I take compliance projects from gap analysis through certification — SOC 2 readiness, HIPAA risk assessments, ISO 27001 certification support, PCI DSS validation, and GDPR/NIST alignment.
Not paperwork-only consulting. I'm CISA certified and AWS Certified Solutions Architect – Professional, with 15 years running production infrastructure — controls get mapped to what's actually deployed, not a generic template.
Track record: led a SOC 2 Type 2 audit to zero major findings, built the evidence collection cadence and automated AWS Config conformance packs. Delivered PCI DSS compliance with zero findings across banking-grade fintech clients. Completed HIPAA PHI audits, including closing an unauthenticated PHI API endpoint before it became an incident.
Included:
- Gap analysis against your target framework
- Evidence collection plan with owners and deadlines
- Policy documentation build-out
- ISO 27001 support through certification body audit
- PCI DSS validation and QSA coordination
- Weekly status tracking
Scope: for SOC 2, I manage readiness and evidence collection — formal attestation comes from a licensed CPA firm, which I coordinate with through sign-off. For ISO 27001, PCI DSS, HIPAA, and GDPR, I work the project through to the certification/compliance outcome.
Let's talk about which framework you're targeting and what stage you're at.