remediation: Co-authored the enterprise security-policy framework and drove technical remediation cycles that resulted in official HITRUST certification and continuous HIPAA compliance. * Secure PHI chain of custody: Orchestrated remote medical-record retrievals on hardware-encrypted IronKey drives (AES-256 / FIPS 140-2); enforced strict Chain-of-Custody documentation with zero HIPAA privacy violations. * Threat detection & vulnerability engineering: Administered network IDS; deployed OpenVAS across Linux fleets; managed Qualys scanning, translating findings into formal remediation to enforce compliance baselines and harden servers.

Level 3 Linux Systems Engineer | Endurance International Group (now Newfold Digital)

July 2012 – February 2014 * Managed technical escalations for 120+ enterprise accounts; advised stakeholders on server hardening, VPS security, and database optimization on Ubuntu/RHEL.


EDUCATION

Western Governors University | Coursework toward B.S., Information Technology (2008 – 2011)

Coursework in network security, systems administration, database management, and enterprise architecture.