22 Security

Advise. Assess. Respond.
Security for growing companies selling to the enterprise.

22 Security is John Patota. Security advisory, security assessment, and incident response from one practitioner who has built the program, run the enterprise review, and shipped the product.

CISSP · CISM · CISA · CCSP · 8× AWS Certified

Services

Three lines of business.

  1. 01

    Security Advisory

    Your team stays on product while I operate or build a program based on your unique business, policies, contractual requirements, and frameworks like SOC 2, ISO 27001, PCI, NIST, HIPAA, and HITRUST. I can conduct a specific defined engagement like creating a gap assessment ahead of a big audit or assess current posture against something like the AWS Well Architected Framework to help you meet annual requirements for external risk assessments. I can also augment the current Security Operations staff providing retainer based hours for things like Third Party Risk Assessments or project work.

    Typical engagements: Third Party Risk Assessment retainer, readiness assessment, architecture review, project implementation.

  2. 02

    Security Assessment and Penetration Testing

    Enterprise customers, auditors, and insurers all want evidence that someone independent has looked at your environment the way an attacker would. I run internal and external security assessments scoped to what actually matters in your stack: exposed services, web applications and APIs, and your AWS account, with findings validated by hand rather than pasted from a scanner. Reports are written the way an enterprise security reviewer wants to read them, because I was the reviewer. Each finding carries severity, evidence, and a fix your team can ship, and a retest confirms it landed. Engagements deepen from external scanning to full assessment to penetration testing as your customer requirements grow.

    Typical engagements: external attack surface assessment, internal and AWS configuration assessment, annual assessment for SOC 2, ISO 27001, or customer security review, remediation retest.

  3. 03

    Incident Response

    When the stakes are high, you want someone who has been there before. I step in as the responder and contain the compromise, cut off the attacker's access, remove what they left behind, and get you safely back to operating again. When the incident is closed you get a straight account of what happened, what was done, and the specific changes that lower the odds of a repeat.

    Typical engagements: incident containment and recovery, post-incident compromise assessment, and hardening.

Why one practitioner

Vision, business sense, and the technical ability to pull it off.

I built the technology programs inside two successful startups full time, then assessed 171 more of them running third-party cyber risk at a Fortune 200 global bank. I know what the enterprise reviewer will ask because I was the reviewer, and I know what your roadmap can absorb because I have shipped one. Graduate training in finance means the security calls arrive as business decisions: priced, sequenced, and tied to growth. Most firms split the advice, the assessment, and the response across three vendors who never compare notes. Here the advice comes from someone who has shipped and knows what can actually change, the assessment goes after what a real attacker would in your stack, and if something does get through, the responder already knows your environment.

Track record

Certified on paper. Proven in production.

Healthcare Tech

A POC that won follow-on funding

I owned the backend and architecture of a patient-facing POC while another engineer built the front end. Because it handled real test results, I routed it through Bedrock and Claude rather than a direct third-party API, keeping protected health data inside our own AWS account, and used deterministic lookups so the model explained real results instead of guessing them. Existing investors saw the demo and committed more capital

Mergers and Acquisition

Acquired by our customer

I led our HITRUST r2 assessment from the inside: the gap assessment, remediating the controls that had to pass in each domain, and assembling the evidence for the assessors. That certification won customer trust and gave Optum, already one of our customers, the confidence in our systems to acquire us.

Startup Operations

Saved $1M per year in operations

At an MSSP serving startups, I redesigned how we handled customer equipment. I replaced shipping empty return boxes with QR-code UPS dropoffs, where an employee gets a box and a printed label on the spot, and moved laptop provisioning to zero-touch deployment straight from Apple with Jamf and Apple Business Manager. Together those changes cut roughly a million dollars a year.

Fortune 200 Financial Services

AI-assisted vendor assessments

Every assessment finding at the global bank must cite the exact internal policy line behind it, and confirm the policy applies to vendors rather than just internal teams. I built a Copilot-based notebook for the team grounded in dozens of policies that returned the citation in seconds instead of the old manual hunt. Assessments got faster, and the findings got harder to dispute.

How I work

Project, retainer, or embedded.

Project

Fixed scope and defined deliverables. Includes audit readiness assessments, architecture reviews, security assessments, implementations, and Incident Response.

Retainer

Ongoing advisory, operations, TPRM, or Incident Response hours at a defined monthly commitment.

Embedded

Deep involvement: full days or weeks for teams needing dedicated security leadership or hands-on engineering.

Start with a conversation.

The right engagement depends on what you’re building and where the gaps are. A 30-minute call gets us to whether and how I can help.