About


I started my career in cybersecurity in 2012, working across endpoint security, infrastructure, compliance, and enterprise technology. What followed was thirteen years of progressively larger mandates, harder problems, and a front-row seat to how serious organizations get security wrong at scale.

The career arc looks clean from the outside: Cigna, Aetna, Booz Allen, Deloitte, LinkedIn. What it doesn't show is the accumulation: patterns seen across every sector, decisions made without perfect information, systems that failed talented people not from bad intent but from structural neglect.

That accumulation became a point of view. That point of view became ProfytAI.

Jeff Kangar

I started at Cigna, moving from analyst to advisor across multiple technical disciplines. From there, the mandates grew: cloud security at Aetna, federal cloud enablement at Booz Allen Hamilton, cybersecurity on a U.S. State Department modernization engagement at Deloitte, and enterprise security program leadership at LinkedIn.

In every one of those roles, the standard was unambiguous. You secured the environment or you didn't. You earned the Authorization to Operate or you went back and fixed what was broken. That shaped how I think about leadership. Not as a title, but as a commitment to the outcome.

I also learned what it looks like when talented people are let down by broken systems. Organizations investing heavily in compliance and still getting it wrong. Not from bad intentions, but because the infrastructure was fragile, manual, and built for a different era. That pattern, repeated across every sector I worked in, is what eventually became ProfytAI.

And I learned to operate at the executive level in the truest sense: translating complex risk into language executives and senior stakeholders can act on, building coalitions across competing priorities, and making hard calls without perfect information. Those aren't skills you get from certifications. They come from showing up, repeatedly, in environments where the cost of getting it wrong is real.

What I accumulated over those thirteen years wasn't just experience. It was a view of the compliance problem from the inside, across every level of scale. I've seen it as an analyst, an advisor, a manager, and a senior leader. I know where the failures originate, what the workarounds cost, and what a real fix would actually require. That's the foundation ProfytAI is built on.

The newest application of that foundation is AI governance. At ProfytAI, I apply my cybersecurity, technology risk, and governance background to AI-assisted regulatory intelligence and evidence workflows, focusing on source traceability, clear decision rights, and human review at critical decision points.


Security and compliance are not the same thing. Most organizations treat them as if they are. Compliance is a floor, not a ceiling. Meeting a framework requirement demonstrates alignment to a defined baseline. It does not, by itself, mean an organization is secure.

The organizations that get security right don't treat it as a constraint on the business. They treat it as a competitive advantage: something that earns trust from customers, partners, and regulators before anyone thinks to ask for it. That posture is a choice, and it starts at the top.

I believe that how you build a team is a security decision. Diverse teams ask different questions, model threats differently, and perform better when it matters most. That's not a values statement. It's an operational reality I've watched play out across every environment I've worked in.

I also believe that how a leader shows up in the hard moments tells you everything about who they actually are. The most important thing you can do for the people on your team is make them feel like they genuinely belong there. Not as a cultural initiative, but as a daily practice. That's the kind of leader I'm still working to be.


By the time I left LinkedIn, I had seen the same underlying problem across enterprise and federal environments: teams interpreting dense requirements manually, mapping them to controls, assembling evidence across fragmented systems, and repeating the work every time a regulation or review changed. ProfytAI grew from that problem.

ProfytAI is built on the idea that regulation should be structured, source-anchored, and usable by both people and systems. We started with financial institutions in Southeast Asia, where regulatory change is accelerating and the cost of interpretation and evidence gaps is high.


Leading ProfytAI through its next stage: expanding regulatory intelligence across BSP and MAS requirements, working with regulated financial institutions in Southeast Asia, and extending the same evidence-first approach into U.S. federal cybersecurity assessment technology.

Writing about leadership, building companies, and the harder personal work that sits underneath both.

Available for advisory engagements and speaking on cybersecurity, AI-driven compliance, and executive leadership in regulated industries.


Thirteen years is enough to understand a problem deeply. It is also enough to understand the cost of leaving it unsolved.

That tension is where ProfytAI comes from. Not from a whiteboard exercise or a gap in the market someone pointed out. From watching organizations get compliance wrong, at every level of scale, for over a decade. From knowing, with real specificity, what a genuine fix would actually require.

The work ahead is significant. I've never been more certain it's the right work.