Nicholas Hammonds
I'm an AI and Cybersecurity Leader with over 25 years of international experience spanning the United Kingdom, Singapore, and Austria. I've served as Chief Technical Officer, Senior AI Solution Architect, and Data Science Lead for organizations including BAE Systems Applied Intelligence, Raiffeisen Bank International, and Nevis Security, bringing a unique blend of technical depth and strategic vision to each role.
View My Experience Through Different Lenses
AI/ML Engineering Vision
I spearhead enterprise-grade AI strategy with focus on Large Language Models, Retrieval-Augmented Generation (RAG), and Agentic AI systems. My expertise spans the complete AI/ML lifecycleâfrom data preprocessing and model training to secure deployment and governanceâusing technologies including VertexAI, PyTorch, TensorFlow, Langchain, Google ADK, and Model Context Protocol (MCP).
Key Professional Achievements
- Nevis Security: Designed, implemented, and delivered the company's first RAG-powered Knowledge System, leveraging data science preprocessing, vector embeddings, and LLM prompt engineering to create an intelligent assistant handling highly sensitive data. As acting lead engineer on an AI security co-pilot, I'm building agentic systems that provide real-time configuration guidance for security integrators. The solution is cloud-agnostic, with primary architecture on GCP and VertexAI, alongside prototypes on AWS and Azure to manage cost, performance, and vendor independence.
- Raiffeisen Bank International: Led a cross-functional team to prototype a hybrid recommender system for ESG portfolio selection using AWS SageMaker, combining matrix factorization with content-based and collaborative filtering techniques. The system integrated predictive analytics to guide investment decisions.
- Content Garden Technologies (CTO): Implemented data science and ML technologies into the advertisement purchasing process using Sentiment Analysis, Linear Regression, and XGBoost, enabling sales staff to negotiate up to 20% more ad space. Built predictive models for advertisement performance optimization, combining Big Data Analytics with machine learning to drive revenue.
Core Philosophy & Technical Depth
My work demonstrates the intersection of AI/ML and cybersecurity through NLP techniques and anomaly detection in cyber threat analytics. I serve on the AI Governance board, ensuring compliance with the EU AI Act, and adopt best practices from the NIST AI RMF for risk management in high-stakes domains including finance, insurance, and healthcare.
Solution Architecture Expertise
I architect solutions that balance security, scalability, and functionality. My expertise encompasses cloud-native architecture across AWS, GCP, and Azure, designing resilient microservices infrastructures, and transforming legacy systems into modern, high-performance platforms.
Key Professional Achievements
- Nevis Security (Lead AI Engineer and Solution Architect): Serve as lead architect on security solution integrations for major finance and transport providers, ensuring enterprise-grade reliability and compliance.
- Raiffeisen Bank International: Re-architected monolithic systems into modern microservices using Docker and Kubernetes with AWS EKS. This transformation resulted in a 75% reduction in deployment time and a 30x improvement in response times. Additionally, I designed secure cloud network infrastructures that successfully withstood stringent penetration tests, leveraging AWS auto-scaling and ElastiCache for optimized performance and cost.
- Content Garden Technologies (CTO): Directed teams to successfully adopt microservices architecture with robust monitoring utilizing CloudWatch, Datadog, Kubernetes, and Docker.
Core Philosophy & Technical Depth
My architecture philosophy centers on three pillars: security-first design, functional excellence that delivers business value, and scalability that supports growth.
I combine AWS Solutions Architect certification with hands-on experience in data architecture, ETL pipelines, database optimization, and DevOps practices including CI/CD with GitLab.
Cyber Security & AI Governance Leadership
I blend offensive threat detection, defensive architecture, and comprehensive security governance. I bring hands-on expertise in cyber analytics, fraud detection, network security, and implementing defense-in-depth strategies aligned with the MITRE ATT&CK Framework and NIST AI RMF.
Key Professional Achievements
-
BAE Systems Applied Intelligence: Designed and delivered a multi-million-dollar enterprise cyber analytics platform utilizing Hadoop, YARN, and Big Data technologies to actively track potential cyber threats across the MITRE ATT&CK kill chain.
- Developed advanced detection analytics, including identifying long-beaconing malware via low-variance analysis of IP connections over extended timeframes.
- The system combined anomaly detection and NLP techniques to provide SecOps teams with actionable intelligence via custom Kibana dashboards.
- Singapore Nationwide Fraud Detection: Served as senior tech lead for the delivery and integration of a nationwide fraud detection platform, leveraging Spark, MapReduce, and distributed computing to detect and mitigate fraud at scale, requiring close collaboration with government agencies and senior decision-makers.
Core Philosophy & Technical Depth
-
Nevis Security (Lead Engineer & AI Governance): Currently leading the engineering of an Agentic AI suite that empowers security integrators with real-time configuration tools for robust cybersecurity systems.
- Established rigorous security protocols for the full AI/ML model lifecycleâfrom secure data ingestion and adversarial training simulations to secure deployment and post-production monitoring.
- As a senior member of the AI Governance board, I drive compliance with the EU AI Act and integrate best practices from the NIST AI RMF.
- I adopt a security-first mindset working with highly sensitive data across finance, insurance, and healthcare sectors.
Software Development Leadership
With over 25 years of hands-on software development experience, I've built mission-critical systems for tier-one financial institutions, telecommunications providers, and enterprise clients worldwide. My development expertise spans Java, Python, SQL, and modern frameworks, combined with deep knowledge of software engineering best practices, code quality, and team mentorship.
Key Professional Achievements
- Patsystems/Ion Trading: Led engineering teams delivering a post-trade risk platform in Java to major financial institutions including JP Morgan and Deutsche Bank. Wrote the technical proposal and prototype that won Nomura Bank as a new client, and implemented Java-based variants of the Black-Scholes algorithms to calculate theoretical prices and Greeks for option tradesâfeatures that helped reduce customer churn during contract renegotiations.
- Raiffeisen Bank International: Optimized poor-performing Python code into streamlined, well-documented classes and functions, leveraging NumPy and Pandas libraries to fine-tune complex ESG calculations. Simultaneously mentored the development team to adopt better coding practices and deployment via GIT-based CI/CD pipelines, significantly improving code quality and team productivity.
- Content Garden Technologies (CTO): Responsible for hiring and mentoring a multidisciplinary team of developers, data scientists, testers, and scrum masters. Established development standards, code review processes, and agile practices that resulted in faster delivery cycles and more maintainable codebases.
Core Philosophy & Technical Depth
My development approach emphasizes clean code, comprehensive testing, documentation, and knowledge transfer. I'm proficient in modern DevOps practices including Docker containerization, Kubernetes orchestration, GitLab CI/CD pipelines, and continuous integration/deployment workflows that enable teams to deliver high-quality software rapidly. My experience includes work at Siemens, THUS Plc./Cable and Wireless, Sungard, and Fujitsu Telecom, building telecommunications and enterprise software systems.
Roles and Projects
Security Solution Integration
Lead architect on the implementation and deployment of secure identity solutions for major finance, gaming and law enforcement providers.
Agentic AI Governance and Response
Advising on the responsible adoption of agentic AI suites including Claude-code and Google's AntiGravity. Analyzing real-world deployments of Agentic AI as both Cyber attack and Cyber defense mechanisms, translating findings into actionable security playbooks to protect sensitive data and brand reputation. Serving as a senior member of the AI Governance board, leading strategic initiatives to align enterprise AI adoption with the EU AI Act and NIST AI Risk Management Framework.
Agentic AI Security Suite
Designed and implemented a state of the art Agentic AI suite to advise and configure nevis security configuration based on human prompts. Agentic suite is now extended to aid fault finding and resolution, this has resulted in sharp decrease in time to find root causes of issues.
Secure Super Knowledge Agent
Designed, implemented and delivered an AI knowledge base using data science pre-processing skills, RAG and LLM prompt engineering. Built with security-first architecture to handle highly sensitive data across finance, insurance and healthcare sectors.
Enterprise Cyber Analytics Platform
Enterprise Fraud Detection Platform
ESG Recommender System
Architecture Overhaul - 30x Improvement
Cloud Infrastructure & Optimization
ML Predictive Performance Modeling
Microservice Architecture Transformation
GDPR Compliance & TCF Integration
Post Trade Risk Platform
Black-Scholes Algorithm Implementation
Technical Skills
AI and ML
Cyber Security Knowledge
Programming Languages & Tools
Cloud Platforms & Services
Big Data and Data Management
DevOps & Practices
Dissecting an AI Driven Cyber Attack
The true story of the OpenAI/HuggingFace incident - when an AI agent escaped its sandbox and launched a real-world cyber attack.
Insights
Clear explanations of key concepts and approaches
What is Solution Architecture?
Solution architecture is the art of designing a reliable and robust system capable of supporting your requirements for the foreseeable future.
As a system vendor, a good solution architecture document forms the basis of your relationship and contract with the customer, clearly articulating the different implementation phases, delivery and payment milestones. It is the key reference document that engineering teams use as they go through the detailed implementation steps of the system.
As the customer, a well written solution architecture document clearly frames and describes your business requirements and use cases as well as your path to a good ROI. It is a clear map to your board of executives as to why the system being implemented is profitable and viable and should reduce red tape when it comes to regulatory review.
System architecture takes into account existing legacy systems and how they should be replaced or integrated with. It determines any regulatory or geographical factors to inform whether the system should be on-premises, on-cloud or a hybrid of both. It outlines the required scalability and elasticity, allowing you to use such modern technologies as Kubernetes to expand and contract your capacity on demand, allowing you to meet demand in busy periods as well as saving costs and resources in times of less demand.
What is Cyber Security?
Cybersecurity is the practice of defending all digital assetsâsystems, networks, and dataâfrom digital attacks and unauthorized access. It deals with security threats across all vectors.
There are two main aspects to cyber security: "perimeter" and "post-perimeter" defense.
Perimeter defense concerns itself with keeping intruders outside of your internal network through the use of a firewall or other Intrusion Prevention and Detection Systems (IDPS). An IDPS will typically employ such methods as Rate Limiting (to stop denial of service attacks) and access control (denying known blacklisted IPs and allowing known IPs).
Post-perimeter defense concerns itself with what happens once an intruder has infiltrated an internal network. This will typically employ advanced cyber machine learning analytics to spot malware or suspicious unusual behavior and alert a Security Operations Centre (SOC) of a possible intrusion.
In today's modern cloud-based systems, a blended approach is required between perimeter and post-perimeter defense techniques. The tools and techniques to achieve this are available, but it is only through careful expert planning, implementation and regular reviews that you can achieve the high level of security needed.
Demystifying Artificial Intelligence, Machine Learning, LLMs and Agentic AI
Artificial intelligence (AI) is a field of computer science dedicated to creating systems that can learn, reason and solve complex problems in a way that is inspired by how a human might solve the same problem.
Machine Learning (ML) is a subset of AI that has been around for many years. ML models are used in many scenarios such as fraud and cyber attack detection and prevention. Common model implementations use regression techniques to learn patterns based on historic data such as what banking system activity could be indicative of fraud. These trained models are then fed real-time data in order that they can predict when an event such as fraud or a cyber attack can be detected.
Large Language Models (LLMs) are another form of AI that came to prominence in November 2022 with the arrival of OpenAI's ChatGPT 3.5. They are categorized by their ability to hold coherent conversations on a seemingly wide variety of subjects. There are several LLM vendors currently, most notably OpenAI (ChatGPT), Google (Gemini), and Anthropic (Claude).
LLMs give rise to many business applications such as chatbotsâa bot that uses LLM technology and company documentation to talk about a company's product, for example. The other main business application is the coupling of LLMs with other tools to achieve Agentic AI. Agentic AI goes one step beyond the functionality of an LLM; it effectively extends the LLM's functionality so that it can interact with other systems and tools on your behalf to achieve a pre-defined goal. Although AI agents give rise to many business applications and savings, they come with risks if the proper security and guardrails are not put in place.
Outside of Work
I am a husband and a father of two lovely children. I am a guitar player and songwriter and member of the local music community. I believe an active lifestyle is essential and love running and training frequently with a local boot camp.