Penetration testing, secure code review, and AppSec consulting for companies that handle sensitive data, face compliance requirements, or need security work auditors will actually accept.
Core Services
Built for engineering teams who need real security work done fast — not a 90-day enterprise sales cycle.
Comprehensive manual and automated security testing of your web applications and APIs that identifies vulnerabilities before your auditors do. Every report is structured to satisfy SOC 2, HIPAA, and PCI audit requirements.
Whitebox analysis of your application code to find security flaws in logic and implementation. Paired with automated scanning and manual review for complete coverage. Actionable remediation steps with code-level context — not just CVE numbers.
Scanner output is noise until someone who's actually exploited vulnerabilities tells you what matters. I review your SAST, DAST, SCA, and third-party pen test findings and give you a clear, risk-based verdict — real threat or false positive — with exploitability context and a prioritized remediation plan your developers can act on immediately.
Embed security into your development lifecycle before it becomes a compliance problem. Pipeline integration, OWASP ASVS-aligned security standards, custom scanning rules, and threat modeling — the same work delivered across 150+ enterprise applications, available to your team.
Gap assessments and remediation support to prepare your security posture for audits. From authentication standards and encryption policies to SAST pipeline coverage reporting — close gaps before an auditor finds them.
Structured analysis of your application's attack surface before a vulnerability becomes an incident. I work through your architecture, data flows, and trust boundaries to identify where attackers will go — and what your team needs to do about it. Deliverables map directly to STRIDE categories and include prioritized mitigations your engineers can act on in the next sprint.
Credentials & Background
Formerly at NetSPI performing secure code review for major financial institutions and Fortune 500 technology companies. Now independent — bringing that same depth to growing businesses.
A career built across network security, offensive application security, and enterprise AppSec program leadership. Formerly at NetSPI, delivering secure code reviews for major banks and Fortune 500 technology companies. The work here is practitioner-driven — grounded in real codebases, real risk, and real engineering constraints.
Why Work With Me
Secure code reviews for major banks. Pen tests for Fortune 500 tech companies. The same practitioner-led depth — without the staffing layers and retainer markups of a large consulting firm.
Years embedded with engineering teams means reports are actionable — clear remediation steps with code-level context, not just severity scores.
I've triaged thousands of scanner findings. I'll tell you exactly which vulnerabilities are real threats, which are false positives, and what to fix first — saving your team hours of wasted effort.
Most penetration tests delivered in 2–3 weeks. No 90-day enterprise sales cycles. No project management overhead. Just fast, high-quality security work.
Every report is structured to satisfy SOC 2, HIPAA, and PCI audit requirements. Hand it directly to your auditor — no reformatting required.
Hands-on experience with Veracode, Semgrep, Burp Suite Pro, Vulcan, and the CI/CD pipelines your team actually uses — no account managers, no subcontracting, no markup.
Based in Madison, WI. Available in-person across the Midwest or fully remote. You work directly with the engineer doing the work — not a project manager.
Who I Work With
Whether you're preparing for your first audit or tightening a mature security program, I meet you where you are.
Virtual CISO
A dedicated security executive embedded in your business — driving strategy, owning compliance, reporting to leadership — at a fraction of a full-time hire.
Build a program from scratch or mature an existing one. Current-state assessment, risk register, roadmap, and prioritized remediation aligned to your business and compliance goals (NIST CSF, ISO 27001).
Author and maintain the security policies auditors expect — acceptable use, incident response, access control, vendor management — in plain language your team will actually follow.
Translate technical risk into business language. Regular reporting on posture, open risks, compliance status, and program progress — so leadership can make informed decisions.
Own SOC 2, HIPAA, and PCI end-to-end — from audit prep and auditor liaison to evidence collection and continuous control monitoring — so engineering can stay focused on shipping.
Frameworks & Standards
Findings, gaps, and remediation plans translate directly to audit evidence. If your audit, contract, or compliance program requires alignment to a specific standard, I can scope work against it directly.
The organizing framework for vCISO program assessments, risk registers, and executive reporting. Maps your security posture to a language leadership and auditors both recognize.
Referenced in policy development and audit preparation work. Particularly relevant for clients pursuing certification or responding to enterprise vendor security questionnaires.
The control baseline for every secure code review and SAST engagement. Findings are mapped to ASVS requirements — giving your team a verifiable standard to point auditors to, not just a list of issues.
The required baseline for any healthcare SaaS engagement. Gap assessments, technical safeguard reviews, and remediation work are scoped directly against its requirements.
Used to establish a maturity baseline for Secure SDLC engagements. Identifies where your development practices stand today and what a realistic improvement roadmap looks like.
Referenced for clients operating in federal-adjacent environments or pursuing FedRAMP readiness. Also used as a rigorous control reference for mature AppSec program development.
Scoping and assessment support for defense contractors pursuing Level 2 certification. Penetration testing, secure code review, and gap analysis mapped directly to the CMMC practice domains — documented to satisfy third-party assessment requirements.
Working against a different standard? If your audit or contract requires alignment to a framework not listed here — PCI DSS, SOC 2 criteria, CIS Controls, or others — reach out. Most engagements can be scoped and documented to satisfy it.
Energy & Critical Infrastructure
Continuous adversary emulation for utilities, co-ops, water systems, and industrial operators — scoped to the IT/OT boundary, mapped to NERC CIP and IEC 62443, and run so that nothing autonomous ever touches a control network.
Free 30-minute scoping call. You'll leave with honest technical feedback on your application, a compliance-readiness checklist, and a clear plan — whether you end up working with me or not.
Book a Scoping Call