08
Security Engineering
Security work that's calibrated to your stage — not enterprise theatre. The goal is a codebase that's hard to break, an external assessor that finds nothing, and a certification process that doesn't stall the next round.

What this looks like
Codebase hardening
- SAST (Semgrep, CodeQL) wired into CI as a blocking gate
- Dependency scanning, SBOM, and patch policy (Renovate, Dependabot)
- Secret scanning at commit, pre-receive, and rotation playbooks
- Hardened defaults: authn/authz, headers, input validation, CSP
Internal pentesting & assurance
- Internal pentest in prep for an external CREST/CHECK engagement
- Threat modelling (STRIDE) on the load-bearing flows
- Pen-test remediation tracking through to closure
Compliance readiness
- Cyber Essentials and Cyber Essentials Plus preparation
- SOC 2 Type I / Type II controls mapping
- ISO 27001 ISMS scoping and control selection
What you walk away with
- Internal pentest report + remediation plan
- Cyber Essentials Plus readiness checklist (signed off)
- Secure SDLC document + CI security gates
Tools & tech
Semgrep
CodeQL
Renovate
Trivy
OWASP ZAP
Vanta
Drata
More services
View all →Fractional CTO Leadership
Embedded as your part-time CTO. Own technical direction, unblock the team, and report into the board.
Fundraising & Deal Support
Pre-seed to seed fundraising from the founder's side of the table. Legal, financial, and technical workstreams run in parallel — so you close faster and cleaner.
Product Management
Ship the right features at the right time. Roadmaps tied to real user outcomes, not founder instinct.
Ready to scale your engineering?
Book a 30-minute discovery call. If we're not a fit, I'll tell you on the call — and point you toward someone who is.