Arcworks
Practice

Security.

Four offerings for the practice a CISO or head of Security actually buys - governance, posture, evidence. Distinct from DevSecOps (delivery discipline, lives under Engineering) because the buyer, the deliverable, and the KPI are different.

← All practices

Offering

Application Security

Stack we live in

Semgrep · CodeQL · Snyk · Trivy · Grype · OWASP ZAP · Burp Suite · Sigstore · GitHub Advanced Security

The work
  • SAST / SCA / secrets baseline across every repo, real triage - not just tickets
  • Threat modeling as a code-review gate, not a quarterly workshop
  • Vuln management ownership - CVE queue, SLAs, exception governance
  • Secure SDLC + code-review governance across product teams
  • Dependency risk + SBOM lineage (Sigstore, provenance)
  • Runtime AppSec posture (WAF / RASP concepts, egress controls)
  • Security champions program - one embedded advocate per squad
Bring us in when

A pen test has surfaced the same class of finding twice. Or the CVE queue is 90 days behind. Or you need AppSec that scales past one security engineer holding it all.

Offering

AI Security

Stack we live in

Anthropic prompt caching · NVIDIA NeMo Guardrails · Guardrails.ai · Lakera · Rebuff · Presidio · custom eval harnesses

The work
  • OWASP LLM Top 10 alignment for shipped AI products
  • Prompt-injection defense + output validation as first-class
  • Guardrails - PII redaction, jailbreak resistance, cost/rate abuse controls
  • Red-teaming LLMs and agents - adversarial eval that measures what breaks
  • Agentic system safety - tool sandbox, permission boundaries, kill-switches
  • Model supply-chain verification - provenance, signing, third-party model risk
  • Data leakage prevention in RAG contexts (training data, retrieval data)
Bring us in when

You're shipping an LLM product without red-team coverage. Or an audit is asking about AI risk and you have no story. Or the agent went off-script last week and nobody has a playbook.

Offering

Cloud Security

Stack we live in

Wiz · Prisma Cloud · Orca · Steampipe · Cloud Custodian · AWS Config · GCP Security Command Center · HashiCorp Vault · Sops

The work
  • CSPM baseline + continuous drift detection
  • IAM boundaries as first-class - least-privilege, break-glass, session policies
  • Workload identity + KMS discipline (rotation, envelope encryption, key hygiene)
  • CIS benchmark alignment + cloud-native compliance mapping
  • VPC design, network segmentation, egress control
  • Org-level guardrails (SCPs / IAM conditions / Config rules)
  • Cloud incident response - detection, triage, forensics playbooks
Bring us in when

An IAM audit finding hasn't closed. Or you've had two "we didn't know that bucket was public" moments in a quarter. Or you're migrating clouds and don't want to re-run the mistakes.

Offering

Compliance & GRC

Stack we live in

Vanta · Drata · Sprinto · Tugboat Logic · Confluence · custom control frameworks

The work
  • Framework selection + scope (SOC 2 / ISO 27001 / HIPAA / DPDP / PCI DSS)
  • Control mapping to the engineering reality (not the aspirational reality)
  • Evidence collection automation - continuous, not audit-crammed
  • GRC tooling stand-up (Vanta / Drata / Sprinto) with real integrations
  • Policy authoring in prose someone will actually read
  • Audit prep + auditor representation for Type I and Type II
  • Control operationalization - a control isn't real until an engineer owns it
Bring us in when

A SOC 2 audit is 90 days out and you have no evidence trail. Or a customer is blocking a deal until you're compliant. Or you're on your fifth policy revision and auditors keep finding the same gaps.

Next

Which posture, which audit, which finding?

Tell us what's on the audit letter or in the pen test report. A principal architect replies within one working day.

Book a call