Advise. Build. Scale.
Security for growing companies shipping AI.
22 Security is John Patota. Security advisory, AI development, and red teaming from one practitioner.
CISSP · CISM · CISA · CCSP · 3× AWS Certified
Services
Three lines of business.
- 01
Security Advisory
Every serious B2B deal now runs through a security review and probably at least one audit certificate. Your team stays on product while I build and operate a program based on your unique business, contractual requirements, and frameworks like SOC 2, ISO 27001, PCI, NIST, HIPAA, and HITRUST. For teams past seed that need a security function before a full-time CISO makes sense.
Typical engagements: fractional CISO retainer, readiness assessment, architecture review.
- 02
AI Development
Production AI systems built to your outcomes instead of hype. Agents, RAG pipelines, and LLM features designed using the latest best practices and shipped secure by default. No handoff between the team that builds it and the team that has to secure it.
Typical engagements: agent build-out, LLM feature delivery, AI architecture and guardrails.
- 03
AI Red Teaming
Protect your customers and your brand by staying out of the headlines. Adversarial testing for LLM products and agents. Prompt injection, data exfiltration, tool abuse, agent-boundary escapes, mapped to the OWASP LLM Top 10 and tested by someone who builds these systems for a living. You get reproducible attack chains with fixes, not a scanner export.
Typical engagements: pre-launch AI assessment, recurring red-team retainer.
Why one practitioner
Vision, business sense, and the technical ability to pull it off.
I built the technology programs inside two successful startups full time, then assessed 171 more of them running third-party cyber risk at a Fortune 200 global bank. I know what the enterprise reviewer will ask because I was the reviewer, and I know what your roadmap can absorb because I have shipped one. Graduate training in finance means the security calls arrive as business decisions: priced, sequenced, and tied to growth. Most firms split strategy, building, and hardening across three vendors who never compare notes. Here the advice knows what can actually ship, the builds know how they get attacked, and the findings come with what it will cost to fix.
Track record
Certified on paper. Proven in production.
Healthcare Tech
A POC that won follow-on funding
I owned the backend and architecture of a patient-facing POC while another engineer built the front end. Because it handled real test results, I routed it through Bedrock and Claude rather than a direct third-party API, keeping protected health data inside our own AWS account, and used deterministic lookups so the model explained real results instead of guessing them. Existing investors saw the demo and committed more capital
Mergers and Acquisition
Acquired a company, then acquired by our customer
I ran the due diligence and led the technology integration when we acquired Joyable, moving them from AWS into our GCP environment. I also led our HITRUST r2 assessment from the inside: the gap assessment, remediating the controls that had to pass in each domain, and assembling the evidence for the assessors. That certification won customer trust and gave Optum, already one of our customers, the confidence in our systems to acquire us.
Startup Operations
Saved $1M per year in operations
At an MSSP serving startups, I redesigned how we handled customer equipment. I replaced shipping empty return boxes with QR-code UPS dropoffs, where an employee gets a box and a printed label on the spot, and moved laptop provisioning to zero-touch deployment straight from Apple with Jamf and Apple Business Manager. Together those changes cut roughly a million dollars a year.
Fortune 200 Financial Services
AI-assisted vendor assessments
Every assessment finding at the global bank must cite the exact internal policy line behind it, and confirm the policy applies to vendors rather than just internal teams. I built a Copilot-based notebook for the team grounded in dozens of policies that returned the citation in seconds instead of the old manual hunt. Assessments got faster, and the findings got harder to dispute.
How I work
Project, retainer, or embedded.
Project
Fixed scope and defined deliverables. Includes readiness assessments, architecture reviews, implementations, and AI red-team engagements. Typically 2 to 8 weeks.
Retainer
Ongoing advisory, operations, or red-team hours at a defined monthly commitment. How most fractional CISO work runs.
Embedded
Deep involvement: full days or weeks for teams needing dedicated security or AI development
Start with a conversation.
The right engagement depends on what you’re building and where the gaps are. A 30-minute call gets us to whether and how I can help.