Services#

I take on a small number of consulting clients through my company, Brooks Security LLC. The work is built around one thing I do end to end: a full-stack SOC 2 compliance program. I write the policy, write the Terraform and Ansible that enforce it in your cloud, and produce the evidence the auditor signs off on.

  • Compliance Program: SOC 2, written and implemented, in 90 days. A fixed-fee project to get you audit ready, with a monthly retainer behind it to keep the program running. This is the offer.
  • SOC 2 for Startups: Your enterprise deal is blocked on SOC 2. The fast, defensible path through Type 1 and Type 2, with controls built in AWS as code.
  • Security Consulting: The full picture of the security and GRC work behind the program: policies and procedures, risk management, cloud security, and vulnerability management.
  • Operations Consulting: The supporting capability. Infrastructure and configuration as code, CI/CD, cloud cost optimization, and reliability engineering.

One thing worth saying up front, because it comes up constantly: a lot of teams are racing to hand this work to AI and let their people go. I use AI heavily myself, but the whole point is having an experienced practitioner steering it. AI plus a seasoned human is powerful. AI on its own will confidently build you something broken. There’s more on that under Security Consulting.

I keep my client list short on purpose, so the work stays hands-on and the quality stays high. If that sounds like what you need, I’d like to hear what you’re working on.

See the offer →