Operational realities from inside an MSP.
MSP environments compress a decade of enterprise variety into a few years. Every tenant is a new threat model, governance posture, and operating tempo. This is the body of work that shape produced.
Multi-tenant operational exposure
Concurrent client estates spanning regulated finance, healthcare, government, and SMB environments.
Enterprise-scale security operations
Coordinated workflows across 50,000+ endpoints on Windows, Linux, and AIX with cross-team partnership.
Zero-day & remediation coordination
Live coordination across server, application, infrastructure, and cybersecurity teams during active threat windows.
Vulnerability management cadence
Prioritization, remediation tracking, and governance evidence aligned to business risk and audit cycles.
IAM & privileged access governance
CyberArk vault onboarding, session controls, least-privilege design, and access recertification.
Audit-ready governance evidence
Evidence packaging and reporting cadence sufficient for FFIEC, SOX ITGC, ISO 27001, and NIST CSF reviews.
SOC 2 Audit Lead & HIPAA Compliance Review — Government Account
Government-sector engagement requiring both a SOC 2 attestation and a HIPAA compliance review across administrative, physical, and technical safeguards.
Coordinate readiness across distributed control owners, evidence a full Trust Services Criteria mapping, and independently assess HIPAA Security and Privacy Rule posture with actionable remediation.
- Led the government account through a 2025 SOC 2 audit end-to-end — control owner coordination, TSC mapping, evidence collection, and direct auditor engagement
- Performed a HIPAA compliance review against the Security and Privacy Rules covering administrative, physical, and technical safeguards
- Documented gaps and prioritized remediation recommendations for the account team
SOC 2 engagement brought to successful completion; HIPAA posture documented with a clear remediation roadmap for account leadership.