A standing specialty, not an add-on
The security discipline of a large company, sized for a team without one.
- 01Critical priorityMFA not enforced on 6 admin accounts
- 02High priorityLegacy mail protocol (IMAP) still enabled
- 03High priorityForwarding rules to outside addresses
- 04Medium priorityOver-privileged service account
- 05Medium priorityDMARC not enforced (policy p=none)
- Email and account security: a continuous audit of Gmail and Microsoft 365
- Threat detection and response, acting before a break-in spreads
- Incident response: you reach me within 30 minutes on your worst day
- Security audits: a short list of fixes ranked by priority, not a 200-page report
- Compliance readiness: the audit your customers ask for (SOC 2) and a contract requires (CMMC)
- Identity and access hardening: multi-factor, least privilege, locked-down accounts
The seat behind the service
Seven years triaging real attacks, before advising anyone on how to stop them.
This did not start with a slide deck. It started in an enterprise security operations center: seven years working up from SOC analyst to senior analyst, triaging alerts across the stack, writing the detections that catch what the stack misses, and owning incidents end to end. You get an operator who has answered the alert at 2 a.m., not a vendor reading from a datasheet.
Detection engineering
Custom detections written in Microsoft Sentinel (KQL): Azure AD device-registration correlation, an AI and LLM consumption anomaly detector, Snowflake brute-force, and AWS suspicious activity. Response automated with Torq SOAR playbooks.
Incident response
Incidents owned start to finish, from a live PHP web shell to the seven-page briefing that translated it for leadership. The technical work, and the version the board can actually read.
The stack, in production
Cortex XDR, Microsoft Defender, Sentinel, Entra ID, and Intune, plus Proofpoint, Palo Alto, Rapid7, and Critical Start MDR, built on with Python and PowerShell.
Proof
Forty-seven hidden forwarding rules, found in one sweep.
An industrial distributor had no view into its 200-plus mailboxes. A mailbox audit surfaced 47 hidden forwarding rules in the first pass. One had been copying invoices and signed contracts to an outside address for the better part of a year. On another engagement, a network audit found a camera server quietly calling home to an address overseas. The line was cut the same day. And for a defense manufacturer, a filable CMMC Level 1 package came together in weeks, not quarters.
Start the hourLet's talk
Tell me what your team does by hand, or what you want to build.
Or email nicholas@papacorporation.com directly.