Advise. Build. Scale.
Security for growing companies shipping AI.
22 Security is John Patota. Security advisory, AI development, and Incident Response from one practitioner.
CISSP · CISM · CISA · CCSP · 8× AWS Certified
Services
Three lines of business.
- 01
Security Advisory
Your team stays on product while I operate or build a program based on your unique business, policies, contractual requirements, and frameworks like SOC 2, ISO 27001, PCI, NIST, HIPAA, and HITRUST. I can conduct a specific defined engagement like creating a gap assessment ahead of a big audit or assess current posture against something like the AWS Well Architected Framework to help you meet annual requirements for external risk assessments. I can also augment the current Security Operations staff providing retainer based hours for things like Third Party Risk Assessments or project work.
Typical engagements: Third Party Risk Assessment retainer, readiness assessment, architecture review, project implementation.
- 02
AI Development
Production AI systems built to your outcomes instead of hype. Agents, RAG pipelines, and LLM features designed using the latest best practices and shipped secure by default. No handoff between the team that builds it and the team that has to secure it.
Typical engagements: agent build-out, LLM feature delivery, AI architecture and guardrails.
- 03
Incident Response
When the stakes are high, you want someone who has been there before. I step in as the responder and contain the compromise, cut off the attacker's access, remove what they left behind, and get you safely back to operating again. When the incident is closed you get a straight account of what happened, what was done, and the specific changes that lower the odds of a repeat.
Typical engagements: incident containment and recovery, post-incident compromise assessment, and hardening.
Why one practitioner
Vision, business sense, and the technical ability to pull it off.
I built the technology programs inside two successful startups full time, then assessed 171 more of them running third-party cyber risk at a Fortune 200 global bank. I know what the enterprise reviewer will ask because I was the reviewer, and I know what your roadmap can absorb because I have shipped one. Graduate training in finance means the security calls arrive as business decisions: priced, sequenced, and tied to growth. Most firms split strategy, building, and hardening across three vendors who never compare notes. Here the advice knows what can actually ship, the builds know how they get attacked, and the findings come with what it will cost to fix.
Track record
Certified on paper. Proven in production.
Healthcare Tech
A POC that won follow-on funding
I owned the backend and architecture of a patient-facing POC while another engineer built the front end. Because it handled real test results, I routed it through Bedrock and Claude rather than a direct third-party API, keeping protected health data inside our own AWS account, and used deterministic lookups so the model explained real results instead of guessing them. Existing investors saw the demo and committed more capital
Mergers and Acquisition
Acquired by our customer
I led our HITRUST r2 assessment from the inside: the gap assessment, remediating the controls that had to pass in each domain, and assembling the evidence for the assessors. That certification won customer trust and gave Optum, already one of our customers, the confidence in our systems to acquire us.
Startup Operations
Saved $1M per year in operations
At an MSSP serving startups, I redesigned how we handled customer equipment. I replaced shipping empty return boxes with QR-code UPS dropoffs, where an employee gets a box and a printed label on the spot, and moved laptop provisioning to zero-touch deployment straight from Apple with Jamf and Apple Business Manager. Together those changes cut roughly a million dollars a year.
Fortune 200 Financial Services
AI-assisted vendor assessments
Every assessment finding at the global bank must cite the exact internal policy line behind it, and confirm the policy applies to vendors rather than just internal teams. I built a Copilot-based notebook for the team grounded in dozens of policies that returned the citation in seconds instead of the old manual hunt. Assessments got faster, and the findings got harder to dispute.
How I work
Project, retainer, or embedded.
Project
Fixed scope and defined deliverables. Includes audit readiness assessments, architecture reviews, implementations, and Incident Response.
Retainer
Ongoing advisory, operations, TPRM, or Incident Response hours at a defined monthly commitment.
Embedded
Deep involvement: full days or weeks for teams needing dedicated security or AI development
Start with a conversation.
The right engagement depends on what you’re building and where the gaps are. A 30-minute call gets us to whether and how I can help.