Now accepting new clients $ rm -rf audit-panic/

Enterprise‑grade security. Fractional CISO pricing.

Get the strategic security leadership your organization needs without the $400K+ salary. SOC 2, ISO 27001, FedRAMP, AI governance, delivered by someone who has built and led the teams, not just audited them. Senior operator. Month to month.

Frameworks SOC 2 ISO 27001 FedRAMP IL4 / IL5 GDPR ISO 42001 NIST AI RMF
hitesh@rmrfs — security program — zsh
$rmrfs audit --framework soc2 --type 2
01 / The situation

You're eight weeks from an audit and your CTO is doing security on weekends.

Sound familiar? Every rmrfs engagement starts in one of these four places.

01

The enterprise deal is stuck in security review

A 300-row SIG questionnaire landed in someone's inbox three weeks ago. Nobody owns it. Procurement has stopped replying to your AE.

02

Compliance tooling isn't a compliance program

The Vanta dashboard has been 61% green since March. Nobody knows which controls the auditor will actually pull evidence for, or who is accountable when they do.

03

AI shipped faster than governance

LLM features are in production. There's no model inventory, no AI use policy, and an enterprise prospect just asked about ISO 42001 and prompt-injection testing.

04

A full-time CISO is $350–450K and four months away

At 40 to 300 people you need fifteen senior hours a week, not forty. You need someone who has run the program before, starting this month.

02 / What a retainer actually covers

Leadership, program, and the unglamorous work in between.

Not another slide deck of recommendations. The retainer owns outcomes: audits passed, questionnaires closed, risks retired, and a board that understands what it's paying for.

01

Fractional CISO leadership

Strategy, roadmap, budget, vendor risk, board reporting, and the judgement calls a first security hire can't make yet. I sit in the leadership meeting, not on the sidelines.

02

Compliance programs

SOC 2, ISO 27001, FedRAMP, IL4/IL5, GDPR. Gap assessment to certificate, with evidence that collects itself.

03

AI security & governance

ISO 42001, NIST AI RMF, LLM application reviews, AI use policy. Governance that lets you ship AI to enterprise buyers.

04

Security questionnaires

SIG, CAIQ, VSAQ and the custom 400-row spreadsheet. Answered in 48 hours from a knowledge base that gets sharper every time.

05

Security operations & cloud posture

Vulnerability management, SAST/DAST in the pipeline, AWS posture, incident response plans and tabletops. Built with your engineers, not around them.

Full service detail
03 / Your first 30 days

Discovery, a roadmap you can defend, and quick wins shipped by week two.

The engagement starts from how your company actually runs, not a generic control checklist. By day 30 you have an operating cadence, not a PDF.

Days 1–5

Discovery

Read-only access to cloud, identity and source. I map commitments, critical systems, data flows and deadlines, and interview the people who actually run them.

  • Scope frameworks & systems
  • Provision read-only access
  • Customer & contract commitments
Days 6–15

Risk-ranked roadmap

Gap assessment against your target framework. A 90-day plan with owners and dates. The cheap, high-impact fixes go out immediately.

  • MFA everywhere, stale access revoked
  • Public buckets & secrets cleaned
  • Roadmap reviewed with founders
Days 16–30

Operating cadence

Working sessions start. Policies drafted in your voice, GRC tooling wired to real systems, and the first investor or board update written.

  • Policies & control owners assigned
  • Evidence automation live
  • First exec security report
Day 31 →

The program runs

Audit scheduled. Questionnaires answered in 48 hours. Vendors reviewed on a cadence. Monthly report your board can read in five minutes.

  • Audit & auditor management
  • Monthly risk & metrics review
  • Tabletop exercise each year
04 / Pricing

Choose how much ownership to hand over.

Every tier is senior-led, month to month, scoped around outcomes. Start where you are; move tiers when the audit date or the funding round changes the math.

rm

Advisory

Your team executes. I set direction, review decisions, and keep you honest about risk.

from$2,500/ month
≈10 senior hours · billed monthly
  • Monthly security & risk review
  • 12-month roadmap, refreshed quarterly
  • Policy and control review
  • Audit and compliance guidance
  • Board-ready recommendations
  • Slack/email access, 48-hour SLA
Discuss scope
rm -rf

Embedded

I'm inside your operating cadence. For FedRAMP, IL4, AI-governance builds, tight audit dates or M&A.

Custom
typically $10,000+ / month
  • Everything in Managed, plus
  • Weekly cadence, incident command when needed
  • FedRAMP / IL4 authorization programs
  • ISO 42001 & AI governance build-out
  • Due diligence for fundraising or M&A
  • Hiring and mentoring your first security team
  • Same-day response
Talk through it

Month to month, 30 days notice. Annual billing saves 15%; cancel and the unused balance is refunded pro rata.

Prices are engagement baselines. Final scope depends on your environment, frameworks, and how fast you need to move. One-time assessments and builds are quoted separately below.

Deliberately small

Four retainer seats. 4 open.

rmrfs is a solo practice on purpose: you work with the operator, not a delivery bench. That caps me at four concurrent retainers, so when I'm full I say so instead of subcontracting you out. Ask on the call and you'll get a straight answer on capacity and a start date.

Retainer capacitymax 4 concurrent
open
open
open
open
Engagementmonth to month
Notice period30 days
First replywithin 1 business day
founder / principal
Hitesh
Founder, rmrfs · Engineering Manager over Cloud, SRE, Security & GRC
05 / Who you're working with

Built by an operator, not a slideware consultant.

I've spent 15+ years building and securing production systems: cloud infrastructure, site reliability, security, and governance, risk & compliance. Today I run all four of those functions as an engineering manager at a B2B SaaS company that sells to enterprises and government.

That means I've led SOC 2, ISO 27001, FedRAMP and IL4 programs from the inside, answered the questionnaires that gate enterprise deals, and explained risk to boards in language that drives action. I've also written the Terraform at 2am during an incident. None of this is theory from an audit checklist.

rmrfs exists because too many companies get stuck choosing between a CISO they can't afford and consultants who hand over PDFs nobody implements. The goal of every engagement is independence: a program that runs without me.

15+ yearsinfra · SRE · security · GRC
4 functions ledCloud, SRE, Security, GRC
7 frameworksSOC 2 → ISO 42001
AWS + Terraformhands-on, still
More about how I work
06 / Free tools

Try before you buy.

Self-assessments I use on real calls. No sign-up, no gate, a branded PDF at the end. If the score stings, that's the point.

Live20 questions · 4 min

SOC 2 Readiness Checker

Score yourself across the Trust Services Criteria and see exactly which controls will stall your audit.

Run the check
PDF reportCategory breakdownNo email required
Live15 questions · 3 min

AI Security Risk Scorer

How exposed is your AI usage? Scored against ISO 42001 and NIST AI RMF with prioritised fixes.

Get your score
PDF reportISO 42001 mappedNo email required
All tools, including what's coming
08 / What buyers ask first

Short answers to the discovery-call questions.

If yours isn't here, ask it on the call. I'd rather lose a bad-fit engagement in ten minutes than in month three.

01Who actually does the work on my engagement?

Me. No juniors, no offshore bench, no account manager between us. When scope calls for something I don't do in-house, like a penetration test or 24/7 monitoring, I bring in a vetted partner and tell you before it happens.

02How many hours do I actually get?

Advisory is roughly ten senior hours a month, Managed roughly twenty, Embedded is scoped to the program. I price on outcomes, not timesheets; the hours tell you what cadence to expect, not where I stop.

03Can you get us SOC 2 ready in twelve weeks?

Type I, yes, if leadership is committed and tooling is wired up in the first two weeks. Type II needs an observation window of three to twelve months, so the calendar matters more than effort. You get an honest timeline on the first call, not the one you want to hear.

04Do you replace Vanta, Drata or Secureframe?

No, I make them mean something. Those platforms collect evidence. A program decides which evidence matters, who owns each control, and what you tell the auditor when a test fails. I administer whichever one you already have.

05What about FedRAMP and IL4?

Yes, and it's where most consultants get vague. I've run these programs from the vendor side. You'll get realistic costs, a realistic timeline, and a candid view of whether your architecture is ready. I won't tell you it takes three months.

06What does "AI governance" involve in practice?

A model and vendor inventory, an AI use policy your engineers will actually follow, risk assessments per system using NIST AI RMF, security reviews of LLM applications (prompt injection, data leakage, tool-call boundaries), and an ISO 42001 gap review if certification is on the roadmap.

07Is it really month to month?

Yes. Thirty days notice, no lock-in. Annual billing saves 15% and refunds the unused balance pro rata if you cancel. Start monthly; move to annual once the audit is scheduled if you want the discount.

08When are you the wrong choice?

If you need a 24/7 SOC, a large team on site, or a healthcare-first compliance program built around HIPAA, I'm not your person and I'll point you to someone who is. I stay inside the frameworks I've actually run.

Ready when you are

Tell me what's on fire.

Thirty minutes. If rmrfs isn't the right fit I'll say so and point you toward someone who is. If it is, we'll leave the call with a scope and a start date.

  • 01Reply within one business day, from me.
  • 02No sales team. You talk to the operator.
  • 03Bring the audit date, the questionnaire, or the investor question.
Prefer a calendar? Book a 30-minute call Or email hiteshjain@rmrfs.com
No newsletter, no drip sequence. Just a reply.