Securing AI in environments where compliance isn't optional
I’m Rudy Carreon : CISSP, U.S. Army veteran, and cybersecurity professional with 20+ years securing FDA-regulated hospital systems, now specializing in AI security and governance.
“Compliance isn't paperwork; it's how you earn the right to run AI in a hospital.”
Rudy Carreon, CISSP
0+
Years in Cybersecurity & Infrastructure
Securing mission-critical, FDA-regulated hospital systems since 2005.
Certifications & Credentials
CISSP, Security+, AWS CCP, with CAISP and CCSP exams in 2026, and an M.S. in Cybersecurity Management.
Certifications earned or in progress across security, cloud, and AI, including CISSP, CCSP, and CAISP.
0+
Bringing 20 years of regulated-environment security to the AI era.
About Me
Twenty years on the front line of regulated-system security
At GE HealthCare I served as a Cybersecurity SME on the CSO Quick-Response Team: leading incident response for hospital system outages, performing vulnerability assessments and root cause analysis, and keeping FDA-regulated imaging systems compliant with HIPAA across on-premises and AWS environments.
Now I’m applying that operational depth to the newest attack surface: AI. Certified AI Security Professional (Practical DevSecOps), CISSP, and M.S. in Cybersecurity Management.
Focus Areas
AI security grounded in real-world compliance
Where twenty years of regulated-industry security meets the newest attack surface.
AI & LLM Security
OWASP Top 10 for LLMs, prompt injection, adversarial ML, and model supply-chain risk. Certified AI Security Professional training.
AI Governance & Risk
NIST AI Risk Management Framework and MITRE ATLAS, applied with the discipline of someone who has actually been through the audits.
Healthcare & Regulated Industries
HIPAA, SOX, and FDA-regulated environments: two decades securing hospital imaging and clinical systems where uptime is patient safety.
Cloud & Infrastructure Security
AWS and on-premises security: vulnerability management, incident response, monitoring, patch management, and disaster recovery.
Why Me
Operational depth most AI security candidates don't have
I know what HIPAA, SOX, and FDA oversight look like in production: at 2 a.m., with a hospital on the phone. As organizations deploy AI into those same regulated environments, they need people who understand both the frameworks and the operational reality.
U.S. Army veteran: 3rd Special Forces Group (Airborne), former Information Systems Security Officer.