Former Amazon Security Leader—Now Helping Growing Companies Build Secure Systems

Hi, I'm Elijah Winter.

I spent 7+ years building security systems at Amazon and the CIA—the kinds of systems that protect hundreds of millions of users and some of the nation's most sensitive information.

At Amazon, I co-founded the AI Security Organization and created security frameworks used by 500+ development teams to build safe AI products. I partnered with 50+ engineering teams implementing access control systems, investigated 200+ security incidents, and built automation that reduced manual security work by 70%. Before that, I worked at the CIA on digital forensics, threat detection, and protecting classified networks.

Why I Freelance

Here's what I learned working at enterprise scale: most startups and mid-market companies face the same security challenges Amazon solved years ago—but they can't hire a 20-person security team to solve them.

That's the gap I fill.

I take the frameworks, tools, and processes that work at Amazon scale and adapt them for fast-moving teams. You get enterprise-quality security engineering without the enterprise overhead, complexity, or six-month timelines.

I also learned that the best security work happens when you deeply understand a company's context—their business model, their technical debt, their competitive pressure, their actual risks. As a consultant, I can focus entirely on your problems without the distractions of corporate politics or unrelated priorities.

What Makes Me Different

Real Enterprise Experience at Scale

I didn't learn security from tutorials or certifications—I built it at Amazon and the CIA. I've secured systems protecting millions of users, investigated actual breaches, and seen every edge case. When you hire consultants who've only worked with 10-20 companies, you get theory. When you hire me, you get battle-tested experience from organizations that operate at a scale most companies will never reach.

I Understand the Business Context

At Amazon, I partnered with VPs and CISOs, consulted with 40+ healthcare customers on architecture decisions, and advised leadership on enabling innovation safely. I learned that security isn't about saying "no"—it's about understanding what you're trying to accomplish and finding the secure path to get there. I care about your business outcomes, not just checking security boxes.

Specialized AI/ML Security Expertise

Most security consultants learned their craft before AI became critical infrastructure. I co-founded Amazon's AI Security Organization and spent years securing machine learning systems, from training pipelines to production models. I understand prompt injection, model inversion, data poisoning, and every other attack vector that didn't exist five years ago. If you're building AI-powered products, this expertise is rare and valuable.

Built for Scale from Day One

The frameworks I use aren't just for today—they're designed to scale with you. I've seen how companies grow from 10 to 10,000 employees, and I know which security decisions will help that transition and which will become technical debt. You get architecture that works now and grows with you.

How I Work

1

Discovery First

I spend time understanding your business, not just your tech stack. What are you optimizing for? Speed to market? Investor confidence? Compliance? Customer trust? The right security solution depends on your actual goals and constraints.

2

Practical, Not Perfect

Perfect security doesn't exist, and even if it did, it would mean you'd never ship. I focus on the security controls you need now, with a clear roadmap for what comes later as you scale. My recommendations are always prioritized: quick wins first, then strategic improvements.

3

Knowledge Transfer Matters

When I'm done, you should understand WHY we implemented things a certain way, not just WHAT we built. I document everything thoroughly and train your team so they can maintain and extend the work. You're not dependent on me forever.

4

Long-Term Partnership

Security isn't one-and-done. Systems change, threats evolve, companies grow. Many of my clients keep me on retainer because having someone who already knows your systems and can respond quickly is valuable. But even if we don't work together long-term, I'm available for questions.

Background & Experience

Senior Security Engineer | Amazon | 2021 - Present

  • Co-founded Amazon's AI Security Organization, defining strategy and organizational structure for team of 15+ security engineers
  • Created AI security standards adopted by 500+ development teams across Amazon
  • Partnered with 50+ engineering teams to implement attribute-based and fine-grained access control
  • Architected security posture management tool for 100,000+ applications
  • Consulted with 40+ healthcare customers on security architecture
  • Led security reviews for high-impact product launches with VPs and CISOs
  • Investigated 200+ insider threat incidents with 95% resolution rate
  • Built security analytics data lake processing 10TB+ daily events
  • Reduced manual security work by 70% through automation

Central Intelligence Agency | 2018 - 2021

Cyber Security Advisor (2021)

  • • Managed cyber security team of 8 analysts
  • • Conducted security assessments across 15+ enterprise systems
  • • Advised executive leadership on critical vulnerabilities
  • • Developed security awareness training for 300+ users

Cyber Data Specialist (2020-2021)

  • • Researched 50+ Advanced Persistent Threats (APTs)
  • • Automated data analytics workflows using Python and Spark
  • • Led data science projects applying machine learning to security datasets
  • • Served as Systems Administrator for classified networks

Digital Forensics Engineer Intern (2018-2020)

  • • Researched emerging file formats, mobile devices, and storage technologies
  • • Developed Python scripts for information recovery and threat identification
  • • Analyzed digital datasets to identify malicious behaviors

Education

Bachelor of Science in Cyber Security Engineering
George Mason University Honors College | 2020

Technical Expertise

Cloud & Infrastructure: AWS (Expert), Azure, Docker, Kubernetes, Terraform
Programming: Python (Expert), Java, JavaScript, C, Bash, SQL
Security Tools: Splunk, Elasticsearch, Kibana, EnCase, FTK, Wireshark
Specializations: AI/ML Security, IAM/Access Control, Incident Response, Digital Forensics, Application Security, Cloud Security

Beyond The Code

When I'm not debugging authorization policies or investigating security incidents, I'm usually exploring new security research, contributing to open-source projects, or staying current on emerging threats (particularly in the AI security space).

I believe good work comes from a balanced life, and I apply the same systematic thinking to my personal interests as I do to security engineering. I'm based in Arlington, Virginia, which keeps me close to the government and tech communities that shaped my career.

Let's Talk About Your Security Challenges

Whether you're preparing for an audit, scaling your infrastructure, building AI features, or just know your security is behind where it should be—let's have an honest conversation.

I'll tell you if I'm the right fit. If not, I'll try to point you in the right direction.