Raleigh / Durham, NC

I am Michael Scholz: Information Systems Security Officer (ISSO), AI Security Consultant, and Founder & CEO.

I secure networks and harden identities by trade, and study where traditional cybersecurity stops working once the systems it protects start making their own decisions.

M.S. Cybersecurity, ODU ’26  ·  CompTIA Security+  ·  AWS Cloud Practitioner

About

Where risk assessment meets AI governance

Michael Scholz, in a graduation gown, standing in front of the Old Dominion University School of Cybersecurity sign.

I'm a cybersecurity professional with hands-on experience leading risk and vulnerability assessments, building cybersecurity architecture aligned with NIST CSF, and evaluating enterprise programs to find gaps before they become incidents. That work has meant investigating security incidents end to end: scoping indicators of compromise, running root-cause analysis, and shipping remediation like enforced MFA, conditional access, and least-privilege baselines, then briefing the outcome to both engineers and executives.

I hold a Master's in Cybersecurity from Old Dominion University, where my research followed a simple observation: most cybersecurity practice was built for deterministic software, and AI systems don't behave that way. My thesis, the AI Workflow Lifecycle Framework (AWLF), treats AI adoption as an organizational capability to be governed, not a one-off software project to be shipped and forgotten.

I lead best when the problem is unowned: I've directed a 500-member university organization, founded and serve as CEO of a cybersecurity startup where I build the product myself end to end, and stepped into an advisory role on a commercial AI SOC platform simply because the questions needed answering.

"As AI evolves from isolated tools to structured organizational capabilities, enterprises require governance models that extend beyond risk management and software development frameworks."Scholz, Secure-by-Design AI Workflows: The AI Workflow Lifecycle Framework, Old Dominion University, 2026

Experience

Professional track record

Jan 2026 – Sep 2026

Cybersecurity Analyst

Valor Cybersecurity · Norfolk, VA
  • Led risk and vulnerability assessments of client endpoint, identity, and cloud environments; built mitigation strategies aligned to NIST CSF and HIPAA and tracked remediation to closure.
  • Investigated security incidents by analyzing endpoint, identity, and cloud telemetry to determine indicators of compromise, scope, and root cause; executed emergency response and remediation, including MFA enforcement, conditional access, and least-privilege baselines.
  • Provided technical oversight using Microsoft Entra ID, Azure Log Analytics, and Microsoft 365 security tools to strengthen endpoint protection, identity security, and threat visibility across client tenants.
  • Configured Zero Trust cloud identity, access controls, and security baselines; architected and led security for the CyberShield Platform (Electron / Next.js / Supabase), hardening RLS, JWT auth, and API endpoints against injection and broken auth.
  • Integrated AI-driven detection tooling into threat hunting and incident response workflows, tuning false-positive rates and measuring detection efficacy; briefed executive stakeholders on emerging threats.
Jan 2025 – May 2025

Cyber Risk Management Intern

Commonwealth Cyber Initiative · Virginia Beach, VA
  • Led comprehensive risk and vulnerability assessments for small and mid-sized organizations, aligning findings to NIST CSF to prioritize remediation.
  • Developed long-range system security strategies (policies, standards, and control documentation) to support compliance and audit readiness.
  • Evaluated cybersecurity programs by assessing configurations and identifying gaps in access control, system hardening, and incident-response preparedness; advised clients on Azure and Microsoft 365 security.
  • Acted as analyst team lead, translating technical findings into plain language for non-technical stakeholders and leadership.

2025

President, Inter-Fraternity Council, ODU

Led a ~500-member organization across multiple chapters; owned day-to-day operations, risk and compliance, and communication with university leadership.

2024

VP of Recruitment, Sigma Phi Epsilon

Directed chapter recruitment and onboarding strategy, increasing new-member recruitment by 80%.

2022

Eagle Scout, Boy Scouts of America

Earned Scouting's highest rank, capping a long-run project in planning and leading a service project to completion.

Projects

Things I've built, hardened, and shipped

From a commercial AI SOC platform to a LAN-based security teaching tool, the common thread is making systems defensible by design.

Research

Academic work on AI security

Graduate coursework and thesis research, written as class deliverables rather than peer-reviewed publications, but the arguments are load-bearing for how I think about AI risk.

Secure-by-Design AI Workflows: The AI Workflow Lifecycle Framework (AWLF) for Managing AI as an Organizational Capability

Master's Thesis · CYSE 698 · Old Dominion University · Advisor: Dr. Sultuk Karahan · 2026
Master's thesis

Existing AI guidance largely treats risk management and cybersecurity as the whole problem, leaving the rest of the organizational lifecycle unaddressed. The AWLF proposes a conceptual framework for managing AI workflows as ongoing organizational capabilities rather than one-time software projects: establishing a working definition of "AI workflow," the lifecycle framework itself, and a secure-by-design operational philosophy for enterprise adoption. It positions business need as the trigger for adoption and emphasizes executive sponsorship, governance, and continuous lifecycle management, designed to complement existing frameworks like NIST CSF 2.0 and the AI Risk Management Framework.

Read the full thesis (PDF) →

Securing Artificial Intelligence Systems: Adapting Traditional Cybersecurity to a New Domain

Graduate coursework paper · Old Dominion University · 2026
Coursework paper

Argues that traditional cybersecurity approaches are insufficient for protecting AI systems, and that closing the gap requires new, purpose-built security strategies. Examines AI-specific threat vectors (data poisoning, adversarial attacks, and model exploitation) alongside the "black box" opacity that makes manipulated AI outputs hard to detect, and evaluates where frameworks like NIST's AI Risk Management Framework 1.0 fall short on technical, AI-specific threats.

Read the full paper (PDF) →

Skills

Technical competencies

Detect & Respond

Threat Detection & Incident Response

  • Azure Log Analytics
  • SIEM fundamentals
  • Log analysis
  • AI-driven detection
  • Emergency response
  • Forensic analysis

Assess & Exploit

Vulnerability Assessment

  • Nmap
  • Wireshark
  • Kali Linux

Design & Govern

Security Architecture

  • Zero Trust
  • CIA Triad
  • IAM
  • Network segmentation
  • IDS / IPS

Deploy

Cloud & Platforms

  • AWS
  • Microsoft Azure
  • Microsoft Entra ID
  • Microsoft 365
  • Linux (Ubuntu, Kali)
  • macOS
  • Windows

Automate

Scripting & Tooling

  • Python
  • Bash
  • PowerShell

Comply

Frameworks & Compliance

  • NIST CSF 2.0
  • NIST AI RMF
  • HIPAA
  • Post-incident documentation
  • Gap analysis
S+
CompTIA Security+ (SY0-701)

Industry-standard certification covering threat management, cryptography, identity and access management, risk management, and incident response.

AWS
AWS Certified Cloud Practitioner

Foundational certification covering cloud architecture, security, compliance, and the shared responsibility model.

Connect

Find the rest of the work

The professional record lives on LinkedIn; the more casual breakdown of cybersecurity concepts lives on TikTok.