Interim security lead
Keep security moving while you hire.
If you are hiring a full-time security person, I fill the gap until they start: running security day to day, or taking on a specific project. Then I help you hire them and hand the work off.
What the work can be
Day to day, or a specific project.
It can be the work a security lead does every week, or one project with a start and an end.
Day to day
- Customer security reviews
- Security questionnaires and review calls from your customers and prospects.
- Vendor risk
- Vetting the vendors and tools you buy.
- Policies and evidence
- Keeping policies current, and evidence ready between audits.
- Architecture reviews
- Going through designs and changes with your engineers before they ship.
- Vulnerabilities
- Triaging scanner findings and working through patches with your team.
- Access
- Periodic reviews of who has access to what, plus onboarding and offboarding.
- Cloud and laptops
- Administering your cloud accounts, and the laptops you manage through MDM.
- Alerts
- Watching alerts, and the first response when one is real.
A specific project
Projects I take on include:
- Preparing for a SOC 2 audit
- Moving off an end-of-life CentOS release
- Getting ready for HITRUST or ISO 27001
- Standing up a vendor risk program
- Rolling out zero-touch laptop setup through MDM
- Setting up logging and guardrails across your AWS accounts
How it runs
From the first week to the hand-off.
- 01
Scoping, if it needs it
If the work is well scoped, I start on it right away. If it is not, the first weeks go to scoping it with you.
- 02
The work
I run security day to day, or take on the project, and report to the person your new hire will report to.
- 03
Hiring
I help you hire your full-time security person: the job description, resume screens, and technical interviews.
- 04
The hand-off
I work alongside your new hire through their first weeks, then hand the work over in writing.
- Term
- No minimum
- Time
- From about one day a week
- Hand-off notes
- What is done, what is open, and where everything lives
Who does the work
Work I have led from the inside.
Healthcare Tech
A POC that won follow-on funding
I owned the backend and architecture of a patient-facing POC while another engineer built the front end. Because it handled real test results, I routed it through Bedrock and Claude rather than a direct third-party API, keeping protected health data inside our own AWS account, and used deterministic lookups so the model explained real results instead of guessing them. Existing investors saw the demo and committed more capital
Mergers and Acquisition
Acquired by our customer
I led our HITRUST r2 assessment from the inside: the gap assessment, remediating the controls that had to pass in each domain, and assembling the evidence for the assessors. That certification won customer trust and gave Optum, already one of our customers, the confidence in our systems to acquire us.
Startup Operations
Saved $1M per year in operations
At an MSSP serving startups, I redesigned how we handled customer equipment. I replaced shipping empty return boxes with QR-code UPS dropoffs, where an employee gets a box and a printed label on the spot, and moved laptop provisioning to zero-touch deployment straight from Apple with Jamf and Apple Business Manager. Together those changes cut roughly a million dollars a year.
Fortune 200 Financial Services
AI-assisted vendor assessments
Every assessment finding at the global bank must cite the exact internal policy line behind it, and confirm the policy applies to vendors rather than just internal teams. I built a Copilot-based notebook for the team grounded in dozens of policies that returned the citation in seconds instead of the old manual hunt. Assessments got faster, and the findings got harder to dispute.
The business case
Customer reviews, audits, and security work don't pause while you hire. Filling the gap keeps them moving, and the hand-off gives your hire a running start.
The compliance case
Supporting evidence for:
- SOC 2 CC1.3, CC1.4
- HIPAA §164.308(a)(2)
- ISO 27001 A.5.2
- NIST CSF GV.RR-02
- NIST 800-53 PM-2
References are to the 2017 Trust Services Criteria for SOC 2, the HIPAA Security Rule at 45 CFR Part 164, ISO/IEC 27001:2022 Annex A, NIST CSF 2.0, and NIST SP 800-53 Rev. 5.
Pricing
Month to month, with no minimum term.
Day-to-day work starts at $6,000 a month, for about one day a week.
How much of the week, and for how many months, depends on what you need. The fee covers the work, the hiring help, and the hand-off.
A specific project is a fixed fee, quoted after a scoping call.
After the hand-off
Keep a responder who knows your environment.
Once your new hire has the work, the incident response retainer gives you priority when something happens, and its prepaid hours go to advising and readiness work when nothing does. The interim work takes the place of the assessment a retainer usually starts with.
Start with a conversation.
The right engagement depends on what you’re building and where the gaps are. A 30-minute call gets us to whether and how I can help.