Services

What I deliver

Six practice areas. Professional-grade work your auditor, board, and team can rely on.

👤
vCISO & Advisory
Ongoing security leadership — board reporting, ISMS ownership, certification programs, risk strategy, executive advisory.
vCISORetainerBoard Advisory
🔐
GRC & Compliance
ISO 27001:2022, SOC 2, HIPAA, GDPR, PCI-DSS, EU CRA — gap analysis, policy design, full ISMS build, audit readiness. I own the program, not just the advice.
ISO 27001SOC 2HIPAAGDPRPCI-DSSEU CRA
☁️
Cloud Security
Azure and M365 architecture review, Sentinel SIEM deployment and tuning, Defender configuration, Zero Trust design, IAM hardening.
AzureM365SentinelZero Trust
🔍
Digital Forensics & IR
19+ investigations — systems, email, mobile, Windows event logs, memory forensics, blockchain. Court-ready reports. Fast turnaround.
FTK ImagerAutopsyEnCaseVolatility
📋
Security Documentation
80+ documents — policies, SOPs, incident response playbooks, HLD/MLD reviews, risk assessments, vendor assessments, whitepapers.
PoliciesPlaybooksHLD/MLD
🎓
Security Training
13+ courses — OWASP Top 10, DevSecOps, AI Red Teaming, Secure Coding, Threat Modeling, CI/CD Security, TPRM mentorship.
OWASPDevSecOpsAI Red TeamTPRM

Standards

Frameworks I work with

ISO/IEC 27001:2022ISO 27002ISO 27701ISO 22301SOC 2 Type I/IIHIPAAGDPRPCI-DSSEU Cyber Resilience ActNIST CSFMITRE ATT&CKCIS BenchmarksZero TrustOWASPCOBITISO 42001

Let's discuss your needs.

All engagements start with a free discovery call.