What the board sees
One page a month. Where the risk is, what changed, what it costs to fix, and who owns it.
Every engagement is senior-led: you work with me, not a bench. Pick a package where I guide, manage, or execute, or a fixed-scope project with a start and an end date. Either way the deliverable is a program that runs, not a deck.
I take the seat a CISO would take. I set the roadmap, own the budget conversation, sit in the leadership meeting, and make the calls a first security hire can't make yet. You get the judgement without the $350–450K salary and the four-month search.
Series A–C startups selling to enterprise, mid-market companies that have outgrown "the CTO does security", and companies between CISOs that need continuity without a rushed hire.
One page a month. Where the risk is, what changed, what it costs to fix, and who owns it.
I've run these programs from the vendor side: scoping, policies, control owners, tooling, auditor, remediation. The tooling is the easy part. The program is deciding which evidence matters, who owns each control, and what you tell the auditor when a test fails.
Companies with a signed deal contingent on SOC 2 or ISO 27001, SaaS vendors entering federal or DoD procurement, and teams whose GRC dashboard has been 60% green for months.
The realistic version. It holds if leadership commits and tooling is wired in the first two weeks.
Trust Services Criteria selected, systems inventoried, gap assessment against every control. GRC platform connected to cloud, identity and source.
Core policies drafted in your voice and approved. Every control gets a named owner. Risk assessment completed and reviewed with founders.
MFA, access reviews, change management, logging and vendor reviews operating. Evidence collecting automatically. Failing tests remediated.
Internal readiness review. Auditor selected and engaged. Type I point-in-time audit performed. Type II observation window opens the same day.
I build internal AI agents and tooling myself, so I review LLM systems as a builder, not a policy author. ISO 42001 and NIST AI RMF provide the structure. The work is inventories, owners, evidence, and a hard look at what your agents can actually reach.
Companies shipping LLM features or agents to customers, teams facing AI questions in due diligence or procurement, and anyone whose prospect just asked for ISO 42001.
Findings from a review of a customer-support agent. Each one gets an owner and a fix, not a slide.
A 300-row SIG shouldn't stall an enterprise deal for three weeks. I answer it, attach the evidence pack, flag the three answers that need your CTO, and store every answer so the next one is faster.
Sales teams losing momentum in security review, founders answering questionnaires themselves at midnight, and companies without a trust page who keep getting asked for one.
Most rows come from the knowledge base. The few that don't get flagged to the right person, with a due date.
I still write Terraform. The operations work is designed to fit your pipeline and your on-call so it survives after I leave: guardrails in code, findings with owners, and runbooks people have actually rehearsed.
Engineering teams on AWS with no dedicated security engineer, companies preparing for their first pentest, and teams whose vulnerability backlog has become a spreadsheet nobody opens.
Guardrails enforced in Terraform, findings owned, and a count that goes down month over month.
Every service above is delivered through one of three packages. The only variable is how much of the work sits with me versus your team. Same operator in all three. More flags, more ownership.
Package 1 · Advisory. You have engineers who can do the work and need someone to point them at the right things, in the right order.
Package 2 · Managed. You want the security and compliance program owned end to end by someone who has run one before.
Package 3 · Embedded. A hard date, a complex program, or no security team at all. I do the work inside your cadence.
Month to month, senior-led, no bench. Each package is scoped around your frameworks, environment and deadline. Numbers, terms and fixed-scope projects are on the pricing page.
I stay inside the frameworks and the work I've actually run. If you need one of these, I'll say so on the first call and make an introduction.
I don't run one. I'll help you select an MDR provider, scope the contract, and own the relationship if you want, but the eyes-on-glass work is theirs.
rmrfs is one operator with a small partner network for pentesting and audit. If you need ten people badged into your office, you need a firm, not me.
Not my expertise, and I won't pretend otherwise. I'll refer you to a practitioner who lives in that world.
Thirty minutes. Bring the audit date, the questionnaire, or the investor question. You'll leave with a straight answer on scope, a tier and a start date, or a referral if I'm not the right fit.