Systems Engineering & Agile Architecture

Accountable systems for people who can't afford a mistake.

Avionics-grade engineering discipline, applied to AI-era software — for regulated teams and small practices alike.

Bringing 25 years in software — 15 years of it in Tier-1 aerospace, where I built the security boundary between flight decks and the ground services that update them — and autonomous execution principles to mission-critical delivery, now augmented with AI-assisted SDLC under engineering control. Specializing in Lean optimization, EVMS alignment, multi-agent architecture, and scaling execution across high-compliance environments.

Now: HIPAAPath — guided, audit-ready HIPAA documentation for small practices.

Run a healthcare practice and worried about staff using AI with client data? I do fixed-fee AI + HIPAA readiness assessments →

2.5x

Problem Reports Closed vs. Peer Teams

25%

Schedule Cut — IMS-3500, 24 Months to 18

<5%

EVMS Variance

$25M+

Total Program Scope

Tim Downs Mullen — 25 years in software, 21 in regulated industries, based in Cedar Rapids, Iowa. Avionics at Rockwell Collins / Collins Aerospace (DO-178B/C; EVMS Control Account Manager on $10M+ baselines) · Enterprise Agile transformation at Transamerica · U.S. Marine Corps · Founder, TDM Technologies.

Tim Downs Mullen — avionics-grade engineering, applied to regulated software

I’m Tim Downs Mullen, an engineering leader in Cedar Rapids, Iowa — fifteen years on certified avionics at Rockwell Collins and Collins Aerospace, DO-178B/C DAL B on flight management systems, and the onboard information systems behind Pro Line 4, 21 and Fusion flight decks. I’m a named inventor on U.S. patents. Today I run TDM Technologies and HIPAAPath: self-serve HIPAA compliance for solo and small healthcare practices, where the documentation stays in the practice’s own storage.

Consulting Capabilities

Bridging the gap between strict regulatory requirements and high-velocity Agile execution.

Agile in High-Compliance Spaces

Tailoring SAFe, Scrum, LeSS, and Lean frameworks to operate seamlessly within rigorous regulatory constraints, including DO-178B/C and EAR/ITAR compliance protocols. At small-team scale the frameworks come off and the mechanics stay — sequenced to the constraint, not to a playbook.

Read: what survived on a certified program →

EVMS & Predictable Execution

Directly managing $10M+ in control accounts (Performance Measurement Baselines). Utilizing Earned Value Management Systems to ensure massive portfolios remain within budget and schedule variance.

Systems Architecture & Autonomy

Orchestrated delivery of Rockwell Collins' IMS-3500/6000 onboard software and the Aircraft Information Manager (AIM) service that keeps Pro Line 4, 21, and Fusion flight decks current, leading the core engineering team on the software, connectivity, and SaaS scope of a program that drew 300+ people over its five-year lifecycle.

Autonomous Execution & Coaching

Scaled in the enterprise. Building high-performing engineering teams utilizing the 5 C's Framework and shared vision principles to empower execution at the lowest level.

Read: the 5 C's Framework →

Security Architecture for Certified Systems

I architected and implemented the security for Rockwell Collins' Aircraft Information Manager service and for its interface to the IMS-3500/6000 onboard equipment — the trust boundary where a ground system talks to certified avionics. There was no airworthiness security standard to follow at the time, so the design had to carry its own argument. That is exactly where AI governance sits today: no settled standard, and you still have to show why your controls are sufficient and produce the evidence that they held.

Read: what that looks like pointed at AI agents →

AI-Augmented SDLC for Regulated Industries

Shipping AI-assisted work under engineering control: every work package backed by a published Engineering SOP, a human-vs-AI authorship ledger, so the AI-generated portions can be disclaimed correctly when the work is registered, and a git-verifiable audit trail. Multi-agent architecture and AI governance discipline — the differentiator is not the tooling, it's the auditability.

Read: what breaks when two agents share state →

AI + HIPAA Readiness for Small Healthcare Practices

Your staff are probably already using AI tools — and client data may be going with them. A fixed-fee assessment maps where regulated data actually flows, what your obligations are, and gives you a prioritized, plain-English fix list. Built on the same audit-trail discipline used to certify flight software — by the founder of HIPAAPath. Technical mapping, not legal advice — it gives your compliance counsel something concrete to work from.

Read: where client data actually goes →

See the assessment — what it costs and what you get →

Capabilities & Technical Matrix

Methodologies

  • SAFe / Scrum / Kanban
  • Lean & LeSS Frameworks
  • MBSE Principles
  • V-Model Lifecycle
  • TDD & DevOps
  • The 5 C's Framework

Compliance & Security

  • DO-178B/C
  • ARP4754
  • EAR/ITAR Export Compliance — Export Classification Lead (Export Jurisdiction & Classification Level 2, a Collins/RTX internal certification)
  • HIPAA
  • Ground-to-Aircraft Security Architecture (AIM / IMS-3500/6000)
  • US Patent 8,736,464 — “System and method for presenting a dynamic checklist to the user of a vehicle”; dynamic flight-deck checklists. Sole inventor, Rockwell Collins, granted 2014
  • US Patent 7,471,199 — “Mobile key using read/write RFID tag”; an RFID-based secure-access key. One of four co-inventors, Intermec, granted 2008
  • NIST SP 800-66 (HIPAA Security Rule)

Engineering Stack

  • Python / .NET / C#
  • C++ / Java / ANSI C
  • SysML & UML
  • Jira (Architect)
  • DOORS / Jama
  • Git / SVN / Selenium

AI & Automation

  • Claude Code / Claude API
  • MCP Servers & Hooks
  • Multi-Agent Orchestration
  • Context Engineering
  • Agent Handoff Protocols
  • Human-vs-AI Authorship Ledger (registration-ready disclaimers)

Stakeholder Feedback

Observations from cross-functional teams and matrixed leadership.

Peer feedback from engineering and business colleagues.

"You speak both tech and biz. You mediate and advocate for both sides. The tech guys can say their 'stuff' and you can turn right around and make it so I understand. Then you can hear what I'm saying and tell it to the tech guys in a way that they understand as well."

— Cross-Functional Stakeholder

"Completely and totally outside the box thinking—encourages others to dream bigger. You exhibit patience and zero annoyance, making it completely comfortable to approach you for anything."

— Engineering Team Member

Insights & Case Studies

Tactical methodologies and outcomes from 25 years of driving engineering excellence.

Transamerica One Desktop Initiative Logo
Case Study

Transamerica 'One Desktop'

Demonstrating the Connect and Count pillars: How an enterprise Agile transformation and rigorous SDLC compliance aligned matrixed stakeholders and led to a Best New Initiative award.

Read Case Study →
Practitioner Essay

Six Practices Survived a Certified Program

Twelve years as the Agile guy, most of it where you can't skip a document. When every ceremony competes with certification evidence, you find out fast which practices are load-bearing — and which ones only a reporting line would miss.

Read the Essay →
Plain-English Guide

Where Client Data Goes When Staff Use AI

For practices and firms, no jargon: the four ordinary ways client and patient data slips out through everyday AI tools, what HIPAA actually asks of you, and a five-step fix you can start this week.

Read the Guide →
Field Report

Externalized Memory

Your agent forgets everything; your filesystem doesn't. One on-disk state file per project as the single source of truth — the scars from making it trustworthy, and why git, not the file, is the ground truth.

Read Field Report →
Field Report

Fail-Closed AI Agents

Prose tells an AI agent to behave. A gate makes it. Why I moved agent governance out of the system prompt and into the tool boundary — fail-open vs. fail-closed, two war stories, and the audit trail you get for free.

Read Field Report →
{ }
Case Study

Multi-Agent Handoff Protocol

What breaks when you give two AI agents a shared notepad, and the architecture that fixed it. Context rot, junk drawer handoffs, and cross-project contamination — three failure modes with one root cause.

Read Case Study →
5 C's Framework
Whitepaper

The 5 C's Framework

Fostering Connect, Count, Capable, Courage, and Choice (Autonomy & Ownership) in highly regulated environments. Scaling autonomous execution by shifting from blame-oriented 'Why' to discovery-oriented 'What' questions.

Read Whitepaper →
Slide Deck Image
Slide Walkthrough

Implementing the 5 C's

An executive briefing and tactical rollout strategy for embedding the 5 C's across traditional waterfall and V-Model lifecycles, accelerating delivery without sacrificing DO-178B/C compliance.

View Slide Deck →