Rainier (Ram) Milanes

Focus profile

Cybersecurity, GRC, and IT risk

Cybersecurity governance, GRC, and IT-risk work emphasizing security governance, controls, audit readiness, and risk remediation, supported by security education and applied governance work.

Competencies

What this track emphasizes

  • GRC
  • IT risk assessment
  • Security controls
  • Audit and compliance readiness
  • Security governance
  • Risk remediation

Featured evidence

PrivAI Guard

Control design, access boundaries, risk scoring, remediation, and audit evidence.

Featured project

PrivAI Guard

Shadow AI privacy-risk triage · 2026

A cloud-deployed full-stack Shadow AI governance MVP that converts potentially risky AI use into structured risk assessment, governance review, remediation, and audit evidence.

Northwestern University MSIS capstone MVP. Non-production. Synthetic demonstration data only. Human governance review — not automated legal or regulatory decisioning.

Read the PrivAI Guard case study

Experience

Selected roles

RAM Privacy & Security

October 2024Present

Principal Consultant

  • Assess cybersecurity, privacy, and technology-risk issues for regulated and high-risk organizations and translate findings into governance, control, and remediation work.
  • Conduct risk assessments and translate findings into prioritized remediation actions, implementation roadmaps, and measurable controls.

National Privacy Commission

October 2024January 2026

Innovation and Transformation Consultant

Designated Chief Information Technology Officer

  • Assessed cybersecurity, technology-risk, and information-security issues and advised on control implementation and critical-infrastructure protection.
  • Supported risk assessments and the development of controls addressing identified cybersecurity and information-security risks.

National Privacy Commission

March 2021September 2024

Chief, Compliance and Monitoring Division

  • Led compliance monitoring, breach-notification processing, registration, compliance support, and regulatory reporting operations.
  • Conducted and oversaw privacy, security, technology, and compliance assessments across high-volume operational workflows.

Bankmer Realty Corporation

January 2017July 2020

Director of Operations & Data Protection Officer

  • Established the organization’s first Privacy Management Program, including privacy governance, policies, security procedures, data-handling standards, employee training, and accountability controls.
  • Conducted privacy and operational risk assessments and translated findings into corrective actions and improved data-governance practices.

Bankmer Realty Corporation

March 2015December 2016

Corporate Counsel / Facilities Manager

  • Planned IT and information-security improvements and digitalized corporate records to protect confidential organizational information.
  • Coordinated technology vendors, contracts, regulatory requirements, and implementation activities involving confidential organizational information.

Credentials

Relevant credentials

Education

Master of Science in Information Systems, Security Specialization

Northwestern University · 2026

Coursework includes Information Security Management; Information Security Strategy; Cybersecurity Attacks & Countermeasures; Disaster Recovery & Business Continuity; Artificial Intelligence; Machine Learning; Spec-Driven Software Development; and Project Management.

Certification

Certified Information Privacy Manager (CIPM)

IAPP

Certification

Certified in Cybersecurity (CC)

ISC2

Training

Professional Development Certificate in Cybersecurity

Australian National University, National Security College

Cyber and Critical Tech Cooperation Program – Cybersecurity Bootcamp

Training

Industrial Control Systems Cybersecurity Training

U.S. Department of Homeland Security, CISA

Licensure

Licensed to Practice Law in the Philippines

Supreme Court of the Philippines / Integrated Bar of the Philippines

This is Philippine legal licensure. It does not imply U.S. bar admission or authorization to practice law in the United States.

Writing

Selected writing

White paper · 2026

Architectural Fragility and the Illusion of Cost-Savings: A Critical Analysis of the eGov PH Super App Outage and the Imperative for Enterprise-Grade BC/DR

A resilience-focused analysis of the eGov PH Super App outage examining cloud capacity, availability, interoperability, identity governance, data protection, sovereign continuity, and business continuity and disaster recovery for national-scale digital services.

Also available: Privacy / AI Governance

Start a conversation

Email and LinkedIn are the public contact channels.