Book a call

hello@enclave.maxdcloudops.us

Cloud & Platform Security

Hardening we ran, access we governed, and the report we will not sell on its own

A security tooling bill that keeps growing usually means products bought one incident at a time, over a baseline nobody enforced across the accounts underneath. We ran the AWS Security Improvement Program and the CIS Benchmark hardening inside it at a high-volume transaction platform under NDA. Configuration and tooling costs came down about 30%.

At a top-5 US bank we ran AWS Identity Center access for 500+ banking users across 50+ AWS accounts, and provisioning went from days to hours. At the NDA platform we built the company-wide vulnerability management program on CVSS and EPSS prioritization, with SLA enforcement and automation behind it.

We sell that work now as a scoped assessment: identity, network boundaries, data handling, detection coverage. You give us read access to the accounts and two hours of your platform lead. You get back a written finding against those four, a remediation backlog with a named owner and a date on every item, and a working session with both principals. It is the same review that would precede any larger engagement.

  • An AWS review against the Well-Architected Security Pillar: IAM, networking, logging, GuardDuty, Inspector, Security Hub, Config
  • Kubernetes security, assessed on what is already running or designed in before it runs — RBAC, network policy, workload identity, supply chain, runtime posture
  • Security inside the SDLC rather than bolted to the end of it. Volodymyr deployed the DevSecOps toolchain at the NDA platform — SAST, DAST, SCA, image scanning, policy-as-code on the IaC — and built the security function around it
  • Compliance and audit readiness for PCI DSS, HIPAA, SOC 2, and NIST CSF: gap analysis, control mapping, remediation planning
  • A virtual CISO seat, plus training for engineering and DevOps teams

PCI DSS and HIPAA have engagements behind them: Volodymyr led PCI DSS audits and annual recertification, and Max built the HIPAA infrastructure that passed regulatory inspections. SOC 2 and NIST CSF do not. We say so in the proposal. If we cannot get into the accounts and change the IAM boundary the finding names, the document is the entire deliverable, and we would rather not write it.

One engagement here is live rather than employment history. A financial-services client has Volodymyr under contract, through Volonaris Security — his own consultancy — to design their cloud security controls and keep the posture defensible under the regulations they answer to. Separate work under Volonaris put CNAPP and CSPM platforms through a scored proof-of-value, sandbox accounts first and production last, and closed with an executive readout.