Xabier Muruaga

Xabier Muruaga

Global Head of AI & Data @ Iberdrola · AI Architect · Adjunct Professor @ IE University

I architect production AI and agentic systems where security, governance, and assurance are structural decisions — not layers added after deployment. My work covers LLM gateways, RAG pipelines, agentic systems, and control planes, with runtime controls, threat boundaries, and audit-ready evidence designed into the architecture from day one.

At Iberdrola, I lead global AI and Data, owning architecture, security, and technical governance, and shaping the platform foundations behind GenAI and agent initiatives at Europe's largest regulated energy operator. A major part of my work translates AI security risks into enforceable controls and assurance evidence aligned with OWASP LLM and agentic AI guidance, MITRE ATLAS, CSA MAESTRO, NIST AI RMF, EU AI Act, and ISO/IEC 42001.

I contribute to industry standards as a founding consortium member of AIUC-1, contributor to the OWASP GenAI Security Project, and member of the CSA AI Safety Working Group. I also teach ML Systems and MLOps at IE University, with a focus on the architecture and controls required to operate AI safely at scale.

Experience

Cloud Security Alliance logo

AI Safety Working Group Member

Cloud Security Alliance
Jan 2026 - Present

Contributing to practical guidance on AI threat modeling, security controls, and risk frameworks for enterprise AI, LLM, and agentic systems.

Technologies & Skills
AI Threat ModelingSecurity ControlsRisk Frameworks
OWASP Foundation logo

OWASP GenAI Security Project Contributor

OWASP Foundation
Jan 2026 - Present

Contributing to OWASP initiatives on AI security standards, LLM application security, and secure adoption of agentic AI systems.

Technologies & Skills
AI Security StandardsLLM Application SecurityOWASP
AIUC-1 logo

Founding Consortium Member

AIUC-1
Nov 2025 - Present

Founding member of the AIUC-1 consortium, working with 50 leaders across industry and academia to shape standards for agentic AI governance, security, assurance, and safe production deployment.

Technologies & Skills
AI GovernanceAgentic AIStandards
IE University logo

Adjunct Professor – Artificial Intelligence

IE University
Apr 2025 - Present

Design and teach the MLOps / ML Systems course in the Master in Business Analytics and Data Science, focused on the architecture, operating models, and lifecycle practices required for production-grade AI systems.

Technologies & Skills
ML SystemsMLOpsMLflowAirflowFastAPIEvidently AICloud ArchitectureScalable AIProduction ML
Iberdrola logo

Global Head of AI & Data

Iberdrola
May 2024 - Present

Leading Iberdrola’s Global AI & Data Center, responsible for enterprise AI and GenAI platforms, reference architectures, and the technical controls and assurance needed to run production AI systems worldwide. My mandate is to turn AI into a dependable production capability, moving from isolated PoCs to a repeatable platform and operating model that scales GenAI and agentic AI with controlled risk, cost, and auditability.

Key Achievements
  • Delivered secure production AI foundations across Azure and AWS, enabling RAG and agentic systems with controls for prompt injection, data leakage, evaluation gates, and end-to-end observability.
  • Industrialized reusable building blocks including LLM gateway, retrieval, tracing and telemetry, and policy-as-code guardrails to reduce time to production and improve consistency.
  • Operationalized Responsible AI, AI Security, and assurance evidence through traceability, policy enforcement signals, evaluation controls, and decision records across the delivery lifecycle.
Technologies & Skills
AI StrategyAzureAWSGenerative AIResponsible AIMLOpsMLflowFeature StoreCI/CDData Governance
Mondragon Unibertsitatea logo

Guest Lecturer – Artificial Intelligence

Mondragon Unibertsitatea
Sep 2024 - Present

Deliver guest lectures on Artificial Intelligence for the Master’s in Entrepreneurship & Open Innovation, focusing on how AI, data and experimentation enable new business models.

Technologies & Skills
Artificial IntelligenceEntrepreneurshipOpen Innovation
Iberdrola logo

Global Cloud & AI Architect

Iberdrola
Mar 2023 - May 2024

Led global cloud and AI architecture initiatives across AWS and Azure, defining scalable, enterprise-wide reference architectures and platform foundations. Drove the integration of Generative AI as a first-class capability, accelerating adoption while strengthening security, reliability, and platform standards.

Key Achievements
  • Defined scalable, enterprise-wide reference architectures across AWS and Azure, strengthening security, reliability, and platform standards.
  • Shipped early AI foundations (access patterns, shared services, governance gates) adopted across multiple teams.
  • Defined practical Responsible AI implementation guidance and controls for production delivery.
Technologies & Skills
AzureAWSVector DatabasesPrompt EngineeringMLflowGitHub ActionsCI/CDLLMsGenerative AI
Iberdrola logo

Global Head of Technology – Smart Solutions

Iberdrola
Nov 2018 - Mar 2023

Defined and led the technology strategy, systems architecture, and platform evolution for Iberdrola's Retail Smart Solutions division from inception to scale. Scaled and guided multidisciplinary technology teams delivering smart home, solar, and EV charging solutions to millions of users, introducing early AI-driven automation across customer operations.

Key Achievements
  • Scaled smart solution products to millions of users across multiple countries.
  • Launched internal automation platforms for critical business processes, significantly improving operational efficiency.
  • Increased customer acquisition by significantly improving digital experiences and scalability.
Technologies & Skills
IoTCloud ArchitectureAgile MethodologiesSmart HomeEV ChargingSolar
Iberdrola (Glasgow, UK) logo

Head of Technology – Metering & Industry Processes UK

Iberdrola (Glasgow, UK)
Dec 2015 - Nov 2018

Led the technology function and systems architecture for metering and industry processes in the UK, heading the metering technology teams supporting millions of customers. Defined the technical roadmap for Smart Metering platforms and data-driven operational systems, improving billing accuracy, automation, and operational efficiency.

Key Achievements
  • Defined technical roadmap and architecture for Smart Metering platforms at scale.
  • Introduced advanced analytics and decision-support capabilities for metering operations and forecasting.
  • Significantly reduced billing errors through improved data processing and system integration.
Technologies & Skills
SAP IS-U/CRMSmart MeteringDigital TransformationAdvanced Analytics
Iberdrola (Glasgow, UK) logo

Senior Systems Analyst – Technology Centre of Excellence UK

Iberdrola (Glasgow, UK)
Dec 2013 - Dec 2015

Drove the technical design and integration of large-scale enterprise systems, modernizing complex legacy platforms through integration with SAP IS-U and CRM. Defined scalable integration patterns that improved system reliability, data consistency, and operational visibility across metering operations.

Key Achievements
  • Delivered large-scale consolidation of legacy systems into a unified SAP IS-U/CRM platform.
  • Defined scalable integration patterns improving reliability and data consistency.
  • Improved operational visibility across metering operations.
Technologies & Skills
SAP IS-U/CRMSolution ArchitectureLegacy System MigrationSystems Integration
PwC logo

Technology Strategy Consultant

PwC
Sep 2011 - Dec 2013

Advised IBEX-35 clients on technology strategy, focusing on transformation programs and digitalization initiatives. Designed and led delivery of impactful technology solutions, including an inter-company reconciliation system that streamlined month-end financial processing. Consulted directly with C-level stakeholders to align technology delivery with evolving business needs.

Key Achievements
  • Designed and delivered an inter-company reconciliation system for an IBEX-35 client.
  • Materially reduced month-end financial processing time.
  • Consulted with C-level stakeholders to align technology delivery with strategic business objectives.
Technologies & Skills
Technology StrategyProcess OptimizationEnterprise ArchitectureEnergy Sector
Atos logo

Software Engineer

Atos
Sep 2007 - Aug 2008

Engineered enterprise applications for clients in the energy and insurance sectors. Built a real-time wind-farm monitoring platform for a major Spanish utility. Contributed across the full software development lifecycle, from requirements and architectural design through to implementation, testing, and deployment.

Key Achievements
  • Engineered a real-time monitoring platform for wind farms from the ground up.
  • Implemented a Java EE solution with robust, high-performance data processing capabilities.
  • Delivered the system successfully for a major Spanish utility company.
Technologies & Skills
Java EESoftware DevelopmentReal-time MonitoringOOPEnergy Sector

Architecture & Security Focus Areas

Enterprise AI Architecture

LLM Gateways · RAG Architecture · Agentic Systems · Control Planes · Multi-Agent Orchestration · Evaluation Gates · Policy-as-Code · LLMOps · Observability · Reference Architectures

AI Security Architecture

OWASP LLM & Agentic AI · MITRE ATLAS · CSA MAESTRO · NIST AI RMF · Threat Modeling · Runtime Controls · Guardrails · Retrieval Security · Tool Security · Identity-Scoped Execution · Adversarial Testing · Assurance Evidence

Governance & Compliance

EU AI Act · ISO/IEC 42001 · AI Management Systems · Risk Classification · Audit-Ready Evidence · Delivery Integration

Cloud & Platform

Azure · AWS · GCP · Amazon Bedrock · Azure AI Foundry · Azure Hosted Agents · AWS AgentCore · Databricks · Langfuse · DeepEval

Certifications

Professional Certifications

IriusRisk
Threat Modeling AI/ML Systems

IriusRisk2026

Saïd Business School, University of Oxford
AI Governance

Saïd Business School, University of Oxford2026

University of Michigan
Generative AI: Governance, Policy, and Emerging Regulation

University of Michigan2026

ISACA
Auditing Generative AI: Strategy, Analysis & Risk Mitigation

ISACA2025

DataTalksClub
MLOps Zoomcamp

DataTalksClub2025

DeepLearning.AI
Machine Learning in Production

DeepLearning.AI2025

Hugging Face
AI Agents

Hugging Face2025

Amazon Web Services
Data Engineering Specialization

Amazon Web Services2024

Microsoft
Microsoft Certified: Azure AI Engineer Associate

Microsoft2024

NVIDIA
NVIDIA AI Infrastructure and Operations

NVIDIA2024

Google Cloud
Responsible AI

Google Cloud2024

IBM
Generative AI for Executives and Business Leaders

IBM2024

Kaggle
Computer Vision

Kaggle2024

Amazon Web Services
AWS Certified Solutions Architect – Associate

Amazon Web Services2023

Microsoft
Microsoft Certified: Azure Solutions Architect Expert

Microsoft2023

Microsoft
Microsoft Certified: Azure Administrator Associate

Microsoft2023

HashiCorp
HashiCorp Certified: Terraform Associate

HashiCorp2023

DeepLearning.AI
Generative AI with Large Language Models

DeepLearning.AI2023

Stanford Online
Machine Learning Certificate

Stanford Online2016

Education

Universidad Internacional de La Rioja
Universidad Internacional de La Rioja
2023 - 2024

MSc, Artificial Intelligence

GPA: 4.0/4.0. Thesis: ML/DL classification of hazardous asteroids (European ADELA project). Focus on applied ML and model evaluation across end-to-end AI pipelines.

Skills:Artificial Intelligence (AI) · Deep Learning · Machine Learning · Generative AI
EOI Business School
EOI Business School
2011 - 2013

Executive MSc, Business

Executive MSc focused on business strategy, operating models, and tech-driven transformation.

Skills:IT Business Strategy · Digital Transformation · Business Operations · Leadership
Tilburg University
Tilburg University
2010 - 2011

MSc, Computer Science & Industrial Engineering (Exchange)

International exchange. Computer science, systems engineering, and applied optimization.

Skills:Computer Science · Systems Engineering · Distributed Systems · Software Architecture
University of Deusto
University of Deusto
2004 - 2011

MSc, Computer Science & Industrial Engineering

Dual degree. Final thesis: Scalable peer-to-peer platform in Python (top distinction 10/10). Strong base in distributed systems and software architecture.

Skills:Computer Science · Software Architecture · Distributed Systems · Artificial Intelligence (AI)