Interim security lead

Keep security moving while you hire.

If you are hiring a full-time security person, I fill the gap until they start: running security day to day, or taking on a specific project. Then I help you hire them and hand the work off.

What the work can be

Day to day, or a specific project.

It can be the work a security lead does every week, or one project with a start and an end.

Day to day

Customer security reviews
Security questionnaires and review calls from your customers and prospects.
Vendor risk
Vetting the vendors and tools you buy.
Policies and evidence
Keeping policies current, and evidence ready between audits.
Architecture reviews
Going through designs and changes with your engineers before they ship.
Vulnerabilities
Triaging scanner findings and working through patches with your team.
Access
Periodic reviews of who has access to what, plus onboarding and offboarding.
Cloud and laptops
Administering your cloud accounts, and the laptops you manage through MDM.
Alerts
Watching alerts, and the first response when one is real.

A specific project

Projects I take on include:

  • Preparing for a SOC 2 audit
  • Moving off an end-of-life CentOS release
  • Getting ready for HITRUST or ISO 27001
  • Standing up a vendor risk program
  • Rolling out zero-touch laptop setup through MDM
  • Setting up logging and guardrails across your AWS accounts

How it runs

From the first week to the hand-off.

  1. 01

    Scoping, if it needs it

    If the work is well scoped, I start on it right away. If it is not, the first weeks go to scoping it with you.

  2. 02

    The work

    I run security day to day, or take on the project, and report to the person your new hire will report to.

  3. 03

    Hiring

    I help you hire your full-time security person: the job description, resume screens, and technical interviews.

  4. 04

    The hand-off

    I work alongside your new hire through their first weeks, then hand the work over in writing.

Term
No minimum
Time
From about one day a week
Hand-off notes
What is done, what is open, and where everything lives

Who does the work

Work I have led from the inside.

Healthcare Tech

A POC that won follow-on funding

I owned the backend and architecture of a patient-facing POC while another engineer built the front end. Because it handled real test results, I routed it through Bedrock and Claude rather than a direct third-party API, keeping protected health data inside our own AWS account, and used deterministic lookups so the model explained real results instead of guessing them. Existing investors saw the demo and committed more capital

Mergers and Acquisition

Acquired by our customer

I led our HITRUST r2 assessment from the inside: the gap assessment, remediating the controls that had to pass in each domain, and assembling the evidence for the assessors. That certification won customer trust and gave Optum, already one of our customers, the confidence in our systems to acquire us.

Startup Operations

Saved $1M per year in operations

At an MSSP serving startups, I redesigned how we handled customer equipment. I replaced shipping empty return boxes with QR-code UPS dropoffs, where an employee gets a box and a printed label on the spot, and moved laptop provisioning to zero-touch deployment straight from Apple with Jamf and Apple Business Manager. Together those changes cut roughly a million dollars a year.

Fortune 200 Financial Services

AI-assisted vendor assessments

Every assessment finding at the global bank must cite the exact internal policy line behind it, and confirm the policy applies to vendors rather than just internal teams. I built a Copilot-based notebook for the team grounded in dozens of policies that returned the citation in seconds instead of the old manual hunt. Assessments got faster, and the findings got harder to dispute.

The business case

Customer reviews, audits, and security work don't pause while you hire. Filling the gap keeps them moving, and the hand-off gives your hire a running start.

The compliance case

Supporting evidence for:

  • SOC 2 CC1.3, CC1.4
  • HIPAA §164.308(a)(2)
  • ISO 27001 A.5.2
  • NIST CSF GV.RR-02
  • NIST 800-53 PM-2

References are to the 2017 Trust Services Criteria for SOC 2, the HIPAA Security Rule at 45 CFR Part 164, ISO/IEC 27001:2022 Annex A, NIST CSF 2.0, and NIST SP 800-53 Rev. 5.

Pricing

Month to month, with no minimum term.

Day-to-day work starts at $6,000 a month, for about one day a week.

How much of the week, and for how many months, depends on what you need. The fee covers the work, the hiring help, and the hand-off.

A specific project is a fixed fee, quoted after a scoping call.

After the hand-off

Keep a responder who knows your environment.

Once your new hire has the work, the incident response retainer gives you priority when something happens, and its prepaid hours go to advising and readiness work when nothing does. The interim work takes the place of the assessment a retainer usually starts with.

Start with a conversation.

The right engagement depends on what you’re building and where the gaps are. A 30-minute call gets us to whether and how I can help.