What I offer
Services
Senior-level expertise across security, cloud, software, and IT. Delivered without the overhead of a full-time hire.
Core Services
These four disciplines form the foundation of every engagement.
Security Consulting
Risk assessments, cloud hardening, IAM design, and incident response readiness. Built for how modern organizations operate.
Typical outcomes
- Identify and prioritize real attack surface
- Harden cloud environments and IAM posture
- Prepare for audits, compliance, and incidents
- Reduce mean time to detect and respond
Includes
- Cloud Security Posture Assessment (AWS/GCP/Azure)
- IAM & Least Privilege Review
- Incident Response Readiness
- Vulnerability Assessment & Risk Prioritization
- Security Awareness & Policy Development
Cloud & Infrastructure
AWS architecture, infrastructure-as-code, CI/CD pipelines, and containerization for teams that need reliable, repeatable systems.
Typical outcomes
- Infrastructure that deploys in minutes, not days
- Automated pipelines with built-in security gates
- Predictable costs and right-sized environments
- Self-healing, observable systems
Includes
- AWS Architecture & Migration
- Terraform / OpenTofu IaC
- CI/CD Pipeline Design (GitHub Actions, GitLab CI)
- Kubernetes & Container Orchestration
- Observability & Alerting Setup
Software Engineering
Backend development, API design, systems integrations, and automation tooling built to production quality from day one.
Typical outcomes
- Reliable APIs and integrations that scale
- Automation that eliminates repetitive ops work
- Secure-by-default software practices
- Code that your team can own and maintain
Includes
- Backend Development (Python, Go, Node.js)
- REST & GraphQL API Design
- Third-Party Integrations & Webhooks
- Internal Tooling & Automation Scripts
- Secure SDLC Implementation
IT & Systems
Networking, endpoint management, identity, and MDM for growing teams that need modern IT without an IT department.
Typical outcomes
- Secure, manageable endpoint fleet
- Identity and access built on zero-trust principles
- Network segmentation that limits blast radius
- MFA and passwordless rollout across the org
Includes
- Small Business IT Modernization
- MDM Deployment (Jamf, Intune)
- Identity & SSO (Okta, Google Workspace)
- Network Segmentation & Firewall Review
- Passwordless / MFA Rollout
Specialized Engagements
Targeted projects with clear scope, timeline, and outcomes.
Fractional CTO / Security Lead
Embedded senior leadership for teams that need strategic direction without a full-time executive hire. Weekly or monthly retainer.
Security Program Build-Out
Stand up a lightweight, practical security program aligned to NIST CSF or ISO 27001 - right-sized for your stage.
DevOps-in-a-Box
A complete CI/CD + IaC + monitoring stack, designed and deployed for your team. Includes documentation and runbooks.
Cloud Cost Optimization
Audit your AWS environment for waste, right-size instances, and implement policies that keep spend predictable.
SOC 2 / ISO 27001 Readiness
Gap assessment, evidence collection, and remediation planning so your audit is a confirmation, not a surprise.
Zero Trust Implementation
Identity-first, least-privilege access design across your infrastructure, SaaS, and application layers.
Penetration Test Coordination
Scope, procure, and manage a third-party pen test, then own the remediation with you.
Disaster Recovery & Backup Strategy
Design and test a DR plan that meets your RTO/RPO requirements, with runbooks your team can actually use.
Pricing
How engagements are priced
Most consultancies make you sit through a call before they'll say a number. Here are the ranges up front, so you can tell in thirty seconds whether this is worth your time.
Security Assessment
Typically 2–3 weeks
A defined-scope review of your cloud environment, access model, and exposed surface. The fastest way to find out where you actually stand.
- Prioritized findings report: by real risk, not CVSS theater
- Remediation roadmap you can hand to your engineers
- Walkthrough call with your team
- Fixed fee agreed before any work starts
Most common
Project Engagement
Typically 4–10 weeks
Scoped delivery work: a cloud migration, SOC 2 readiness, a DevOps build-out, a zero trust rollout. Defined outcome, defined price.
- Written scope and milestones before kickoff
- Hands-on implementation, not just recommendations
- Documentation and runbooks your team owns afterward
- Weekly progress checkpoints
Fractional Retainer
Typically rolling, 30-day notice
Ongoing senior capacity: a fractional CTO or security lead. For teams that need judgment on tap rather than a one-off project.
- Agreed monthly hours, from about 10 up to 40
- Standing advisory plus hands-on work
- Architecture and code review as you ship
- Cancel with 30 days notice, no lock-in
Ranges are indicative. Where you land depends on scope, environment size, and timeline. Every engagement gets a written scope and a fixed fee agreed before any work begins, so there are no hourly surprises.
Running a small business? Scopes below these ranges are absolutely possible. A focused review for a ten-person team is a different job than one for a hundred-person team, and it's priced that way. Ask.
Non-profit and partner rates are available. See below if you're an agency or MSP.
Partner work
For agencies, MSPs & dev shops
If a client needs security or cloud depth your team doesn't carry in-house, I'll work as an extension of yours. Under your brand, in your process, on your timeline. The client relationship stays entirely yours.
Typical arrangements are subcontracted project work, an on-call security reviewer for client deliverables, or a named senior engineer for a proposal you're bidding. NDA-friendly, and I don't solicit partner clients directly - ever.
How it works
-
White-label by default
Deliverables carry your branding. I can join client calls as part of your team or stay entirely behind the scenes.
-
No client poaching
Contractual. Your clients are yours. I won't approach them during or after an engagement.
-
$150 – $185 per hour
Partner rate, billed to you not your client. Toward the lower end for committed monthly volume; fixed-fee available for defined projects.
-
Fast to start
NDA and MSA signed same week. For proposals you need to bid now, I can supply a bio and scope language within a day.
Start with a Cloud Security Snapshot
Thirty minutes, screen shared, no prep needed. I'll walk your AWS IAM setup and public-facing surface with you and name the three risks worth fixing first. You get the findings whether or not you ever hire me. It's the fastest way to judge whether I'm any good.
Book a free snapshotNot sure where to start?
Most engagements begin with a free 30-minute call to scope the problem and figure out where I can make the most impact.
Schedule a Free Consultation