Services

Five things I own so your engineers don't have to.

Every engagement is senior-led: you work with me, not a bench. Pick a package where I guide, manage, or execute, or a fixed-scope project with a start and an end date. Either way the deliverable is a program that runs, not a deck.

01 / Fractional CISO leadership

Security leadership before the full-time hire.

I take the seat a CISO would take. I set the roadmap, own the budget conversation, sit in the leadership meeting, and make the calls a first security hire can't make yet. You get the judgement without the $350–450K salary and the four-month search.

Who it's for

Series A–C startups selling to enterprise, mid-market companies that have outgrown "the CTO does security", and companies between CISOs that need continuity without a rushed hire.

Typical deliverables
  • Security strategy and a 12-month roadmap, refreshed quarterly, with owners and cost attached
  • Board and investor reporting: a one-page risk view they can read in five minutes
  • Budget planning: what to buy, what to build, what to stop paying for
  • Vendor risk and due diligence in both directions: your vendors, and your acquirers' and investors' questions about you
  • Incident response plan, escalation structure, and an annual tabletop with leadership in the room
  • Hiring and mentoring your first security hires: job descriptions, interview loops, 90-day plans
01

What the board sees

One page a month. Where the risk is, what changed, what it costs to fix, and who owns it.

Delivered via rm · Guide rm -r · Manage rm -rf · Execute
Typical cadence Weekly leadership sync Monthly exec report Quarterly board update
02 / Compliance programs

Gap assessment to certificate, with evidence that collects itself.

I've run these programs from the vendor side: scoping, policies, control owners, tooling, auditor, remediation. The tooling is the easy part. The program is deciding which evidence matters, who owns each control, and what you tell the auditor when a test fails.

Who it's for

Companies with a signed deal contingent on SOC 2 or ISO 27001, SaaS vendors entering federal or DoD procurement, and teams whose GRC dashboard has been 60% green for months.

Typical deliverables
  • SOC 2 Type I and Type II: readiness, control design, observation window, auditor management through to the report
  • ISO 27001 ISMS build: scope, risk methodology, Statement of Applicability, internal audit, certification audit support
  • FedRAMP authorization support: boundary definition, SSP authoring, control implementation, 3PAO coordination
  • IL4 / IL5 for DoD contracts: impact-level scoping, inherited controls, CUI handling
  • GDPR program: data map, lawful bases, DPAs, DSAR process, DPIA templates
  • ISO 42001 AI management system, built alongside 27001 when AI is in scope
  • Evidence automation and GRC tooling: Vanta, Drata or Secureframe administered so the dashboard means something
  • Auditor selection and management, and remediation tracked to closure
02

SOC 2 Type I readiness, twelve weeks

The realistic version. It holds if leadership commits and tooling is wired in the first two weeks.

Weeks 1–2

Scope and gap

Trust Services Criteria selected, systems inventoried, gap assessment against every control. GRC platform connected to cloud, identity and source.

Weeks 3–5

Policies and owners

Core policies drafted in your voice and approved. Every control gets a named owner. Risk assessment completed and reviewed with founders.

Weeks 6–9

Controls live

MFA, access reviews, change management, logging and vendor reviews operating. Evidence collecting automatically. Failing tests remediated.

Weeks 10–12

Audit

Internal readiness review. Auditor selected and engaged. Type I point-in-time audit performed. Type II observation window opens the same day.

Delivered via Program build · fixed scope rm -r · Manage rm -rf · Execute
Typical cadence Biweekly working sessions Weekly in audit month
03 / AI security & governance

Governance that lets you ship AI to enterprise buyers.

I build internal AI agents and tooling myself, so I review LLM systems as a builder, not a policy author. ISO 42001 and NIST AI RMF provide the structure. The work is inventories, owners, evidence, and a hard look at what your agents can actually reach.

Who it's for

Companies shipping LLM features or agents to customers, teams facing AI questions in due diligence or procurement, and anyone whose prospect just asked for ISO 42001.

Typical deliverables
  • ISO 42001 AI management system: scope, AI policy, impact assessments, roles, certification readiness
  • NIST AI RMF risk assessments per system (Govern, Map, Measure, Manage) with a ranked risk register
  • Model and vendor inventory: every model, provider, data flow and DPA, each with an owner
  • AI acceptable-use policy and training your engineers will actually follow
  • LLM application security reviews: direct and indirect prompt injection, data leakage, tool-call boundaries, agent permissions, output handling
  • AI due-diligence responses for enterprise procurement and investors
03

What an LLM review finds

Findings from a review of a customer-support agent. Each one gets an owner and a fix, not a slide.

Delivered via AI risk assessment · fixed scope rm -r · Manage rm -rf · Execute
Typical cadence One-time review Quarterly re-assessment
04 / Security questionnaires & trust

Answered in 48 hours, from a knowledge base that gets sharper.

A 300-row SIG shouldn't stall an enterprise deal for three weeks. I answer it, attach the evidence pack, flag the three answers that need your CTO, and store every answer so the next one is faster.

Who it's for

Sales teams losing momentum in security review, founders answering questionnaires themselves at midnight, and companies without a trust page who keep getting asked for one.

Typical deliverables
  • SIG, SIG Lite, CAIQ, VSAQ and custom spreadsheets, answered and evidence-backed
  • Security sections of RFPs and RFIs, written to win the deal, not just to comply
  • Answer knowledge base: reusable, versioned, mapped to your controls and policies
  • 48-hour turnaround on standard questionnaires; same week for the 400-row custom ones
  • Trust-page content: security overview, sub-processor list, policy summaries, report request flow
  • Evidence pack ready to send under NDA: SOC 2 report, pentest summary, policies, architecture overview
04

The queue on a Tuesday

Most rows come from the knowledge base. The few that don't get flagged to the right person, with a due date.

Delivered via Per questionnaire · fixed fee rm -r · 2 included / month
Typical cadence 48-hour turnaround Knowledge base refreshed each cycle
05 / Security operations & cloud posture

Built with your engineers, not around them.

I still write Terraform. The operations work is designed to fit your pipeline and your on-call so it survives after I leave: guardrails in code, findings with owners, and runbooks people have actually rehearsed.

Who it's for

Engineering teams on AWS with no dedicated security engineer, companies preparing for their first pentest, and teams whose vulnerability backlog has become a spreadsheet nobody opens.

Typical deliverables
  • Vulnerability management program: scanning, severity SLAs, ownership, and a monthly review that actually closes things
  • SAST, DAST, dependency and secrets scanning wired into CI with tuned rules and blocking thresholds
  • AWS posture: IAM least privilege, S3 public-access blocks, CloudTrail and GuardDuty, Terraform guardrails and policy-as-code
  • Pentest scoping and coordination with a vetted partner; findings triaged and tracked to closure
  • Phishing simulation and security awareness that isn't a compliance checkbox
  • Incident response runbooks per scenario, and tabletop exercises with the people who will actually get paged
05

Posture you can read in a minute

Guardrails enforced in Terraform, findings owned, and a count that goes down month over month.

Delivered via Security assessment · 2 weeks IR retainer rm -r · Manage rm -rf · Execute
Typical cadence Monthly vuln review Annual pentest Annual tabletop
06 / Three ways to buy this

Guide. Manage. Execute.

Every service above is delivered through one of three packages. The only variable is how much of the work sits with me versus your team. Same operator in all three. More flags, more ownership.

rm

Guide

Package 1 · Advisory. You have engineers who can do the work and need someone to point them at the right things, in the right order.

You execute.
I set direction, review, and unblock.
MeYour team
  • CISO leadershipRoadmap, priorities and the board narrative. Your team runs the meetings between mine.
  • ComplianceGap assessment and control mapping. I review your policies and evidence before the auditor does.
  • AI governancePolicy skeleton, a risk-assessment method, design review of your LLM features.
  • QuestionnairesYou draft, I review and flag the answers that will lose the deal.
  • SecOps & cloudArchitecture and posture review. Your engineers ship the fixes.
See pricing
rm -rf

Execute

Package 3 · Embedded. A hard date, a complex program, or no security team at all. I do the work inside your cadence.

I do it.
Weekly cadence, hands on keyboard, incident command.
MeYour team
  • Everything in Manage, plus
  • CISO leadershipActing CISO on the org chart. Due diligence for fundraising or M&A. Hiring your first security team.
  • ComplianceFedRAMP and IL4 authorization programs built and driven: boundary, SSP, 3PAO.
  • AI governanceISO 42001 management system built to certification. LLM fixes shipped with your engineers.
  • QuestionnairesUnlimited within scope. Trust page built and maintained.
  • SecOps & cloudTerraform guardrails and pipeline controls written and merged by me. Incidents led live.
See pricing

Month to month, senior-led, no bench. Each package is scoped around your frameworks, environment and deadline. Numbers, terms and fixed-scope projects are on the pricing page.

07 / Not a fit

Three things I don't do, and who I'll send you to.

I stay inside the frameworks and the work I've actually run. If you need one of these, I'll say so on the first call and make an introduction.

01

A 24/7 SOC or managed detection

I don't run one. I'll help you select an MDR provider, scope the contract, and own the relationship if you want, but the eyes-on-glass work is theirs.

02

A large team on site

rmrfs is one operator with a small partner network for pentesting and audit. If you need ten people badged into your office, you need a firm, not me.

03

A healthcare-first program built around HIPAA

Not my expertise, and I won't pretend otherwise. I'll refer you to a practitioner who lives in that world.

Not sure where to start

Not sure which service you need?

Thirty minutes. Bring the audit date, the questionnaire, or the investor question. You'll leave with a straight answer on scope, a tier and a start date, or a referral if I'm not the right fit.

Prefer to write first? Send a message Or email hiteshjain@rmrfs.com
  • 01Reply within one business day, from me.
  • 02No sales team. You talk to the operator.
  • 03If it's a project, you get a fixed quote. If it's a retainer, you get a tier and a start date.