Rainier (Ram) Milanes

Cybersecurity, risk, and privacy work grounded in technical practice.

Substantial governance and privacy experience, an earned Northwestern MSIS (Security Specialization), and hands-on technical work through PrivAI Guard, a non-production Shadow AI governance capstone.

  • Cybersecurity
  • GRC
  • IT Risk
  • Data Privacy
  • AI Governance
Professional portrait of Rainier Milanes.

Featured work · 2026

PrivAI Guard

Employee use of public AI tools often outpaces the privacy and governance controls around them.

A non-production Shadow AI governance MVP I designed and developed that turns risky employee AI use into structured privacy-risk triage, human review, and auditable remediation.

  • Shows that governance requirements can be translated into a working technical system.
  • Structured risk review and remediation with a human decision path.
  • Not automated legal or regulatory decisioning.
  • Next.js
  • React
  • TypeScript
  • Supabase/PostgreSQL
  • Vercel
  • GitHub

Northwestern University MSIS capstone MVP. Non-production. Synthetic demonstration data only. Human governance review — not automated legal or regulatory decisioning.

Experience

Selected recent work

Selected examples of transferable risk, controls, and privacy work.

RAM Privacy & Security

October 2024Present

Principal Consultant

  • Conduct risk assessments and translate findings into prioritized remediation actions, implementation roadmaps, and measurable controls.
  • Develop policies, standards, procedures, incident-readiness materials, and executive reports; support third-party risk, audit readiness, regulatory compliance, and stakeholder coordination.

National Privacy Commission

October 2024January 2026

Innovation and Transformation Consultant

  • Supported risk assessments and the development of controls addressing identified cybersecurity and information-security risks.
  • Directed pre- and post-production security implementation for the Compliance and Security Monitoring Command Center, supporting centralized monitoring and remediation workflows.

National Privacy Commission

March 2021September 2024

Chief, Compliance and Monitoring Division

  • Led compliance monitoring, breach-notification processing, registration, compliance support, and regulatory reporting operations.
  • Led development and implementation of the Data Breach Notification Management System and the National Privacy Commission Registration System.

Credentials

Education and certifications

Formal credentials that support the public focus areas.

Education

Master of Science in Information Systems, Security Specialization

Northwestern University · 2026

Certification

Certified Information Privacy Manager (CIPM)

IAPP

Certification

Certified in Cybersecurity (CC)

ISC2

Review the work or start a conversation

Explore experience, projects, and credentials, or reach me by email or LinkedIn.