Engagement playbooks

How engagements work

Three of the most common ways teams bring me in: how each one gets scoped, sequenced, and delivered.

These are engagement models, not client reports. They describe how I scope, sequence, and deliver each type of work, and what I hold the engagement accountable to. Client work is covered by NDA. If you want to dig into specifics from my background, ask me on a call and I'll walk you through it directly.

Security Consulting For: Series A–B SaaS, ~20–60 employees, first audit ahead

Building a Security Program from Zero for a Series A SaaS

The situation

You have a working product and paying enterprise customers BUT no formal security program, no documented controls, and a SOC 2 Type I audit on a six-month deadline. The engineering team is small and can't afford to stop shipping to focus on compliance.

How I'd approach it

Start with a gap assessment against SOC 2 Trust Services Criteria to establish where the biggest risks and gaps actually are. Prioritize controls by audit impact and real risk, not just checkbox status. Work directly with the CTO and engineering lead to design controls that fit the existing tooling rather than forcing a platform migration.

What gets delivered

A lightweight security program covering access management, change management, availability, and incident response. Automated evidence collection via GitHub Actions and AWS Config. Policy documents the team can actually maintain. Pen test procurement and the remediation cycle coordinated end to end.

What success looks like

SOC 2 Type I passed on schedule with no major findings
Audit evidence collected automatically rather than by hand each cycle
Every critical and high-severity gap closed before the audit window
Program structured so Type II readiness is an increment, not a restart
Cloud & Infrastructure For: E-commerce or consumer SaaS with AWS spend that outgrew its architecture

AWS Cost Reduction and Infrastructure Hardening

The situation

AWS spend has grown well past what the workload should cost, often because the infrastructure was built fast during a growth sprint and never revisited. Typically there are also open findings from a recent pentest that got deprioritized behind shipping.

How I'd approach it

A two-week audit of the AWS environment: EC2 sizing, RDS configuration, S3 storage classes, data transfer patterns, NAT gateway usage. Findings are checked against actual traffic patterns to separate true over-provisioning from headroom you genuinely need. Pentest findings are triaged in parallel by exploitability and blast radius.

What gets delivered

Right-sized EC2 fleet, auto-scaling groups with properly configured warm pools, cold S3 data migrated to Glacier Intelligent-Tiering, redundant data transfer eliminated via VPC endpoints. Highest-severity pentest findings remediated first, starting with anything exposing internal service endpoints to the internet.

What success looks like

Meaningful reduction in monthly AWS spend --- commonly 20-40% on environments that have never been audited
Critical and high-severity infrastructure findings closed
Infrastructure scales correctly under peak load instead of being permanently over-provisioned for it
Deployment reliability improved and rollbacks measurably less frequent
Security Consulting / IT & Systems For: Regulated remote-first teams (HIPAA, PHI) around 50-200 employees

Zero Trust Implementation and HIPAA Alignment

The situation

A remote-first company running a largely flat network with wide-open lateral movement between segments. Often the trigger is a red team exercise flagging credential-based attack paths, or a HIPAA review on the calendar. Access was built for a ten-person company and never rebuilt.

How I'd approach it

Map existing identity, device, network, and application access flows before changing anything. Identify the highest-risk access paths first, particularly around PHI stores and internal admin tooling. Design a phased rollout that doesn't disrupt the engineering team's ability to ship.

What gets delivered

Okta with hardware-backed MFA and device trust policies. Network segmentation separating PHI workloads from general engineering infrastructure. Shared service credentials replaced with machine identity using short-lived tokens via Vault. An access review process that runs quarterly without requiring a full-time security engineer.

What success looks like

Shared credential usage eliminated across production systems
PHI network segment fully isolated with documented access controls
Access management ready to withstand a HIPAA review without material findings
Access revocation reduced from days to minutes

Does one of these sound like your situation?

Let's start with a discovery call. We'll scope what you actually need, and we'll tell you if it isn't us.

Schedule a Consultation