Enterprise-quality security adapted for growing companies. Clear scope, transparent pricing, measurable results.
I offer specialized security services designed for startups and mid-market companies that need more than basic security but aren't ready to hire a full security team. All services include documentation, knowledge transfer, and a support period after delivery.
I offer services at multiple price points because I remember what it was like starting out. Sometimes you just need an hour of expert advice ($500 advisory session). Sometimes you need a quick security check before a big demo ($2,500 rapid review). And sometimes you need comprehensive security engineering ($15K+ full projects). Start where it makes sense for your stage and budget. Many clients begin with advisory sessions, then move to larger projects once we've built trust and they see the value.
* All prices shown are estimates and can be customized based on the specific scope and amount of work requested. Final pricing will be provided after discussing your unique requirements.
Not every security challenge needs a full engagement. Sometimes you just need expert advice, a second opinion, or guidance on a specific decision.
Technical leaders who need expert guidance on a specific security decision, architecture review, or want a second opinion before committing to a larger initiative.
Each session includes:
Perfect for: Quick decisions, second opinions, spot guidance
* Price is an estimate and can be customized based on scope
Junior to mid-level security engineers wanting to level up their skills, developers transitioning into security roles, or technical leaders building security expertise in their teams.
Topics we can cover:
Each session includes:
(Subscription) OR $95 - $150/hour (individual sessions) | Tiers: Starter ($150/mo, 2hrs), Professional ($225/mo, 4hrs), Executive ($300/mo, 6hrs)
* Price is an estimate and can be customized based on scope
Startups that need quick security feedback before a demo day, product launch, or customer security questionnaire. Not a full audit, but faster and more affordable than comprehensive assessments.
Each session includes:
Perfect for: Early-stage startups, pre-seed to Series A
Includes: Assessment, report, and 1-hour presentation
* Price is an estimate and can be customized based on scope
Startups preparing for investor due diligence, companies pursuing SOC 2 or ISO 27001 certification, or any business that needs to understand their current security posture.
(Varies based on infrastructure size and compliance requirements) | Includes: Comprehensive assessment, all documentation, and 2 weeks post-delivery support
* Price is an estimate and can be customized based on scope
SaaS companies scaling from 10 → 100+ users with complex permission requirements, businesses building multi-tenant systems, or teams struggling with unmaintainable authorization code.
At Amazon, I partnered with 50+ development teams implementing ABAC and FGAC models:
(Depends on system complexity and integration requirements) | Includes: Full architecture, reference code, implementation support, and 30 days post-launch support
* Price is an estimate and can be customized based on scope
Teams spending too much time on manual security reviews, companies wanting to shift left on security, or engineering organizations that need security integrated into CI/CD.
From my work at Amazon automating security processes:
(Based on scope of automation and infrastructure complexity) | Includes: All tooling, implementation, training, and 60-day refinement period
* Price is an estimate and can be customized based on scope
Companies that experienced or suspect a security breach, businesses needing incident response planning, or organizations wanting a security incident commander on call.
At Amazon and CIA:
Available 24/7 for critical incidents
* Price is an estimate and can be customized based on scope
Companies building AI-powered products, startups using LLMs in production, or businesses needing to secure machine learning pipelines and training data.
(Based on number of models, data sensitivity, and compliance requirements) | Includes: Full assessment, framework implementation, and 3 weeks support
* Price is an estimate and can be customized based on scope
Growing companies needing consistent security expertise without hiring full-time, businesses wanting priority access for emerging issues, or teams that benefit from monthly security reviews.
You get a bank of hours each month to use as needed:
Hours don't roll over, but we plan monthly to ensure efficient use.
All retainers include direct Slack/email access and rollover of up to 5 unused hours per month.
* Price is an estimate and can be customized based on scope
Companies needing focused security review of critical code before deployment, third-party integrations, or high-risk features. Get expert eyes on specific code sections without a full audit.
Small Review: $2,000 (up to 5,000 LOC) | Medium Review: $5,000 (up to 15,000 LOC) | Large Review: $9,000 (up to 40,000 LOC)
* Price is an estimate and can be customized based on scope
Startups building MVP with security from day one, companies scaling beyond initial architecture, or businesses preparing for compliance audits. Get Amazon-proven frameworks adapted to your business.
Strategy Session: $4,000 (1 day, virtual) | Deep Dive: $7,500 (2 days, comprehensive) | Enterprise Package: $11,000 (3 days, on-site)
* Price is an estimate and can be customized based on scope
Development teams needing security education, companies preparing for compliance, or organizations building security culture. Move from reactive to proactive security with hands-on training.
Half-Day Workshop: $2,500 (4 hours, up to 15 participants) | Full-Day Workshop: $4,500 (8 hours, up to 20 participants) | Multi-Day Program: $6,000+ (custom, 2-3 days)
* Price is an estimate and can be customized based on scope
Series A/B companies needing security leadership, businesses pursuing compliance certifications, or organizations scaling security programs. Get part-time Chief Information Security Officer expertise without full-time salary.
All retainers include direct access via Slack/email and first priority for overflow work.
(6-12 month minimum) | Includes: Security leadership, program development, compliance support, and board reporting
* Price is an estimate and can be customized based on scope
High-availability SaaS platforms, healthcare and financial services companies, businesses handling sensitive customer data, or organizations with regulatory response requirements. Get 24/7 access to incident response expertise.
Monthly Retainer: $1,500 (reserves your spot, includes consultations) | Incident Response: $190/hour (only when activated) | Average Total: $2,000-3,500/month
* Price is an estimate and can be customized based on scope
| Your Situation | Recommended Service | Investment | Timeline |
|---|---|---|---|
| "I need quick advice on a specific security decision" | Security Advisory Session | $500 | 1 session |
| "I want to learn security engineering from an expert" | Technical Security Mentorship | $150-$300/mo | Ongoing |
| "We need basic security feedback before launching" | Rapid Security Review | $2,500 | 1 week |
| "We need security review of specific code before deployment" | Security Code Review | $2K-$9K | 1-2 weeks |
| "We're preparing for investor due diligence" | Security Audit & Compliance | $12K-$35K | 2-4 weeks |
| "We need security architecture designed from scratch" | Security Architecture Consulting | $4K-$11K | 1-3 days |
| "Our permissions system is becoming unmaintainable" | IAM & Access Control | $14K-$45K | 3-5 weeks |
| "We waste too much time on manual security work" | Security Automation | $15K-$55K | 4-6 weeks |
| "We're building AI-powered features" | AI/ML Security | $18K-$60K | 3-5 weeks |
| "We suspect a security breach" | Incident Response | $6K-$18K | Immediate |
| "We need security training for our development team" | Security Training & Workshops | $2.5K-$6K | 4-8 hours |
| "We need ongoing security support" | Security Retainer | $4.5K-$13.5K/mo | Monthly |
| "We need part-time security leadership" | Fractional CISO | $6.5K-$18K/mo | 6-12 months |
| "We need 24/7 emergency security access" | Emergency Security Hotline | $1.5K/mo + $190/hr | 24/7 |
Every business has unique security challenges. If your needs don't fit a standard package above, let's discuss a custom engagement.
Additional areas I work in:
I'll work with you to define scope, deliverables, timeline, and pricing that fits your situation.
A: I specialize in AWS, Python, JavaScript/Node.js, PostgreSQL, and most modern development stacks. I'm technology-agnostic and comfortable learning what's needed. If you're using something unusual, let's discuss—I've worked with everything from cutting-edge AI frameworks to legacy mainframe systems.
A: It depends on current project commitments. Typical lead time is 1-2 weeks for new engagements. Emergency incident response can often be prioritized within 24 hours. Retainer clients get immediate priority access.
A: We'll establish clear milestones and check-ins. If scope changes, we handle it through a transparent change order process—you'll always know what you're paying for and why. No surprise bills.
A: Yes. Standard terms for project work are 50% upfront, 50% on delivery. For larger engagements over $20K, we can structure milestone-based payments. Retainers are invoiced monthly in advance.
A: Absolutely. Your security concerns and business details stay confidential. I'll sign your NDA or we can use mine. All work is done under a clear contract with defined scope, deliverables, and terms.
A: Primarily remote, which keeps costs down for you. I'm based in Arlington, VA and can meet onsite for initial kickoffs or critical sessions if you're in the DC/Northern Virginia area.
A: I'll tell you honestly in our first conversation. If I'm not the right person for your needs, I'll likely know someone who is and can make a referral.
A: I've worked extensively with SOC 2, HIPAA, and GDPR requirements, particularly at Amazon where compliance was critical. If you need specialized expertise in CMMC, PCI-DSS, or other frameworks, I can advise or bring in a specialist partner.
A: Every engagement includes a support period (typically 2-4 weeks) for questions and minor adjustments. After that, you own all deliverables and documentation. Many clients convert to retainers for ongoing support.
A: Weekly status updates minimum, plus async updates via Slack/email as needed. For longer engagements, bi-weekly check-in calls. You'll always know what's been done, what's next, and if there are any blockers.