Skip to content
Connection is secure Connection is secure ethanlinton.com is served over HTTPS with a valid certificate, so everything you type here is encrypted in transit. Network activity Network activity Every window here fetches its content from the WordPress REST API. Each bar is one response, and its height is how much data came back. Nothing fetched yet

Desktop

Ethan

About Me

SME in network security and high-grade cryptography

  • CISSP
  • CCNP
  • M.CyberSec (Hons 1st)

Cybersecurity engineer, infrastructure nerd, and chronically online.

I’ve spent my career working across high-assurance government environments, enterprise infrastructure, networking, and security operations. These days, I’m focused on security engineering, threat investigation, and figuring out how things break – preferably before someone else does.

When I’m not staring at terminals, or packet captures, I’m probably still staring at a screen for an entirely different reason.

Experienced in

  • Network Engineering Routing, segmentation, and network security
  • Cyber Security Threat modelling, investigation, and incident response.
  • Software Development Tooling and automation in Python, Go, and Java
  • Cryptography Protocol design and review - IPsec, TLS, PKI, and what comes after RSA.

Experience

  1. CURRENT Nov 2025 – Present

    Security Engineer II (TSE2)

    Arctic Wolf - Full-time · Sydney, Australia

    • Awards & Recognition
    • Q4 FY26 TSE International Award - awarded within first six months
    • Pack Impact - Security Triage & Investigation
    • Pack Impact - mEDR Toolkit
  2. Jan 2025 – Nov 2025

    Network & Systems Engineer

    International College of Management - Full-time · Sydney, Australia

    • Managed and engineered enterprise hybrid infrastructure across multiple sites, supporting an environment of 10,000+ users across Cisco networking and wireless, Fortinet/Cisco firewalls, Windows and Linux servers, Azure and Entra ID.
    • Led secure remote-access modernisation initiatives, improving connectivity, authentication and access management across the organisation. Designed and supported hybrid connectivity between on-premise infrastructure and Azure, while managing Windows and Linux server environments and enterprise networking infrastructure.
    • Investigated security incidents using endpoint, firewall, SIEM and cloud telemetry, and developed AI-assisted security reporting workflows to analyse activity, identify anomalies, summarise investigations and produce actionable security insights.
    • Automated infrastructure backups, configuration validation and routine administration to reduce manual operational effort and improve consistency across the environment.
    • Provided technical guidance and mentoring across networking, systems administration, automation and security engineering, while acting as an escalation point for complex infrastructure and security issues.
  3. Sep 2023 – Dec 2024

    Senior Systems Engineer

    National Cyber Security Centre - Full-time · Wellington, New Zealand

    • Cryptography SME and Senior Systems Engineer specialising in high-assurance cryptographic systems, secure network architecture and cyber security within New Zealand Government environments.
    • Served as a senior escalation point for complex technical issues involving the integration of cryptographic systems into secure network and security architectures. Developed cryptographic algorithms, led critical system modernisation projects, and conducted cyber security risk assessments, security testing and penetration testing. Also developed tooling and automation to improve engineering and operational workflows.
    • Responsible for the deployment, integration and lifecycle management of cryptographic hardware and supporting infrastructure, including cryptographic generation and distribution processes. Worked across complex LAN, WAN and international network environments.
    • Owned the technical validation process for new cryptographic hardware software releases, leading acceptance testing and providing formal approval for operational use before deployment was permitted across other organisations.
    • Worked closely with government stakeholders, customers and technology vendors on system modernisation and network deployment projects. Communicated complex technical and security concepts to senior stakeholders and presented to security leaders internationally.
  4. Aug 2023 – Sep 2023

    Team Lead Engineering

    National Cyber Security Centre - Acting · Wellington, New Zealand

    • Acted as Team Lead Engineering for periods of up to a month at a time, leading a specialist engineering team responsible for critical national infrastructure and high-assurance technical environments.
    • The team operated across cryptography, network engineering, systems administration and national wide area networks. Provided technical leadership, mentoring and escalation support across multidisciplinary engineering work while maintaining delivery and operational continuity.
  5. Mar 2022 – Sep 2023

    System Engineer (Level 2)

    National Cyber Security Centre - Full-time · Wellington, New Zealand

  6. Jan 2021 – Mar 2022

    Systems Engineer

    National Cyber Security Centre - Full-time · Wellington, New Zealand

  7. Oct 2020 – Dec 2020

    Network Engineer

    Toi Ohomai Institute of Technology - Contract · New Zealand

  8. Nov 2016 – Sep 2020

    IT

    Spark New Zealand - Contract · New Zealand

Certifications

  • AAISM – Advanced in AI Security Management

    ISACA

    Earned
    Sep 2026
    Expires
    —
    ID
    268502

    Verify credential

  • Master of Cyber Security

    University of Waikato

    Earned
    —
    Expires
    —
  • Understanding of Cisco Network Devices

    Cisco

    Earned
    Feb 2020
    Expires
    Feb 2023
    ID
    P4F8WVBFKCEQQGKF

    Verify credential

  • Cisco Certified Specialist – Enterprise Core (CCNP ENCOR)

    Cisco

    Earned
    Jul 2021
    Expires
    Jul 2024
    ID
    YN2J5Q5P33VQ1P9Y

    Verify credential

  • Implementing and Administering Cisco Solutions (CCNA)

    Cisco

    Earned
    Feb 2020
    Expires
    Jul 2024
    ID
    BYP5MQWDWDREQ2WN

    Verify credential

  • CCNP – Cisco Certified Networking Professional

    Cisco

    Earned
    Aug 2021
    Expires
    Aug 2024
    ID
    W6CZLX8FMLF41XG8

    Verify credential

  • Cisco Certified Specialist – Enterprise Advanced Infrastructure Implementation

    Cisco

    Earned
    Aug 2021
    Expires
    Aug 2024
    ID
    BBB6LG8P3CV4QZ9M

    Verify credential

  • CISSP – Certified Information Systems Security Professional

    ISC2

    Earned
    May 2025
    Expires
    —
    ID
    946550

    Verify credential

  • Microsoft Certified: Azure Administrator Associate (AZ-104)

    Microsoft

    Earned
    Aug 2025
    Expires
    Aug 2026
    ID
    C17AD2415DE6C80

Awards

  • Quarterly International TSE

    Arctic Wolf · May 2026

    Recognised with Arctic Wolf’s Quarterly International TSE Award for outstanding performance and impact across the international Triage Security Engineering organisation. Received within my first six months at the company, the award reflected strong contributions to investigations, technical improvement, and the wider team.

  • Impact Recognition – mEDR Toolkit

    Arctic Wolf · Sep 2026

    Recognised for developing tooling that improved the EDR platform.

  • Impact Recognition – Security efficiency

    Arctic Wolf · Mar 2026

    Recognised for exceptional impact in operational efficiency, and response quality.

Portfolio

  • CRYPTOGRAPHY

    Crypting: The Art of Detection Evasion

  • CRYPTOGRAPHY

    Implementation of the DJ Quantum Algorithm

  • AUTOMATION

    Google Cloud Network Automation

  • NETWORK

    RADIUS PPPoE & Q-in-Q

  • NETWORK

    Segment Routing

  • SECURITY

    AWS Ethanlinton.com

Blog

September 28, 2026 · 7 min read

Passing the ISACA AAISM: My Study Journey and Exam Experience

Artificial intelligence is quickly becoming part of everyday business and cybersecurity operations. While I already work within cybersecurity and have spent a lot of time experimenting with AI personally, I wanted to develop a better understanding of AI from a security, governance and enterprise risk perspective.

That led me to ISACA’s Advanced in AI Security Management (AAISM) certification.

AAISM Certification Overview

The ISACA Advanced in AI Security Management (AAISM) is an advanced certification designed for experienced security professionals responsible for managing the security and risk implications of artificial intelligence within organisations.

Unlike many certifications, AAISM has a prerequisite: candidates must already hold an active CISSP or CISM certification before they can take the exam. The exam contains 90 multiple-choice questions and candidates have 150 minutes to complete it.

To maintain the certification, holders must keep their qualifying CISSP or CISM active, comply with ISACA’s Code of Professional Ethics, and complete 10 AAISM-related CPE hours each year and 30 over a three-year period.

This prerequisite structure positions AAISM as a specialist extension to an existing security-management background rather than an entry-level AI or cybersecurity certification.

Preparing for the exam

My primary study resource was the official ISACA AAISM Review Manual.

I worked through the material systematically, focusing on understanding how ISACA approaches AI governance, risk management, security controls and the wider AI lifecycle rather than simply memorising terminology.

Given my existing cybersecurity background, many of the underlying principles were already familiar. The main challenge was understanding how those established security concepts are extended to AI – particularly around model risk, data governance, responsible AI, third-party dependencies and continuous monitoring.

Overall, I found the material reasonably approachable. The biggest shift was not learning an entirely new security discipline, but learning how existing governance, risk and security practices need to adapt when AI becomes part of an organisation’s technology environment.

Sitting the exam

Going into the exam I felt reasonably confident, although, as with most certification exams, there were still questions where I had to stop and think carefully about what was actually being asked.

I flagged approximately 15 of the 90 questions for review.

After going back through those questions and reviewing my answers, I submitted the exam with roughly an hour remaining.

I was then greeted with the result I had been hoping for:

Preliminary Pass.

That was a pretty good screen to see.

What I actually learned

One thing I appreciated about AAISM was that it wasn’t trying to turn security professionals into data scientists.

Instead, the certification focuses on how AI changes the responsibilities of security professionals.

The material looks at AI as an enterprise security and risk-management problem, covering how organisations govern AI, assess its risks, secure the technology and data behind it, and continue monitoring it after deployment.

The curriculum is divided into three main domains.

AI Governance and Program Management

The first domain covers how organisations establish appropriate governance around AI.

This includes defining ownership, roles and responsibilities; establishing AI strategies, policies and acceptable-use requirements; and making sure AI initiatives remain aligned with wider organisational objectives.

There is also significant emphasis on responsible AI.

Topics include:

  • Bias and fairness
  • Transparency and explainability
  • Trust and safety
  • Privacy
  • Intellectual property
  • Human rights
  • Human oversight
  • Regulatory and compliance requirements

Another important aspect is simply understanding what AI an organisation is using.

The material covers maintaining inventories of AI systems and associated data, data classification and lineage, security metrics, AI-specific security awareness, and incorporating AI into existing incident-response, business-continuity and disaster-recovery processes.

This domain represents 31% of the AAISM exam.

AI Risk and Opportunity Management

The second domain applies familiar risk-management principles specifically to AI.

This includes identifying AI risk, establishing acceptable risk thresholds, determining appropriate risk responses and carrying out assessments throughout the AI lifecycle.

Frameworks and regulatory approaches covered include the NIST Artificial Intelligence Risk Management Framework and the EU AI Act, alongside concepts such as privacy impact assessments, conformity assessments and fundamental-rights impact assessments.

The more security-focused part of this domain covers the emerging AI threat landscape.

Some of the threats covered include:

  • Prompt injection
  • Training-data leakage
  • Data poisoning
  • Model poisoning
  • Model theft
  • Model inversion
  • Model evasion

AAISM also spends time on the less obvious risks surrounding AI.

Organisations increasingly rely on third-party models, cloud services, APIs, open-source components and external datasets. Because of this, vendor management, shared responsibility and AI software supply-chain risk become significant parts of AI security.

This domain also represents 31% of the exam.

AI Technologies and Controls

The third and largest domain provides enough technical background to understand what is actually being protected.

It covers different forms of AI and machine learning, including:

  • Generative and predictive models
  • Supervised learning
  • Unsupervised learning
  • Reinforcement learning
  • Neural networks
  • Agentic AI

It then looks at security architecture and secure-by-design principles for AI systems.

A particularly useful part was viewing AI through its complete lifecycle:

Plan and design → collect and process data → build or adapt models → test and validate → deploy → operate and monitor → retire or decommission.

Security considerations exist throughout every stage.

The material also goes heavily into data governance and security because AI systems are fundamentally dependent on data. That includes data acquisition, storage, retention, destruction, access control, confidentiality, integrity and backups.

Other security concepts include Zero Trust, auditability and traceability, human-in-the-loop controls, shadow AI, supply-chain controls and AI-specific incident management.

Importantly, deploying an AI system isn’t the end of the process.

AI needs continuous monitoring for changes such as model drift, evolving threats, inappropriate use and changes to the underlying models, data or integrations.

This domain represents the remaining 38% of the exam.

Existing cybersecurity principles still matter

Probably my biggest takeaway from studying AAISM was that AI security isn’t an entirely separate discipline from cybersecurity.

A lot of the foundations are already familiar.

What changes is the technology being protected and some of the risks surrounding it.

AI introduces considerations around training data, models, unpredictable outputs, explainability, bias, model drift and attacks that simply didn’t exist in the same form within traditional infrastructure.

The underlying security principles still apply, but they need to be extended to account for those differences.

I think this is an important distinction as organisations increasingly adopt AI. It is very easy for AI security discussions to become focused entirely on the latest models or technical capabilities, when many of the problems organisations will face are ultimately governance, risk and security-management problems.

Was AAISM worthwhile?

For me, yes.

I didn’t pursue AAISM because I expected it to teach me how to train a neural network or build a large language model from scratch.

That isn’t really what the certification is designed for.

Its value is in understanding how AI fits into the wider security environment of an organisation.

As AI adoption continues, security teams are going to have to answer questions such as:

How do we know which AI systems are being used?

What data are employees putting into them?

How do we assess an AI vendor?

Who owns the risk associated with an AI system?

How do we respond if an AI system is compromised?

How do we test and monitor these systems?

What happens when a model begins behaving differently six months after deployment?

And how do we allow an organisation to benefit from AI without simply blocking it because it introduces new risks?

Those are fundamentally security-management questions.

AAISM gave me a much more structured way of thinking about them.

What’s next?

AI security is still developing extremely quickly.

Standards, regulation, attack techniques and the technology itself are all evolving at the same time, which means I don’t see completing AAISM as the end of learning about AI security.

If anything, it has given me a stronger foundation from which to continue exploring the technical side of AI security, AI-enabled cybersecurity and the risks that emerge as organisations integrate increasingly capable AI systems into their environments.

For someone already working in cybersecurity, that was exactly what I wanted to get out of it.

All posts

Crypto Lab

A small workbench over the browser's own cryptography, running three primitives on input you provide. Nothing is sent anywhere — every value is produced locally and discarded when the window closes.

  • Authenticated encryption — AES-256-GCM, keyed by PBKDF2-SHA256 over your passphrase. Flip a single bit of the ciphertext and the tag check refuses the whole message.
  • Signatures — ECDSA over P-256. Sign a message, then edit one character and watch verification fail as you type.
  • Digests — SHA-256, shown beside the digest of the same input with one bit changed, with every moved bit of the 256 marked.

The lab needs JavaScript, and a browser only exposes its cryptography to a page served over HTTPS.

Terminal

ethan@ethanlinton.com ~ $ whoami
Ethan — SME in network security and high-grade cryptography
CISSP  ·  CCNP  ·  M.CyberSec (Hons 1st)

ethan@ethanlinton.com ~ $ ls
about.txt   experience/   certs/   awards/   projects/   blog/   contact

ethan@ethanlinton.com ~ $ certs
  AAISM – Advanced in AI Security Management
  Master of Cyber Security
  Understanding of Cisco Network Devices
  Cisco Certified Specialist – Enterprise Core (CCNP ENCOR)
  Implementing and Administering Cisco Solutions (CCNA)
  CCNP – Cisco Certified Networking Professional
  Cisco Certified Specialist – Enterprise Advanced Infrastructure Implementation
  CISSP – Certified Information Systems Security Professional
  Microsoft Certified: Azure Administrator Associate (AZ-104)

ethan@ethanlinton.com ~ $ help
help  whoami  ls  cat about.txt  certs  projects  contact  open  clear

The interactive shell needs JavaScript.

Contact

The quickest way to reach me is email.

Social links are set in Settings → Ethan OS

Ethan