Presentation
What I do:
Security Control Assessments: I review your current IT environment against NIST CSF, ISO 27001, and SOC 2 frameworks. I deliver a gap analysis, risk register, and prioritized remediation roadmap so you know exactly where you stand and what to fix first.
GRC Policy Development: I write clear, enforceable security policies tailored to your business: access control, data retention, incident response, change management, acceptable use, and business continuity. These are ready for compliance audits and built from real operational experience—not templates.
Virtual CISO (vCISO) Services: I act as your part-time security leader. Monthly strategy calls, risk register management, policy maintenance, compliance guidance, vendor security reviews, and incident response support. You get executive-level expertise without the full-time cost.
Why work with me:
I bring 5+ years of hands-on infrastructure experience on different types of companies (from smaller businesses to international ones) plus pentesting certifications that let me see security from both sides defender and attacker. I don't just check boxes. I help you build programs that reduce real risk and keep your business moving.
Timeline & investment depends on scope. Hourly, project-based, and monthly retainers available. Let's talk about what you need.
Offered services
Background
technical issues for a SaaS product with a resolution of 100% of issues under SLA.
- Manage customer inquiries, plan and schedule operations for resolutions that require an on-site technician
- Maintained IT asset documentation supporting internal controls and audit trails.
- Resolved 90% of tickets independently using an independent ticketing system.
- Achieved 95%+ SLA compliance through systematic tracking in Jira.
- Documented issue resolutions contributing to knowledge base for consistent control application.
- Partnered with cybersecurity teams to support control implementation during AWS migration.
- Participated in change management, documenting infrastructure updates and assessing security impact.
- Maintained asset inventories and configuration baselines supporting audit readiness.
- Automated provisioning with Terraform/Ansible, saving 20+ hours/month.
