AI Engineer · Cybersecurity Innovator · Gamification Pioneer
Clint Bodungen
At the intersection of AI, cybersecurity, and games — building with AI since 2013, long before the wave.
00 — What I do
Cybersecurity is where I come from — innovation is what drives me.
For 30+ years I've done the same thing on repeat: bring an emerging technology into a field before it's obvious — first gamification, then AI. Find the frontier, and make it real.
The origin
Gamification of Cybersecurity
Co-created the world's first online, multiplayer, game-based cybersecurity simulation — making security training something you play, not sit through.
Since 2013
AI in Cybersecurity
Brought AI into security tooling and training years before the generative-AI wave — and published on generative AI for security while most of the field was still watching.
The convergence
AI + Gamification
Adversarial game AI, autonomous AI exercise facilitation, and AI-driven training — the two frontiers, fused.
Now
AI in Games & AI That Builds
AI in commercial video games — and AI systems that engineer software themselves. The domain keeps changing; the pattern doesn't.
01 — What I can do for you
The short version, without the jargon
When you need to reach the right person, I can usually pick up the phone.
Most of those years were spent directly inside the environments people usually write about second-hand: supermajor oil and gas, electric utilities, chemical manufacturing, national labs, major tech and infrastructure, and federal agencies. Stay in one field that long and you know the people who built it and who buys it.
I'll help you solve real problems with production ready AI.
Most of my work follows one pattern: take a slow, manual process that depends on a few experienced people, and build something that does the heavy lifting, improves efficiency, and increases value, while humans keep the decisions.
Support Ticket Systems
Automate the request queue that is eating your team
Nearly every organization has one workflow that quietly burns hundreds of staff hours a month: a request arrives, someone interprets it, someone checks it against policy, someone approves, someone implements. I build systems that run that whole path and stop wherever a human should be the one deciding.
What that looked like
Firewall change requests for a large enterprise: plain-language intake, enrichment against the asset database and existing rules, triage, risk and compliance checks, then a fully populated ticket in the service-management system. Days become minutes, and the same pattern moves to any request queue.
- Saves time
- Fewer mistakes
- Auditable
Asset Inventory & CMDB Maintenance
Keep your asset inventory true without people doing it by hand
Onboarding new assets, reconciling updates and removing duplicates is one of the great unglamorous time sinks in security and IT, and scripting only takes it so far. An AI-native pipeline handles the messy matching that rules cannot.
What that looked like
Asset onboarding, updating and de-duplication for a critical-infrastructure security company, at a scale of tens of thousands of assets per ingest, cutting work that traditionally consumed enormous manual effort no matter how much scripting was thrown at it.
- Saves time
- Fewer mistakes
- Richer data
Cyber Risk Assessment
Turn asset and exploit data into a ranked list of what to fix
Scanners produce findings. What nobody has is the connection between an asset, a reachable path to it, and an adversary who actually goes after organizations like yours. Correlating those is what turns a backlog into a priority.
What that looked like
Attack-path and exploit analysis over a graph database, correlating asset, vulnerability, adversary-behavior and mitigation data to rank risk and remediation, delivered through dashboards, interactive graphs, and a chat interface so an analyst can ask in plain English instead of writing queries.
- Richer data
- Scales expertise
- Fewer mistakes
Cyber Vulnerability Assessment
Make a regulated assessment repeatable instead of heroic
Compliance work usually rests on a few experienced people and a pile of spreadsheets. That does not scale, and it does not hold up when an auditor asks how you reached a conclusion.
What that looked like
A configuration-change and vulnerability-assessment platform for an electric utility, designed to take a 30-plus hour per-facility process down to 3 or 4 with audit-ready output. Also a business-impact-analysis platform designed to cut assessment questionnaires roughly in half through conditional logic.
- Saves time
- Auditable
- Scales expertise
Third-Party Risk & GRC Workflows
Replace the spreadsheet-and-email process with a real system
Some of the most consequential processes in a company run on a shared workbook and a mail thread, and afterwards nobody can reconstruct why a decision was made. These are usually the largest easy wins available.
What that looked like
An end-to-end third-party risk platform covering intake, inherent-risk scoring, due diligence, continuous monitoring and offboarding, with a complete audit trail behind every decision. Periodic review becomes something that runs all the time.
- Saves time
- Auditable
- Always on
AI Agents for Security Operations
Put AI agents into real operations, not demos
There is a wide gap between a chatbot that impresses in a meeting and an agent you would trust with production. The difference is memory, guardrails, human checkpoints, and being explicit about what it must never do alone.
What that looked like
A persistent threat-intelligence agent running continuously and issuing daily intelligence to a live dashboard, and an agent-led recovery of a ransomware-encrypted production server: forensics, rebuild, hardening and cutover inside one working day, with zero data loss.
- Always on
- Newly possible
- Scales expertise
Persistent AI Identity & Memory
Give an AI a memory so it stops starting over every session
Every AI assistant forgets you the moment the window closes. That is the single biggest reason they stay novelties instead of colleagues. I build the architecture that gives an agent continuous identity, memory and accumulated judgement.
What that looked like
MindStone and the Layered Continuity Architecture behind it, running a working group of agents that keep their history and judgement across months, machines, and even a change of underlying model. See the portfolio →
- Newly possible
- Richer data
AI Software Engineering & Evaluation
Build software with an AI team, and prove it actually works
Plenty of people now generate code with AI. Far fewer can show that what came out is correct. The interesting engineering is in the verification, not the generation.
What that looked like
TestFlight, which carries a project from research through to deployment, paired with Benchmark, a five-layer harness gating on types, unit behavior, API contract parity, real user flows, and whether the output is correct on held-out data. See the portfolio →
- Saves time
- Fewer mistakes
- Auditable
AI-Native Game Development
Put real AI inside a game, not a chatbot bolted onto one
AI-native gameplay is new ground, and most of what is shipping is a language model in a costume. Doing it properly means the AI changes what the experience is, not just how it talks.
What that looked like
Dreamscape Legends, whose characters react to how a match actually went, and ScryForge, where eleven specialist agents help tabletop game masters build and run campaigns. Both have real players today. See the portfolio →
- Better experience
- Newly possible
AI Vendor & Exposure Assessment
Find out whether the AI you are being sold is real
Most AI security claims are a thin wrapper over something ordinary, and the people asked to evaluate them are rarely handed a method. I do this for buyers, and I teach the method publicly.
What that looked like
A structured approach to evaluating vendor AI claims, presented at S4, plus a diagnostic that scores an organization on where AI is actually exposing it against where it is an advantage not yet taken.
- Fewer mistakes
- Saves time
Security Training & Tabletop Exercises
Train your people with an exercise they will actually engage with
Security training fails because it is boring. Make it something people want to play and they retain it, argue about it, and ask when the next one is.
What that looked like
ThreatGEN Red vs. Blue and AutoTableTop, so a team can run a realistic incident without a week of preparation. See the portfolio →
- Better experience
- Scales expertise
Health & Personal Data Platforms
Turn your own data into something that helps you every day
The same pattern that works for an enterprise works for one person with a serious problem to manage. Scattered numbers nobody looks at become a clear picture of what is actually under control.
What that looked like
HeartOps, which turns passive, anxiety-driven disease management into daily visibility of which risk factors are and are not under control. See the portfolio →
- Better experience
- Always on
- Richer data
02 — Capabilities
An unusually broad AI toolkit
From classic and bio-inspired AI to modern LLM and agentic systems — techniques applied across games, enterprise platforms, and security research.
Agentic & LLM Systems
- Multi-Agent Orchestration
- Agent Harnesses
- Retrieval-Augmented Generation (RAG)
- Persistent AI Identity & Memory
Bio-Inspired & Classic AI
- Swarm Intelligence (Ant Colony Optimization)
- Evolutionary Computation & Genetic Algorithms
- Neural Networks & Neuroevolution
- Multi-Objective Optimization
Game AI
- Utility-Based Behavior Trees
- Adversarial Search (Minimax)
- Pathfinding and Probability Algorithms
- AI-native NPCs and Narrative
Data & Knowledge
- Knowledge Graphs (i.e. Neo4j)
- Vector Databases & Semantic Search
- LLM Fine-Tuning
03 — Portfolio
Flagship work
Named products and research, plus a genericized enterprise engagement. Every AI claim traces to real, shipped systems.
Research · personal
Project DARWIN — Bio-Inspired Cyber-AI
Open research applying bio-inspired AI to cyber risk: virtual 'ant' swarms (Ant Colony Optimization) traverse a Neo4j attack graph of MITRE ATT&CK / D3FEND / CVSS to surface the most probable, high-impact attack paths, while genetic algorithms evolve adaptive defenses.
Product · personal
HeartOps
A cardiovascular health platform that turns passive, anxiety-driven disease management into daily visibility of which risk factors are and are not under control. Uses AI analysis and consultation. This project is still under development and has not been released yet.
AI Infrastructure · personal
Benchmark — AI Efficacy Test Harness
The standard answer to "does this thing actually work?" Benchmark is an AI-driven test harness for software engineers (including AI coding agents) with five independent gated layers: static analysis, unit behavior, API contract parity between backend and frontend, real end-to-end user flows, and efficacy — whether the AI produces correct, valuable output on held-out data. Used as a release gate, not a report.
Enterprise · critical-infrastructure security client
AI Vulnerability-Management Platform
A security knowledge graph (Neo4j) fusing enterprise assets, vulnerabilities, MITRE ATT&CK / D3FEND, and CISA KEV exploit intelligence, with a multi-agent AI layer for natural-language querying and a four-layer AI asset-deduplication engine. Delivered under a fixed-price engagement.
04 — Experience
AI résumé
Leading AI/ML engineering, pioneering AI in cybersecurity products, and self-directed AI research — a track record that predates the current AI wave by a decade.
Arcova
formerly MorganFranklin Cyber · Full-time · RemoteDirector, AI/ML Engineering
Aug 2025 – Present- Lead the AI/ML engineering team building production, agentic-AI applications across cybersecurity and GRC — including an AI-powered third-party risk-management platform (automated vendor tiering, evidence mapping from trust centers, OSINT/dark-web risk monitoring), an AI change-management intake system, and LLM-powered go-to-market and sales-intelligence tools.
- Architect multi-agent and LLM systems using retrieval-augmented generation (RAG), structured/constrained generation, tool-using research agents, and provider-abstracted multi-model integration (Anthropic, OpenAI, and local models).
- Established an AI-efficacy testing framework — multi-layer, including LLM-as-judge evaluation — as an engineering release gate that measures whether AI features actually perform, not just whether the code runs.
- Advise on the secure integration of agentic AI — human-in-the-loop controls, source provenance/confidence tracking, and deterministic fallbacks.
- Drive AI-native product strategy, reframing document-heavy GRC workflows around AI ingestion/inference layers that draft analysis from evidence with per-field provenance.
Director, Cybersecurity Innovation
Aug 2024 – Aug 2025- Led an innovation engagement delivering an AI-powered vulnerability-management platform for a critical-infrastructure security client — fusing enterprise assets, NVD vulnerabilities, MITRE ATT&CK / D3FEND, and CISA KEV exploit intelligence into a Neo4j security knowledge graph queryable in natural language.
- Designed a multi-agent AI layer (LangChain / LangGraph): natural-language-to-Cypher graph querying, RAG-based security chatbots, and a self-extending meta-agent that writes its own graph analytics from plain-English use cases.
- Built an exploit-aware, four-layer AI asset-deduplication engine (deterministic fingerprinting → semantic-embedding similarity → graph adjacency → LLM adjudication) that cut LLM cost ~70% via cheapest-method-first tiering.
ThreatGEN
Founder / Chairman / Head of Product Innovation · Full-timeFounder / Chairman / Head of Product Innovation
Jul 2017 – Present- Founded a funded cybersecurity startup closing the skills gap through gamification and AI-driven training — built on modern game engines, simulation technology, and Generative AI/LLMs.
- Co-creator of ThreatGEN® Red vs. Blue — the world's first online, multiplayer, game-based cybersecurity simulation — including its adversarial red-team/blue-team game AI: utility-based behavior trees with animation-curve utility scoring (plus an exploratory neural-network opponent), now re-engineered for the web in TypeScript.
- Creator of ThreatGEN AutoTableTop™ — an AI-powered incident-response tabletop-exercise platform driven by a multi-agent LLM system (an AI facilitator, scenario/timeline agents, and dynamic inject delivery) with structured outputs and real-time orchestration.
- Pioneering the applied use of Generative AI and LLMs across cybersecurity training, exercises, and real-world application — spanning game AI, autonomous exercise facilitation, and AI-assisted content generation.
Independent AI Research
OngoingFounder & Principal Researcher
Building with AI since 2013- Designed a persistent-identity and long-term-memory architecture for LLM agents (Layered Continuity Architecture) — vector-backed semantic recall with experiential-salience weighting and dream-cycle consolidation — enabling agents to keep identity and knowledge across sessions and across different underlying models.
- Built a substrate-neutral, multi-agent software-engineering framework that orchestrates ~20 specialized AI sub-agents under a codified SDLC, with a rapid-prototyping methodology and an adversarial verification loop.
- Demonstrated, via pre-registered blind-judged A/B experiments, that the harness lifts a lower-cost model into a frontier model's shipped-quality band — isolating the gap as engineering discipline, not raw capability.
- Pioneering bio-inspired AI for cybersecurity (Project DARWIN) — Ant Colony Optimization for attack-path discovery combined with genetic algorithms for adaptive defense.
05 — Research
Research & thought leadership
Self-directed work at the frontier of applied AI — bio-inspired methods, persistent agent identity, and the empirical study of what actually makes AI systems perform.
Bio-Inspired AI for Cyber Risk (Project DARWIN)
Swarm intelligence (Ant Colony Optimization) for attack-path discovery, fused with genetic algorithms and neuroevolution for adaptive defense — a multi-objective, nature-inspired approach to modeling attacker behavior and evolving mitigations.
06 — Applied impact
AI agents doing real work
Beyond experiments — the persistent-agent systems applied to autonomous security operations and high-stakes incident response.
07 — In the media
Speaking and publications
Published author, speaker, and educator on AI and cybersecurity.


Talks & Classes
- Industry Panel: AI on Defense, Right Now: What's Actually Working in OT — Industrial Cyber Days — virtual conference · Jul 2026
- Project D.A.R.W.I.N.: Can Bio-Evolution Finally Solve Cybersecurity? — HouSecCon · Jan 2026
- Cutting Through the AI Hype: How AI Is Actually Used in ICS/OT — Industrial Cyber Days — virtual conference · May 2025
- Evaluating Vendor AI Claims — S4x25 · Apr 2025
- Real-World Cybersecurity Applications with Generative AI and LLMs — HouSecCon · Oct 2024
- Security Risks in LLMs: Prompt Injection & Data Poisoning — Packt · Sep 2024
- AI Jailbreaking Demo: How Prompt Engineering Bypasses LLM Security — Packt · Sep 2024
- Laugh, Learn, and Lock Down: An Interactive IR Adventure — ElevateIT — Phoenix Tech Summit · Sep 2024
- AI in Production in OT: Today, Right Now, Not in the Future — S4x24 · Mar 2024
Podcasts & Media
- Broken Governance, Agentic AI, and the MindStone Agent — SecurityWeek · Jul 2026
- Gen AI in Cybersecurity — Tech Leader · Jun 2025
- AI, Tabletop Exercises & OT: Navigating Cyber Challenges — PrOTect IT All · Nov 2024
- Harnessing AI to Revolutionize OT Protection — PrOTect IT All · Feb 2024
- Cybersecurity Simulation as a Video Game, with AI Adversaries — The PrOTect OT Cybersecurity Podcast · Nov 2023
- Are You Doing Your Vulnerability Assessments Wrong? — Cyber Superhuman AI · Aug 2023
- Bracing for an AI-Infused Future: A Cyber Mastermind's Perspective — Cyber Superhuman AI · Aug 2023
- Cybersecurity Superhuman: 6-part live-stream series — Cyber Superhuman AI · Jun 2023
- How the Gamification of Cybersecurity Changes the Game for GOOD — Tigerpaw Software · Sep 2022
- Red vs. Blue and the Gamification of Cyber Security — Manufacturing Hub · Mar 2022
- Cybersecurity & Gamification to Industrial Cybersecurity (Ep. 50) — SolisPLC · Feb 2022

