A decade of work on U.S. government cybersecurity, across a defence contractor, a consulting giant and two of the largest cloud providers.
On 17 June 2021, Microsoft’s Azure Government blog carried a short announcement. The U.S. Department of Defence had approved Microsoft’s access to the Enterprise Mission Assurance Support Service, known as eMASS, the system the Pentagon uses to manage cybersecurity authorisations. Defence mission owners could now work directly with Microsoft on the security authorisation packages for Azure.
The post was written by Ibrahim Waziri Jr, then a product manager on the Azure Government team. In the version now published, he says the milestone was reached with the Defence Information Systems Agency and Booz Allen Hamilton, by converting Azure’s system security plans into a machine-readable format and loading them into eMASS using the National Institute of Standards and Technology’s Open Security Controls Assessment Language, or OSCAL.
It is a small item in a large cloud business, but it summarises much of his career: taking compliance paperwork and making it something software can read.
Washington, first as a student
Waziri’s professional life began in Washington while he was still at Purdue. In 2015, he interned as a cybersecurity analyst in the Office of the Chief Information Officer at the U.S. International Trade Commission, and he worked as a cyber anti-fraud analyst for RSA.
After finishing his PhD in 2016, he took a job as a security research engineer in the capital. The Guardian (Nigeria) has identified his employer as Apogee Research, a U.S. defence contractor. He worked on defence and national security research there and later as an information systems security engineer.
Deloitte
In 2018, He joined Deloitte. A 2019 Daily Trust profile described him as a senior consultant in the firm’s federal cyber risk practice, working with U.S. agencies on cyber risk and threats. The Guardian later reported that he led cybersecurity engineering, governance, risk and compliance work on federal digital transformation programmes, including projects for the Department of Health and Human Services and the Food and Drug Administration.
Teaching
From 2017, he also taught as an adjunct professor of cybersecurity at Marymount University in Arlington, Virginia, and served on PhD dissertation committees. His website lists courses in managing cybersecurity risk, cybersecurity in the system lifecycle, securing evolving technology infrastructure, computer security and computer networking.
Microsoft, 2020 to 2025
Waziri joined Microsoft in 2020 on the Azure for U.S. Government team, working on governance, risk and compliance engineering. The eMASS effort was his best-documented project there. His profile places the work between March 2020 and the June 2021 announcement.
From 2022 to 2024, he worked on Virtual Enclaves in Azure Mission Engineering, which builds cloud services for U.S. national security customers, according to his profile. In 2024, he moved to a cybersecurity and trust engineering group in Microsoft’s Corporate, External, and Legal Affairs division as a principal security product manager. He also worked on the Secure Future Initiative, the company-wide security programme Microsoft launched after a federal review board criticised its handling of a 2023 Exchange Online intrusion; he wrote about the review and the initiative’s first progress report on his personal website in 2024.
In his Georgia Southern alumni profile, he describes rising over five years from senior product manager to principal security product manager, owning cybersecurity compliance strategy for the Defence Department’s largest cloud programmes, building products that reduced high-risk security exposure for engineering teams and shortened authorisation timelines for national security customers, and advising Microsoft’s Cybersecurity Governance Council on security policy and AI governance. Those are his own descriptions; Microsoft has not published a separate account.
A seat on Nigeria’s digital health committee
In spring 2024, Waziri was named to the 20-member implementation committee of the Nigeria Digital in Health Initiative. The Federal Government inaugurated the body in Abuja; Health Minister Muhammad Ali Pate presented the appointment letters, and Minister of State for Health Tunji Alausa chairs it.
According to the Federal Ministry of Information’s statement, the committee is meant to shape data policy and regulation, manage data repositories and act as an ombudsman for a national digital health environment, beginning with a unified national electronic medical records platform. The ministry’s list of members includes Waziri. Nigerian newspapers reported his appointment in late April 2024.
Google, 2025 to 2026
In June 2025, he joined Google Cloud as Global Insider Risk and Incident Governance Lead in the risk and compliance group of the Cloud CISO organisation. In his alumni profile, he says he led the regulatory incident governance domain, helped shape Google’s AI insider-risk strategy by developing and prioritising controls to protect proprietary cloud and AI models and training data, and led risk reviews for major regulatory engagements and corporate transactions. His website adds security due diligence for acquisitions and support for Google’s Secure AI Framework.


