Standing up a first security program for a global SaaS provider
Established the first information security program at a SaaS travel-technology company, including PCI-DSS and NIST SP 800-53 compliance and an enterprise threat and vulnerability management program.
A hosting and SaaS provider handling travel and payment data for large customers had grown faster than its security function. Customers were starting to ask questions the company could not answer.
Approach
Built the program from policy up: governance, PCI-DSS and NIST 800-53 compliance, and a threat and vulnerability management practice, then hired the team to run it.
Served as the security face to customers, answering assessments and running vendor security reviews so security became a sales asset rather than a blocker.
A multi-tenant Slack alternative in production at cinchme.app, with tenant isolation proven in the database, a browser suite run against the production image, and a release gate that refuses to promote traffic without evidence.
A risk and compliance program aligned to ISO 27001, HITRUST, HIPAA, GDPR, and UK Cyber Essentials that certified on the first pass and opened more than a billion dollars of revenue.