Services
Five ways to work together — as a one-off assessment, an embedded build, or ongoing advisory.
Every engagement is scoped directly with David, not a sales team.
Cloud Security & Architecture
Design and harden environments across AWS, Azure, and GCP. Zero Trust architecture, IAM and Microsoft Entra ID configuration, and secure-by-design cloud migrations — built to hold up under audit, not just under a demo.
DevSecOps & CI/CD Security
Security folded into the pipeline itself: Terraform-driven infrastructure-as-code, GitHub Actions security gates, dependency and vulnerability scanning with Snyk, and secrets management done properly — so security stops being the thing that blocks a release.
Security Operations & SIEM Engineering
SIEM design and tuning across Splunk, Datadog, and Microsoft Sentinel, endpoint protection with CrowdStrike Falcon, and detection engineering that's built around your actual threat model — not a vendor's default ruleset.
Compliance & Governance
ISO 27001 and SOC 2 readiness, audit preparation, and continuous compliance monitoring with tools like Drata — framed as an engineering problem with a paper trail, not a paperwork problem with a deadline.
Fractional Security Leadership
For organisations that need senior security judgement at the table — architecture reviews, board-level risk reporting, vendor evaluation — without the cost or commitment of a full-time CISO hire.
Engagement Models
How the work is structured.
Fixed-scope assessment
A bounded piece of work (e.g. a cloud security review or SOC 2 readiness gap analysis) with a clear deliverable and timeline.
Project-based build
Hands-on implementation work (e.g. a CI/CD security overhaul or SIEM migration) scoped to a defined outcome.
Retained advisory
Ongoing access on a day-rate or monthly-retainer basis for organisations that want continuity rather than a one-off engagement.