Security Portfolio

Cybersecurity Engineering, Documented by Project

This page presents selected cybersecurity engineering engagements across compliance, identity, cryptography, cloud security, and vulnerability management. Project status is shown throughout.

The projects below involve identity systems, cryptographic infrastructure, compliance frameworks, and vulnerability management. Some are completed engagements; others are still active. Status is noted for each project below.

Compliance, Identity, and Cryptographic Engineering for an Enterprise Cloud Platform

Confidential enterprise clientDelivered

SiegePal supported a large enterprise's cloud-based data analytics platform across three connected areas. The first was a formal gap assessment against FedRAMP and PCI-DSS control frameworks. Controls were mapped against required baselines and verified against live infrastructure, not documentation alone. The second was building a centralized identity federation service. It enabled authentication with external identity providers through SAML 2.0 and OIDC, along with SCIM provisioning and multi-protocol authentication. The third was a data security suite covering dynamic data masking, column-level encryption, and key management across multiple cloud providers. Where gaps were found, SiegePal implemented remediation directly within the platform.

Technologies / Frameworks
FedRAMP (NIST 800-53), PCI-DSS, SAML 2.0, OIDC, SCIM, JWT, Kerberos, TLS 1.2/1.3, PKI, FIPS 140-2, AWS KMS, Azure Key Vault, Google Cloud KMS, HashiCorp Vault
Key capabilities
Control-by-control verification, federated identity architecture, encryption at scale

WaTech Compliance Audit for a Government-Facing AI Platform

AiperionDelivered

Aiperion needed to meet Washington Technology Solutions security principles before onboarding a Washington State government agency. SiegePal conducted the compliance audit and identified the findings. The team worked directly with Aiperion's developers to resolve them ahead of launch. The engagement included a pre-go-live security sign-off, documented ahead of the agency onboarding.

Technologies / Frameworks
WaTech Security Standards (Washington State)
Key capabilities
Jurisdiction-specific compliance audit, direct developer coordination, pre-go-live sign-off

SOC 2 Type II Gap Assessment for a Technology-Focused Family Office

Confidential clientActive

SiegePal is evaluating a family office's technology environment against SOC 2 Type II Trust Services Criteria. The scope covers security, availability, and confidentiality. The engagement includes control mapping and a remediation roadmap ahead of formal audit. The goal is audit readiness, not the certification itself.

Technologies / Frameworks
SOC 2 Type II (AICPA Trust Services Criteria)
Key capabilities
Trust Services Criteria evaluation, control mapping, audit-readiness roadmap

Security Architecture Review for an AI Infrastructure Analytics Platform

Confidential clientActive

SiegePal is reviewing the security architecture of a cloud-based AI infrastructure analytics platform. The assessment covers SOC 2, FedRAMP, and HIPAA requirements, identifying control gaps along the way. It also includes evaluating the platform's cryptographic infrastructure, encryption implementation, and key management practices across its cloud environment. Findings are being turned into prioritized, actionable remediation guidance.

Technologies / Frameworks
SOC 2, FedRAMP (NIST 800-53), HIPAA
Key capabilities
Multi-framework compliance review, cryptographic infrastructure assessment, prioritized remediation guidance

Security Audit and Hardening for an SMB Retail Operation

Confidential clientActive

SiegePal is auditing and hardening the technology stack of a small-to-medium retail business. The scope covers Google Workspace, Shopify, Monday.com, and QuickBooks. It also includes the business's banking and payment platforms, and its domain registrar settings. The engagement also produced foundational documentation: security procedures, a business continuity plan, a disaster recovery plan, and backup procedures.

Technologies / Frameworks
Google Workspace, Shopify, Monday.com, QuickBooks, domain and account hardening
Key capabilities
Cross-platform SMB security hardening, business continuity and disaster recovery planning

Vulnerability Management and DevSecOps Integration

Delivered

SiegePal deployed Snyk and SonarQube for automated security scanning across an enterprise development lifecycle. Both tools were integrated into CI/CD pipelines through GitHub Actions. This ran automated SAST, SCA, and container scans on every pull request and deployment. SiegePal also built triage workflows and severity-based gating to help teams resolve findings faster. Snyk and ArmorCode were used to identify cryptographic weaknesses and dependency vulnerabilities in production code.

Technologies / Frameworks
Snyk, SonarQube, ArmorCode, GitHub Actions, GitLab Pipelines, SAST, SCA
Key capabilities
CI/CD-integrated scanning, severity-based triage, cryptographic weakness detection

Regulatory Forensic Investigation Under Bermuda Monetary Authority Standards

Confidential clientDelivered

SiegePal supported a client subject to Bermuda Monetary Authority oversight during a phishing investigation. The incident involved an Adversary-in-the-Middle attack and session replay activity on financial transaction systems. The engagement required technical forensics alongside incident disclosure obligations under BMA jurisdiction. It also touched related payment and messaging standards affecting the environment.

Technologies / Frameworks
Regulatory forensics, incident disclosure handling
Key capabilities
AiTM and session-replay forensic analysis, regulatory-aware evidence handling. See Incident Response.

Security Architecture and Compliance Readiness for a Cloud Marketplace

Listy.roDelivered

SiegePal assessed Listy.ro's cloud infrastructure, identity and access controls, and data protection practices ahead of anticipated growth. The review covered authentication flows, encryption in transit and at rest, and logging and monitoring posture. The engagement produced a gap analysis against SOC 2 and ISO 27001 readiness criteria. Remediation guidance was scoped for an early-stage marketplace environment.

"The deliverable was structured, technically solid, and immediately actionable for our development team. The SiegePal team combines strong cloud security architecture expertise with practical compliance knowledge. Highly recommended." — Listy.ro, 5.0/5.0
Technologies / Frameworks
SOC 2, ISO 27001
Key capabilities
Cloud infrastructure and IAM review, SOC 2/ISO 27001 gap analysis, growth-stage remediation planning

Have a Specific Requirement?

Explore how SiegePal can support your cybersecurity engineering requirements. For AI engineering work, see the AI Portfolio.

Schedule a Consultation