Security.
Four offerings for the practice a CISO or head of Security actually buys - governance, posture, evidence. Distinct from DevSecOps (delivery discipline, lives under Engineering) because the buyer, the deliverable, and the KPI are different.
Application Security
Stack we live in
Semgrep · CodeQL · Snyk · Trivy · Grype · OWASP ZAP · Burp Suite · Sigstore · GitHub Advanced Security
- SAST / SCA / secrets baseline across every repo, real triage - not just tickets
- Threat modeling as a code-review gate, not a quarterly workshop
- Vuln management ownership - CVE queue, SLAs, exception governance
- Secure SDLC + code-review governance across product teams
- Dependency risk + SBOM lineage (Sigstore, provenance)
- Runtime AppSec posture (WAF / RASP concepts, egress controls)
- Security champions program - one embedded advocate per squad
A pen test has surfaced the same class of finding twice. Or the CVE queue is 90 days behind. Or you need AppSec that scales past one security engineer holding it all.
AI Security
Stack we live in
Anthropic prompt caching · NVIDIA NeMo Guardrails · Guardrails.ai · Lakera · Rebuff · Presidio · custom eval harnesses
- OWASP LLM Top 10 alignment for shipped AI products
- Prompt-injection defense + output validation as first-class
- Guardrails - PII redaction, jailbreak resistance, cost/rate abuse controls
- Red-teaming LLMs and agents - adversarial eval that measures what breaks
- Agentic system safety - tool sandbox, permission boundaries, kill-switches
- Model supply-chain verification - provenance, signing, third-party model risk
- Data leakage prevention in RAG contexts (training data, retrieval data)
You're shipping an LLM product without red-team coverage. Or an audit is asking about AI risk and you have no story. Or the agent went off-script last week and nobody has a playbook.
Cloud Security
Stack we live in
Wiz · Prisma Cloud · Orca · Steampipe · Cloud Custodian · AWS Config · GCP Security Command Center · HashiCorp Vault · Sops
- CSPM baseline + continuous drift detection
- IAM boundaries as first-class - least-privilege, break-glass, session policies
- Workload identity + KMS discipline (rotation, envelope encryption, key hygiene)
- CIS benchmark alignment + cloud-native compliance mapping
- VPC design, network segmentation, egress control
- Org-level guardrails (SCPs / IAM conditions / Config rules)
- Cloud incident response - detection, triage, forensics playbooks
An IAM audit finding hasn't closed. Or you've had two "we didn't know that bucket was public" moments in a quarter. Or you're migrating clouds and don't want to re-run the mistakes.
Compliance & GRC
Stack we live in
Vanta · Drata · Sprinto · Tugboat Logic · Confluence · custom control frameworks
- Framework selection + scope (SOC 2 / ISO 27001 / HIPAA / DPDP / PCI DSS)
- Control mapping to the engineering reality (not the aspirational reality)
- Evidence collection automation - continuous, not audit-crammed
- GRC tooling stand-up (Vanta / Drata / Sprinto) with real integrations
- Policy authoring in prose someone will actually read
- Audit prep + auditor representation for Type I and Type II
- Control operationalization - a control isn't real until an engineer owns it
A SOC 2 audit is 90 days out and you have no evidence trail. Or a customer is blocking a deal until you're compliant. Or you're on your fifth policy revision and auditors keep finding the same gaps.
More of what we build.
Which posture, which audit, which finding?
Tell us what's on the audit letter or in the pen test report. A principal architect replies within one working day.
Book a call