{"schemaVersion":1,"updated":"2026-09-05","scope":"Curated public professional summary. The linked final PDF is the primary resume.","name":"Xavier Charles Motley","headline":"Security leadership. Product secrecy. Practical protection.","summary":"Security leader combining Apple-account information protection, global CISO experience, product and cloud security, and investigations in sensitive research environments. A partner to creative, technical, and executive teams, translating risk into practical decisions that preserve trust and momentum.","focus":["Marketing and product-launch security","Information protection and third-party risk","Investigations and incident response","Product, software and cloud security","Executive advisory and security operating models"],"links":{"resume":"/Xavier-Charles-Motley-Resume.pdf","linkedin":"https://www.linkedin.com/in/xaviermotley/","github":"https://github.com/xaviermotley","writing":"https://xaviermotley.substack.com"},"book":{"title":"The Chief Information Security Officer Operating System","subtitle":"A field guide for the modern security function","author":"Xavier Charles Motley","status":"Forthcoming","releaseDate":"2026-10-31"},"projects":[{"name":"Creative Content Security Lab","type":"Personal research lab","question":"How do you protect creative work across partner handoffs?","description":"A small Python and FastAPI lab exploring recipient-specific packaging, vendor access, activity logging, and detection patterns for sensitive creative assets.","decision":"Keep the recipient and package identity connected across the workflow so activity can be investigated in context.","boundary":"Local proof of concept with ten automated access tests: recipient checks, revocation, expiry, and encrypted package delivery. Production identity, key distribution, concurrent policy changes, and independent validation remain outside scope.","url":"https://github.com/xaviermotley/creative-content-security-lab","evidence":"https://github.com/xaviermotley/creative-content-security-lab/blob/main/tests/test_access.py","evidenceLabel":"Inspect the access tests","tags":["Python","FastAPI","Content protection"]},{"name":"Secure Cloud Data Architecture","type":"Reference architecture","question":"How do you make data useful without making it indiscriminately accessible?","description":"An AWS architecture study with Terraform examples, STRIDE threat models, control mappings, and decision records for data zoning and access boundaries.","decision":"Separate sensitive data flows and document the usability, access and operational tradeoffs instead of treating security as an afterthought.","boundary":"Architecture and example infrastructure, not a validated production deployment. The documented target design is broader than the current Terraform implementation.","url":"https://github.com/xaviermotley/secure-data-lake-aws-architect","evidence":"https://github.com/xaviermotley/secure-data-lake-aws-architect/blob/main/docs/DECISIONS.md","evidenceLabel":"Read the design decisions","tags":["AWS","Terraform","Threat modeling"]}],"writing":[{"title":"Protecting the Story","description":"Security, trust, and the creative supply chain.","date":"2025-11-16","topic":"Creative work","url":"https://xaviermotley.substack.com/p/protecting-the-story?review=20260906"},{"title":"Trust With Clear Boundaries","description":"Practical controls, clear accountability, and collaboration that preserves trust.","date":"2025-11-17","topic":"Leadership","url":"https://xaviermotley.substack.com/p/ciso-philosophy-creating-high-trust?review=20260906"},{"title":"Securing Creative Pipelines","description":"Practical handling rules, partner handoffs, intake, and escalation for sensitive creative work.","date":"2025-11-17","topic":"Creative workflows","url":"https://xaviermotley.substack.com/p/securing-creative-pipelines-content?review=20260906"}]}