Max AlexanderD.Eng., CEng MIET

I work on the two hardest problems in security: what survives failure, and what is being hidden.

Firmwide technology resiliency at JPMorganChase. Digital forensics in the classroom. Twenty years in Army Special Forces and defense special operations.

Illustrated portrait of Max Alexander

Resiliency, emerging threats, and client engagement

I lead REACT — Resiliency, Emerging Threats, Assessments, and Client Engagement — a global function within Firmwide Technology Resiliency at JPMorganChase. The work is designing and running multinational crisis exercises, conducting strategic assessments and after-action reviews, and advising boards, CISOs, and institutional clients on what their systems will actually do under stress.

Less about preventing failure than about knowing, in advance and in detail, the shape it will take.

Employer JPMorganChase Function REACT

Teaching digital forensics and artificial intelligence

Professorial Lecturer at the George Washington University School of Engineering & Applied Science, advising doctoral research in cybersecurity analytics, digital forensics, insider threat, and applied AI. Primary advisor for ten completed doctorates and a committee member on more than twenty-five others.

Adjunct Professor and Digital Forensics Course Coordinator at University of Maryland Global Campus.

Institutions GWU SEAS UMGC Doctoral advising 10 as primary advisor
25+ committees

Twenty years in Army Special Forces

From 1998 to 2018, U.S. Army Special Forces and defense special operations, assigned and attached to other intelligence agencies. At the Office of the Director of National Intelligence, I chaired the Technical Surveillance Countermeasures Working Group. That work is the reason I read a system the way I do: not as a diagram of how it is meant to behave, but as a set of assumptions someone else may already be exploiting.

Period 1998–2018 Role Chair, TSCM Working Group
ODNI
Detail Not further specified

Chief technology officer and CISO

From 2016 to 2019, CTO and Director of Cybersecurity at Aveshka. In that role I headed the Pentagon's digital forensics team for PENTCIRT, its incident response team, and helped establish the User Activity Monitoring and Insider Threat Program.

Insider threat is counterintelligence work. It runs from catching spies and national security crimes at one end of the range to improper computer use at the other.

Employer Aveshka Role CTO · Director of Cybersecurity Period 2016–2019

Cybersecurity attack simulation

From 2019 to 2024 at JPMorganChase, building and running adversary simulation against the firm's own controls — finding out what the defenses actually did, rather than what the documentation claimed.

Employer JPMorganChase Period 2019–2024

Foreign denial and deception

Doctoral research in modern war studies specializing in foreign denial and deception. Before that, formal study in science and technology intelligence at the National Intelligence University, and certification from the Foreign Denial and Deception Committee.

Deception is the one adversary technique that turns your own evidence against you, which makes it the hardest thing an analyst ever has to price in.

Institution University of Buckingham National Intelligence University Science and technology intelligence
FDDC certification
Status Thesis submitted
Viva pending

Cyber security analytics

A doctorate in cyber security analytics, grounded in electrical engineering and artificial intelligence, with a praxis in digital forensics. That last part is why the teaching and the research are one subject rather than two careers.

Before any of it, a first training as a philosopher. The philosophy is not decorative. It is why I ask what would have to be true for a claim to be wrong before I ask whether it sounds right.

ORCID 0009-0007-6111-6946 Certifications CISSP · CISM · CRISC
CCSP · CFE
DoD cybercrime examiner

Selected work

Peer-reviewed publications, white papers, and conference sessions on resiliency, financial crime, and AI-driven fraud.

Read the writing →

Index ORCID record

Elsewhere