Services

Engagements range from a focused one-week assessment to ongoing fractional leadership of your infrastructure and security operations.

Security Assessment & Hardening

A structured review of your external and internal attack surface, your servers and your web applications, aligned with OWASP, CIS Benchmarks and NIST guidance.

I combine automated scanning (Nmap, Greenbone/OpenVAS, Nessus) with manual verification, so you get confirmed findings — not a 300-page scanner dump.

Ideal for: SMBs, startups preparing for audits, teams without an in-house security engineer

What you get

  • Vulnerability assessment (network, hosts, web)
  • Firewall & VPN configuration review
  • Linux / Windows Server hardening (CIS)
  • OWASP Top 10 web application review
  • Executive summary + technical report with CVSS scoring
  • Remediation plan and retest

Infrastructure & Network Engineering

From a single office to dozens of interconnected sites: segmentation, routing, site-to-site and remote-access VPNs, virtualization and monitoring — designed for availability and security from day one.

Ideal for: Multi-site organizations, schools, public-sector and growing companies

What you get

  • Network design & segmentation (VLANs, zones, firewall policy)
  • Site-to-site and remote-access VPN (IPsec, WireGuard, OpenVPN)
  • Dynamic routing (OSPF/BGP) and high availability
  • Virtualization (Proxmox, Hyper-V, VMware) and Docker
  • Monitoring & documentation handover

Cloud Migration & Security

Migration planning and execution, plus configuration audits of existing cloud tenants against CIS and provider best practices. Infrastructure as Code where it makes sense, so the secure baseline is repeatable.

Ideal for: Companies moving on-prem workloads to the cloud or inheriting an unreviewed tenant

What you get

  • Cloud readiness assessment and migration plan
  • Azure / AWS landing zone and identity (SSO, MFA, least privilege)
  • Configuration audit (Prowler, ScoutSuite, Defender for Cloud)
  • Logging, alerting and backup strategy
  • Terraform baselines

Database Administration & Security

Performance tuning, migrations and upgrades, backup and recovery testing, and security hardening of your database estate — including auditing, encryption in transit and least-privilege access.

Ideal for: Teams with business-critical databases but no dedicated DBA

What you get

  • Health check and performance tuning
  • Migration and version upgrades (on-prem or cloud)
  • Backup / restore strategy with recovery tests
  • Hardening: roles, auditing (pgaudit), TLS, row-level security
  • Data-protection compliance review

Need a security assessment, an infrastructure lead or an extra pair of expert hands?

Tell me about your environment and goals. I usually reply within one to two business days.