Enterprise-quality security adapted for growing companies. Clear scope, transparent pricing, measurable results.
I offer specialized security services designed for startups and mid-market companies that need more than basic security but aren't ready to hire a full security team. All services include documentation, knowledge transfer, and a support period after delivery.
I offer services at multiple price points because I remember what it was like starting out. Sometimes you just need an hour of expert advice ($500 advisory session). Sometimes you need a quick security check before a big demo ($2,500 rapid review). And sometimes you need comprehensive security engineering ($15K+ full projects). Start where it makes sense for your stage and budget. Many clients begin with advisory sessions, then move to larger projects once we've built trust and they see the value.
Not every security challenge needs a full engagement. Sometimes you just need expert advice, a second opinion, or guidance on a specific decision.
Technical leaders who need expert guidance on a specific security decision, architecture review, or want a second opinion before committing to a larger initiative.
Each session includes:
Perfect for: Quick decisions, second opinions, spot guidance
Junior to mid-level security engineers wanting to level up their skills, developers transitioning into security roles, or technical leaders building security expertise in their teams.
Topics we can cover:
Each session includes:
(3-month minimum commitment) | Individual sessions: $500/hour (if not doing monthly package)
Startups that need quick security feedback before a demo day, product launch, or customer security questionnaire. Not a full audit, but faster and more affordable than comprehensive assessments.
Each session includes:
Perfect for: Early-stage startups, pre-seed to Series A
Includes: Assessment, report, and 1-hour presentation
Startups preparing for investor due diligence, companies pursuing SOC 2 or ISO 27001 certification, or any business that needs to understand their current security posture.
(Varies based on infrastructure size and compliance requirements) | Includes: Comprehensive assessment, all documentation, and 2 weeks post-delivery support
SaaS companies scaling from 10 → 100+ users with complex permission requirements, businesses building multi-tenant systems, or teams struggling with unmaintainable authorization code.
At Amazon, I partnered with 50+ development teams implementing ABAC and FGAC models:
(Depends on system complexity and integration requirements) | Includes: Full architecture, reference code, implementation support, and 30 days post-launch support
Teams spending too much time on manual security reviews, companies wanting to shift left on security, or engineering organizations that need security integrated into CI/CD.
From my work at Amazon automating security processes:
(Based on scope of automation and infrastructure complexity) | Includes: All tooling, implementation, training, and 60-day refinement period
Companies that experienced or suspect a security breach, businesses needing incident response planning, or organizations wanting a security incident commander on call.
At Amazon and CIA:
Available 24/7 for critical incidents
Companies building AI-powered products, startups using LLMs in production, or businesses needing to secure machine learning pipelines and training data.
(Based on number of models, data sensitivity, and compliance requirements) | Includes: Full assessment, framework implementation, and 3 weeks support
Growing companies needing consistent security expertise without hiring full-time, businesses wanting priority access for emerging issues, or teams that benefit from monthly security reviews.
You get a bank of hours each month to use as needed:
Hours don't roll over, but we plan monthly to ensure efficient use.
All retainers include direct Slack/email access and rollover of up to 5 unused hours per month.
| Your Situation | Recommended Service | Investment | Timeline |
|---|---|---|---|
| "I need quick advice on a specific security decision" | Security Advisory Session | $500 | 1 session |
| "I want to learn security engineering from an expert" | Technical Mentorship | $800/month | Ongoing |
| "We need basic security feedback before launching" | Rapid Security Review | $2,500 | 1 week |
| "We're preparing for investor due diligence" | Security Audit & Compliance | $12K-$25K | 2-4 weeks |
| "Our permissions system is becoming unmaintainable" | IAM Architecture | $15K-$30K | 3-5 weeks |
| "We waste too much time on manual security work" | Security Automation | $18K-$35K | 4-6 weeks |
| "We're building AI-powered features" | AI/ML Security | $20K-$40K | 3-5 weeks |
| "We suspect a security breach" | Incident Response | $5K-$15K | Immediate |
| "We need ongoing security support" | Security Retainer | $3.5K-$12K/mo | Monthly |
Every business has unique security challenges. If your needs don't fit a standard package above, let's discuss a custom engagement.
Additional areas I work in:
I'll work with you to define scope, deliverables, timeline, and pricing that fits your situation.
A: I specialize in AWS, Python, JavaScript/Node.js, PostgreSQL, and most modern development stacks. I'm technology-agnostic and comfortable learning what's needed. If you're using something unusual, let's discuss—I've worked with everything from cutting-edge AI frameworks to legacy mainframe systems.
A: It depends on current project commitments. Typical lead time is 1-2 weeks for new engagements. Emergency incident response can often be prioritized within 24 hours. Retainer clients get immediate priority access.
A: We'll establish clear milestones and check-ins. If scope changes, we handle it through a transparent change order process—you'll always know what you're paying for and why. No surprise bills.
A: Yes. Standard terms for project work are 50% upfront, 50% on delivery. For larger engagements over $20K, we can structure milestone-based payments. Retainers are invoiced monthly in advance.
A: Absolutely. Your security concerns and business details stay confidential. I'll sign your NDA or we can use mine. All work is done under a clear contract with defined scope, deliverables, and terms.
A: Primarily remote, which keeps costs down for you. I'm based in Arlington, VA and can meet onsite for initial kickoffs or critical sessions if you're in the DC/Northern Virginia area.
A: I'll tell you honestly in our first conversation. If I'm not the right person for your needs, I'll likely know someone who is and can make a referral.
A: I've worked extensively with SOC 2, HIPAA, and GDPR requirements, particularly at Amazon where compliance was critical. If you need specialized expertise in CMMC, PCI-DSS, or other frameworks, I can advise or bring in a specialist partner.
A: Every engagement includes a support period (typically 2-4 weeks) for questions and minor adjustments. After that, you own all deliverables and documentation. Many clients convert to retainers for ongoing support.
A: Weekly status updates minimum, plus async updates via Slack/email as needed. For longer engagements, bi-weekly check-in calls. You'll always know what's been done, what's next, and if there are any blockers.