Enterprise Security & AI Architecture · Montréal, QC

Raoul Elysée

Enterprise AI & Cyber Risk Architect  ·  Regulated Industries

Bridging AI innovation, cybersecurity architecture, and regulatory governance for complex, regulated enterprises — aligning technical execution with risk reduction, compliance requirements, and strategic business objectives.

About

Who I Am

I am a cybersecurity and AI architect with over 20 years of IT experience. Nearly 19 years were spent within the Great-West Lifeco group — across London Life and Canada Life — where I progressed through claims and insurance operations, then over a decade as IT Security Coordinator, and finally as a regulatory compliance consultant. This breadth of roles within regulated financial institutions — across multiple functions and lines of defense — gives me a genuine understanding of the business and fiduciary stakes behind every system I protect. My career began with a college diploma in business administration at Collège Marie-Victorin and a university certificate in software development at UQAM — years also spent building web and mobile products with startup teams.

My expertise sits at the intersection of cybersecurity architecture, regulatory compliance, governance and risk management, AI systems, and operational security leadership — combining deep technical execution with regulatory awareness and board-level governance exposure. I have collaborated with internal audit teams, enterprise architects, domain architects, and executive committees — advancing security maturity, leading GRC programs, and translating regulatory requirements into concrete architecture decisions. This executive mindset extends to my 10+ year tenure as president of a co-ownership corporation — leading recruitment, RFP management, stakeholder assemblies, member communications, and board-level governance decisions.

More recently I have developed deep expertise in agentic AI engineering — building multi-agent systems and deploying LLM-powered solutions in production across AWS, Azure, GCP, Vercel, and private VPS environments, while applying security principles (guardrails, memory management, least privilege) to every AI architecture I design. I also maintain personal AI infrastructures connected to a broad toolset to amplify creativity, accelerate ideation, and explore how AI can genuinely augment human and production capabilities.

I am currently completing a Bachelor's degree by accumulation in Cybersecurity at Polytechnique Montréal (evenings). Outside of work and studies, I spend time with my family, follow finance, economics, and current events closely, train at the gym, and enjoy cycling in the summer and hiking through the forest.

19
Years at Great-West Lifeco
10+
Years in Cybersecurity & Compliance
40+
LLMs Tested (open source + cloud)
2027
BSc Cybersecurity (in progress)
Education

Academic Background

2026 – 2027

Certificate — Cybersecurity Incident Management & Response

Polytechnique Montréal

In Progress
2024 – 2025

Certificate — Cybersecurity Analysis & Operations

Polytechnique Montréal

Completed
2022 – 2023

Certificate — Cybersecurity Architecture & Management

Polytechnique Montréal

Completed
2012 – 2015

Certificate — Software Development (Computer Science)

UQAM

Completed
1998 – 2001

College Diploma (DEC) — Business Administration

Collège Marie-Victorin

Completed
Strategic Edge

Why This Profile Is Different

Regulated Industry Authority

Nearly 19 years embedded in regulated financial institutions — across pension, insurance and compliance — provide a ground-level understanding of regulatory mechanics, fiduciary risk, and audit processes that most architects lack.

  • 6 years pension & insurance compliance consulting (1st & 2nd line of defense)
  • IT Security Coordination within a regulated enterprise environment
  • Claims and risk operations experience
  • Deep familiarity with PIPEDA, Loi 25, Insurance Act, Loi RCR, CCQ, PCI DSS

Cross-Functional Executive Interface

Proven ability to operate across all organizational layers — from development and architecture teams to audit committees and executive boards — translating risk into business language and business intent into architecture.

  • Collaboration with internal audit, IT compliance, and enterprise architects
  • Stakeholder awareness programs and business unit engagement
  • Risk governance alignment across technical, compliance, and executive functions
  • 10+ years board-level governance as co-ownership president

Applied AI & Security R&D

Every recommendation is grounded in hands-on experimentation. A private AI and security lab running production-grade deployments, continuous tooling validation, and applied vulnerability research.

  • Private VPS with self-hosted AI infrastructure
  • Graph RAG with Neo4j + Qdrant in production
  • Security tooling validation and exploit research
  • 40+ LLMs tested — open source and cloud
Expertise

Core Competencies

Security Architecture & IAM

Enterprise IAM/CIAM strategy, Zero Trust implementation, privileged access controls, and threat modeling (STRIDE/MITRE ATT&CK). Secure design from architecture phase through production.

Zero TrustIAM / CIAMSTRIDEThreat ModelingMITRE ATT&CK

Governance, Risk & Compliance

6 years as regulatory compliance consultant in pension and insurance sectors at Canada Life and London Life, across both 1st and 2nd lines of defense. Delivered strategic risk advisory on a broad regulatory landscape — PIPEDA, Loi 25, Insurance Act, Loi RCR, CCQ, PCI DSS, NIST, and ISO 27001 — and enterprise risk exposure. Led stakeholder awareness initiatives and collaborated with business units to translate complex compliance requirements into operational practices — driving maturity through continuous improvement programs, KPIs, and KCIs.

PIPEDA / Loi 25 / PCI DSSInsurance Act / Loi RCR / CCQNIST / ISO 27001Stakeholder AwarenessGRC

AI & Agentic Engineering

Production multi-agent systems using OpenAI Agent SDK, CrewAI, LangGraph, and AutoGen. Hands-on experience with 40+ LLMs — open source (Ollama) and cloud. Vector databases, Graph RAG (Neo4j + Qdrant), and MCP integrations.

Graph RAGVector DBMulti-Agent40+ LLMsMCP

DevSecOps & Application Security

Secure CI/CD pipelines integrating SCA, SAST, and DAST (Azure DevOps). OWASP Top 10 remediation, vulnerability management using Nessus, Burp Suite, and DefectDojo, and SSDLC implementation. Security automation with Python and PowerShell. 10+ years of development across web (React, Next.js), mobile (Flutter), and security tooling.

OWASPDevSecOpsSSDLCNessus / Burp SuiteSplunk / Sentinel

Cloud Architecture & MLOps

End-to-end AI deployment on AWS, Azure, GCP, Vercel, and private VPS environments — including self-hosted open-source vector databases and RAG systems for data sovereignty use cases. Infrastructure as Code with Terraform and GitHub Actions CI/CD.

AWS / Azure / GCPPrivate VPSData SovereigntyTerraformGitHub Actions
Projects

Selected Work

AI Digital Twin

Live

Personal AI representative on a fully serverless AWS architecture: CloudFront, API Gateway, S3, Lambda, and Amazon Bedrock for LLM inference. Provisioned with Terraform and automated through GitHub Actions CI/CD.

AWS BedrockLambdaTerraformNext.jsGitHub Actions

Principal Cybersecurity Advisor — Regulated Healthcare

Live

Current mandate as principal cybersecurity advisor in a regulated healthcare organization. Leading vulnerability management programs and coordinating penetration testing. Conducting threat modeling and risk assessments. Implementing DevSecOps pipelines with SCA, SAST, and DAST tooling. Driving security automation through Power Apps, Python, and PowerShell. Authoring security guides and defining security requirements for RFPs.

Vulnerability ManagementThreat ModelingDevSecOpsPowerShell / PythonPower Apps

Legal Brain — Graph RAG

In Development

AI legal assistant trained on Quebec and Canadian law using Graph RAG: a Neo4j knowledge graph combined with a Qdrant vector database for semantic retrieval. Delivers precise article-level citations. Targeting LegalTech commercialization.

Graph RAGNeo4jQdrantLangGraphCanadian Law

Business & Enterprise Architect – Security Governance

Enterprise

Business and enterprise architecture roles within the governance function of a major financial institution. Strategic advisory to executive committees on security investment prioritization aligned with enterprise risk reduction. Validated project relevance and funding continuity through structured value and risk posture impact analyses. Directed the project selection process to ensure alignment between technological capabilities and the institution's business ambitions.

Business ArchitectureEnterprise ArchitectureStrategic AdvisoryExecutive CommitteesPortfolio Governance

Security & IAM Governance — Expert Mandate

Enterprise

Expert governance mandate within the IAM function of a major financial institution. Defined IAM policies, standards, and governance frameworks aligned with enterprise risk objectives. Assessed organizational maturity and directed external security consultants. Previously held a principal IT analyst and security SME role in an enterprise architecture context — delivering structured security analyses and pragmatic, framework-aligned recommendations (NIST, CIS, TOGAF) to architecture teams and executive decision-makers.

IAM GovernanceMaturity AssessmentPolicy & StandardsNIST / CIS / TOGAFExternal Consultant Direction

Voice AI & Edge Lab

Research

Production voice cloning app deployed on Hugging Face. Separately: on-device inference experiments with a Raspberry Pi 5 and AI Hat+2 for real-time computer vision and a Pi Dog robot — stress-testing open source models at the edge.

Voice CloningRaspberry Pi 5AI Hat+2Edge AIHugging Face

Agentic Systems Portfolio

Research

Engineering across all major agentic frameworks: OpenAI Agent SDK, CrewAI, LangGraph, AutoGen, and MCP (40+ tool integrations). Includes deep research agents, SDR sales agents, simulated dev teams via Docker, and a financial analysis floor.

OpenAI SDKCrewAILangGraphAutoGenMCP
Business Impact

Business & Enterprise Impact

My work consistently targets measurable, risk-aligned outcomes — not theoretical compliance or checkbox security.

  • Strengthened organizational security posture through architecture-led programs and structured risk reduction strategies
  • Delivered compliance alignment across PIPEDA, Loi 25, Insurance Act, PCI DSS, and NIST — translating regulatory complexity into operational practices
  • Bridged the gap between security teams and business operations — enabling informed, risk-aware decision-making at every organizational layer
  • Enabled secure AI innovation through applied AI security principles: guardrails, least privilege, memory controls, and responsible operationalization
  • Built cross-functional governance momentum — aligning technical, compliance, and executive functions around shared risk objectives

Rather than viewing security as a constraint, I position it as a structured enabler of sustainable growth and innovation.

Security is not a control layer. It is a risk-aligned business enabler.

AI is not innovation by default. It must be governed, secured, and operationalized responsibly.

Architecture must integrate business objectives, regulatory exposure, and governance accountability.

AI-Powered

Talk to My Digital Twin

This AI representative can discuss my experience, projects, architecture decisions, and expertise — in English or French — as if you were speaking with me directly.

Digital Twin Assistant

Explore my security frameworks and AI architectures

Welcome!

I'm Raoul's digital twin. Ask me about my professional experience, skills, or projects.

ExperienceSkillsProjects

Next.js · AWS Bedrock · Graph RAG · Qdrant · Sovereign Architecture

Contact

Let's Connect

Interested in discussing security architecture, AI-driven security transformation, or leadership opportunities? I would love to hear from you.