AI Engineer · Cybersecurity Innovator · Gamification Pioneer

Clint Bodungen

I build 

At the intersection of AI, cybersecurity, and games — building with AI since 2013, long before the wave.

13+ yearsbuilding with AI
30+ yearsin cybersecurity
20+ yearsof speaking engagements
2published books

00 — What I do

Cybersecurity is where I come from — innovation is what drives me.

For 30+ years I've done the same thing on repeat: bring an emerging technology into a field before it's obvious — first gamification, then AI. Find the frontier, and make it real.

The origin

Gamification of Cybersecurity

Co-created the world's first online, multiplayer, game-based cybersecurity simulation — making security training something you play, not sit through.

Since 2013

AI in Cybersecurity

Brought AI into security tooling and training years before the generative-AI wave — and published on generative AI for security while most of the field was still watching.

The convergence

AI + Gamification

Adversarial game AI, autonomous AI exercise facilitation, and AI-driven training — the two frontiers, fused.

Now

AI in Games & AI That Builds

AI in commercial video games — and AI systems that engineer software themselves. The domain keeps changing; the pattern doesn't.

01 — What I can do for you

The short version, without the jargon

When you need to reach the right person, I can usually pick up the phone.

Most of those years were spent directly inside the environments people usually write about second-hand: supermajor oil and gas, electric utilities, chemical manufacturing, national labs, major tech and infrastructure, and federal agencies. Stay in one field that long and you know the people who built it and who buys it.

I'll help you solve real problems with production ready AI.

Most of my work follows one pattern: take a slow, manual process that depends on a few experienced people, and build something that does the heavy lifting, improves efficiency, and increases value, while humans keep the decisions.

Support Ticket Systems

Automate the request queue that is eating your team

Nearly every organization has one workflow that quietly burns hundreds of staff hours a month: a request arrives, someone interprets it, someone checks it against policy, someone approves, someone implements. I build systems that run that whole path and stop wherever a human should be the one deciding.

What that looked like

Firewall change requests for a large enterprise: plain-language intake, enrichment against the asset database and existing rules, triage, risk and compliance checks, then a fully populated ticket in the service-management system. Days become minutes, and the same pattern moves to any request queue.

  • Saves time
  • Fewer mistakes
  • Auditable

Asset Inventory & CMDB Maintenance

Keep your asset inventory true without people doing it by hand

Onboarding new assets, reconciling updates and removing duplicates is one of the great unglamorous time sinks in security and IT, and scripting only takes it so far. An AI-native pipeline handles the messy matching that rules cannot.

What that looked like

Asset onboarding, updating and de-duplication for a critical-infrastructure security company, at a scale of tens of thousands of assets per ingest, cutting work that traditionally consumed enormous manual effort no matter how much scripting was thrown at it.

  • Saves time
  • Fewer mistakes
  • Richer data

Cyber Risk Assessment

Turn asset and exploit data into a ranked list of what to fix

Scanners produce findings. What nobody has is the connection between an asset, a reachable path to it, and an adversary who actually goes after organizations like yours. Correlating those is what turns a backlog into a priority.

What that looked like

Attack-path and exploit analysis over a graph database, correlating asset, vulnerability, adversary-behavior and mitigation data to rank risk and remediation, delivered through dashboards, interactive graphs, and a chat interface so an analyst can ask in plain English instead of writing queries.

  • Richer data
  • Scales expertise
  • Fewer mistakes

Cyber Vulnerability Assessment

Make a regulated assessment repeatable instead of heroic

Compliance work usually rests on a few experienced people and a pile of spreadsheets. That does not scale, and it does not hold up when an auditor asks how you reached a conclusion.

What that looked like

A configuration-change and vulnerability-assessment platform for an electric utility, designed to take a 30-plus hour per-facility process down to 3 or 4 with audit-ready output. Also a business-impact-analysis platform designed to cut assessment questionnaires roughly in half through conditional logic.

  • Saves time
  • Auditable
  • Scales expertise

Third-Party Risk & GRC Workflows

Replace the spreadsheet-and-email process with a real system

Some of the most consequential processes in a company run on a shared workbook and a mail thread, and afterwards nobody can reconstruct why a decision was made. These are usually the largest easy wins available.

What that looked like

An end-to-end third-party risk platform covering intake, inherent-risk scoring, due diligence, continuous monitoring and offboarding, with a complete audit trail behind every decision. Periodic review becomes something that runs all the time.

  • Saves time
  • Auditable
  • Always on

AI Agents for Security Operations

Put AI agents into real operations, not demos

There is a wide gap between a chatbot that impresses in a meeting and an agent you would trust with production. The difference is memory, guardrails, human checkpoints, and being explicit about what it must never do alone.

What that looked like

A persistent threat-intelligence agent running continuously and issuing daily intelligence to a live dashboard, and an agent-led recovery of a ransomware-encrypted production server: forensics, rebuild, hardening and cutover inside one working day, with zero data loss.

  • Always on
  • Newly possible
  • Scales expertise

Persistent AI Identity & Memory

Give an AI a memory so it stops starting over every session

Every AI assistant forgets you the moment the window closes. That is the single biggest reason they stay novelties instead of colleagues. I build the architecture that gives an agent continuous identity, memory and accumulated judgement.

What that looked like

MindStone and the Layered Continuity Architecture behind it, running a working group of agents that keep their history and judgement across months, machines, and even a change of underlying model. See the portfolio →

  • Newly possible
  • Richer data

AI Software Engineering & Evaluation

Build software with an AI team, and prove it actually works

Plenty of people now generate code with AI. Far fewer can show that what came out is correct. The interesting engineering is in the verification, not the generation.

What that looked like

TestFlight, which carries a project from research through to deployment, paired with Benchmark, a five-layer harness gating on types, unit behavior, API contract parity, real user flows, and whether the output is correct on held-out data. See the portfolio →

  • Saves time
  • Fewer mistakes
  • Auditable

AI-Native Game Development

Put real AI inside a game, not a chatbot bolted onto one

AI-native gameplay is new ground, and most of what is shipping is a language model in a costume. Doing it properly means the AI changes what the experience is, not just how it talks.

What that looked like

Dreamscape Legends, whose characters react to how a match actually went, and ScryForge, where eleven specialist agents help tabletop game masters build and run campaigns. Both have real players today. See the portfolio →

  • Better experience
  • Newly possible

AI Vendor & Exposure Assessment

Find out whether the AI you are being sold is real

Most AI security claims are a thin wrapper over something ordinary, and the people asked to evaluate them are rarely handed a method. I do this for buyers, and I teach the method publicly.

What that looked like

A structured approach to evaluating vendor AI claims, presented at S4, plus a diagnostic that scores an organization on where AI is actually exposing it against where it is an advantage not yet taken.

  • Fewer mistakes
  • Saves time

Security Training & Tabletop Exercises

Train your people with an exercise they will actually engage with

Security training fails because it is boring. Make it something people want to play and they retain it, argue about it, and ask when the next one is.

What that looked like

ThreatGEN Red vs. Blue and AutoTableTop, so a team can run a realistic incident without a week of preparation. See the portfolio →

  • Better experience
  • Scales expertise

Health & Personal Data Platforms

Turn your own data into something that helps you every day

The same pattern that works for an enterprise works for one person with a serious problem to manage. Scattered numbers nobody looks at become a clear picture of what is actually under control.

What that looked like

HeartOps, which turns passive, anxiety-driven disease management into daily visibility of which risk factors are and are not under control. See the portfolio →

  • Better experience
  • Always on
  • Richer data

02 — Capabilities

An unusually broad AI toolkit

From classic and bio-inspired AI to modern LLM and agentic systems — techniques applied across games, enterprise platforms, and security research.

Agentic & LLM Systems

  • Multi-Agent Orchestration
  • Agent Harnesses
  • Retrieval-Augmented Generation (RAG)
  • Persistent AI Identity & Memory

Bio-Inspired & Classic AI

  • Swarm Intelligence (Ant Colony Optimization)
  • Evolutionary Computation & Genetic Algorithms
  • Neural Networks & Neuroevolution
  • Multi-Objective Optimization

Game AI

  • Utility-Based Behavior Trees
  • Adversarial Search (Minimax)
  • Pathfinding and Probability Algorithms
  • AI-native NPCs and Narrative

Data & Knowledge

  • Knowledge Graphs (i.e. Neo4j)
  • Vector Databases & Semantic Search
  • LLM Fine-Tuning

03 — Portfolio

Flagship work

Named products and research, plus a genericized enterprise engagement. Every AI claim traces to real, shipped systems.

AI Infrastructure · personal

TestFlight — Multi-Agent Engineering Framework

A substrate-neutral framework that turns a coding agent into a disciplined, multi-agent software-engineering system — ~20 specialist agents, a verification loop with adversarial QA, and a differentiated rapid-prototyping methodology. Blind-judged experiments show it lifts a cheaper model to a frontier model's quality band. It built this very site.

Multi-AgentAgentic SDLCRapid PrototypingAI Eval

AI Infrastructure · personal

MindStone — Persistent AI Identity & Memory

A platform for persistent, memory-continuous AI agents: vector-backed semantic recall with experiential-salience weighting, a no-compaction continuity model, and dream-cycle consolidation — so an agent keeps its identity across sessions and even across different underlying models.

Vector MemoryRAGLLM AgentsLanceDB / sqlite-vec

Research · personal

Project DARWIN — Bio-Inspired Cyber-AI

Open research applying bio-inspired AI to cyber risk: virtual 'ant' swarms (Ant Colony Optimization) traverse a Neo4j attack graph of MITRE ATT&CK / D3FEND / CVSS to surface the most probable, high-impact attack paths, while genetic algorithms evolve adaptive defenses.

Swarm IntelligenceGenetic AlgorithmsNeo4jATT&CK

Product · ThreatGEN

ThreatGEN® Red vs. Blue

The world's first online, multiplayer, game-based cybersecurity simulation. Its red-team/blue-team opponent runs a utility-based game AI — behavior trees driven by animation-curve utility scoring — re-engineered from Unity/C# into a TypeScript web app.

Game AIUtility Behavior TreesUnity → Web

Product · ThreatGEN

ThreatGEN AutoTableTop™

An AI-powered incident-response tabletop-exercise platform driven by a multi-agent LLM system: an AI facilitator, scenario/timeline agents, and dynamic 'inject' delivery with structured outputs and real-time orchestration.

Multi-Agent LLMStructured OutputReal-time

Product · personal

Dreamscape Legends

A commercial online trading-card game with a minimax AI opponent (scalable difficulty) plus production LLM features — in-game AI narrative characters and AI-generated campaign content — and AI-assisted game design and balance analysis.

MinimaxLLM / GenAIGame Design

Product · personal

ScryForge

An AI toolkit for tabletop game masters: eleven specialist agents generate campaign-consistent NPCs, encounters, monsters and items, with session prep, a live-session mode, and content that stays linked to the campaign it belongs to. Real game masters use it to run real games.

Multi-Agent LLMContent GenerationLive Session

Product · personal

HeartOps

A cardiovascular health platform that turns passive, anxiety-driven disease management into daily visibility of which risk factors are and are not under control. Uses AI analysis and consultation. This project is still under development and has not been released yet.

Health DataRisk TrackingFull-Stack

AI Infrastructure · personal

Benchmark — AI Efficacy Test Harness

The standard answer to "does this thing actually work?" Benchmark is an AI-driven test harness for software engineers (including AI coding agents) with five independent gated layers: static analysis, unit behavior, API contract parity between backend and frontend, real end-to-end user flows, and efficacy — whether the AI produces correct, valuable output on held-out data. Used as a release gate, not a report.

AI EvaluationContract TestingRelease Gating

Product · personal

Operation Zero Hour

A full NFC conference-gamification platform: a Unity mobile app (player + sponsor lead-capture), a Firebase backend, and a React admin dashboard with conference-management features — guest-list import, badge-PDF generation, walk-up registration, and analytics.

MobileFirebaseReactFull-Stack

Enterprise · critical-infrastructure security client

AI Vulnerability-Management Platform

client

A security knowledge graph (Neo4j) fusing enterprise assets, vulnerabilities, MITRE ATT&CK / D3FEND, and CISA KEV exploit intelligence, with a multi-agent AI layer for natural-language querying and a four-layer AI asset-deduplication engine. Delivered under a fixed-price engagement.

Knowledge GraphLangGraphRAGNL→Cypher

04 — Experience

AI résumé

Leading AI/ML engineering, pioneering AI in cybersecurity products, and self-directed AI research — a track record that predates the current AI wave by a decade.

Arcova

formerly MorganFranklin Cyber · Full-time · Remote

Director, AI/ML Engineering

Aug 2025 – Present
  • Lead the AI/ML engineering team building production, agentic-AI applications across cybersecurity and GRC — including an AI-powered third-party risk-management platform (automated vendor tiering, evidence mapping from trust centers, OSINT/dark-web risk monitoring), an AI change-management intake system, and LLM-powered go-to-market and sales-intelligence tools.
  • Architect multi-agent and LLM systems using retrieval-augmented generation (RAG), structured/constrained generation, tool-using research agents, and provider-abstracted multi-model integration (Anthropic, OpenAI, and local models).
  • Established an AI-efficacy testing framework — multi-layer, including LLM-as-judge evaluation — as an engineering release gate that measures whether AI features actually perform, not just whether the code runs.
  • Advise on the secure integration of agentic AI — human-in-the-loop controls, source provenance/confidence tracking, and deterministic fallbacks.
  • Drive AI-native product strategy, reframing document-heavy GRC workflows around AI ingestion/inference layers that draft analysis from evidence with per-field provenance.

Director, Cybersecurity Innovation

Aug 2024 – Aug 2025
  • Led an innovation engagement delivering an AI-powered vulnerability-management platform for a critical-infrastructure security client — fusing enterprise assets, NVD vulnerabilities, MITRE ATT&CK / D3FEND, and CISA KEV exploit intelligence into a Neo4j security knowledge graph queryable in natural language.
  • Designed a multi-agent AI layer (LangChain / LangGraph): natural-language-to-Cypher graph querying, RAG-based security chatbots, and a self-extending meta-agent that writes its own graph analytics from plain-English use cases.
  • Built an exploit-aware, four-layer AI asset-deduplication engine (deterministic fingerprinting → semantic-embedding similarity → graph adjacency → LLM adjudication) that cut LLM cost ~70% via cheapest-method-first tiering.

ThreatGEN

Founder / Chairman / Head of Product Innovation · Full-time

Founder / Chairman / Head of Product Innovation

Jul 2017 – Present
  • Founded a funded cybersecurity startup closing the skills gap through gamification and AI-driven training — built on modern game engines, simulation technology, and Generative AI/LLMs.
  • Co-creator of ThreatGEN® Red vs. Blue — the world's first online, multiplayer, game-based cybersecurity simulation — including its adversarial red-team/blue-team game AI: utility-based behavior trees with animation-curve utility scoring (plus an exploratory neural-network opponent), now re-engineered for the web in TypeScript.
  • Creator of ThreatGEN AutoTableTop™ — an AI-powered incident-response tabletop-exercise platform driven by a multi-agent LLM system (an AI facilitator, scenario/timeline agents, and dynamic inject delivery) with structured outputs and real-time orchestration.
  • Pioneering the applied use of Generative AI and LLMs across cybersecurity training, exercises, and real-world application — spanning game AI, autonomous exercise facilitation, and AI-assisted content generation.

Independent AI Research

Ongoing

Founder & Principal Researcher

Building with AI since 2013
  • Designed a persistent-identity and long-term-memory architecture for LLM agents (Layered Continuity Architecture) — vector-backed semantic recall with experiential-salience weighting and dream-cycle consolidation — enabling agents to keep identity and knowledge across sessions and across different underlying models.
  • Built a substrate-neutral, multi-agent software-engineering framework that orchestrates ~20 specialized AI sub-agents under a codified SDLC, with a rapid-prototyping methodology and an adversarial verification loop.
  • Demonstrated, via pre-registered blind-judged A/B experiments, that the harness lifts a lower-cost model into a frontier model's shipped-quality band — isolating the gap as engineering discipline, not raw capability.
  • Pioneering bio-inspired AI for cybersecurity (Project DARWIN) — Ant Colony Optimization for attack-path discovery combined with genetic algorithms for adaptive defense.

05 — Research

Research & thought leadership

Self-directed work at the frontier of applied AI — bio-inspired methods, persistent agent identity, and the empirical study of what actually makes AI systems perform.

06 — Applied impact

AI agents doing real work

Beyond experiments — the persistent-agent systems applied to autonomous security operations and high-stakes incident response.

07 — In the media

Speaking and publications

Published author, speaker, and educator on AI and cybersecurity.

Clint Bodungen presenting on the main stage at S4x25, audience in the foreground
S4x25 · main stage
Clint Bodungen speaking at the podium in an LED mask at the ICS Cybersecurity Conference
ICS Cybersecurity Conference