$ modulo --status [ok] fractional ciso ..... security and compliance leadership [ok] ai enablement ....... guardrails · owasp llm top 10 · secure by default [ok] offensive ........... pentest · threat model · code review [ok] compliance .......... soc 2 · iso 27001/42001 · fedramp · pci · hipaa · gdpr principal: matthew marji // toronto, canada
available for engagements

Security that ships
with the product.

Modulo Security builds and runs security programs for engineering-led companies. Fractional CISO leadership, AI enablement, penetration testing, and the compliance work that comes with selling to enterprises.

Most security slows teams down because it arrives as a checkpoint. I build it into how software already gets made, so the secure path is also the fast one.

[01] · where i spend most of my time

when leadership wants to ai all the things

They can. Most of the caveats are security, and a few are budget.

Every exec team has already decided AI is the priority. Engineering adopts it in weeks. Security shows up a year later, once the data flows are built and nobody can say which tools touch what.

The work is making that adoption safe without slowing it down, and without tying you to one vendor. No matter which tool a team picks, the guardrails stay in place.

// 01

Guardrails that survive a tool change

Teams pick their own tools, and they change them every few months. The controls sit in your pipeline instead of inside a vendor, so swapping a model does not undo your security.

// 02

Checks in CI/CD

AI writes code faster than anyone reviews it. The checks run where your code already runs, so AI-written code passes through the same gate as everything else.

// 03

A standard set of security-review skills

One shared set of AI skills any team can pull from, which reviews code for security before it merges. One standard, instead of every team improvising its own.

// 04

Financial guardrails

AI spend gets away from companies quietly. The same standardization caps what gets consumed, so everyone keeps access and finance still recognizes the bill.

// 05

OWASP Top 10 for LLMs

Prompt injection, insecure output handling, data leakage. Threat modeled against your architecture and your agents, not scored against a generic checklist.

// 06

Secure by default

Engineers should not have to make the secure choice. They should get it by taking the normal path, because the normal path is the one that was built properly.

Companies do not need permission to use AI. They need the guardrails that make it defensible.
[02]

what i do

Six things. Most engagements are one or two of them, and they tend to grow into the others.

// 01

Fractional CISO

Senior security leadership for teams that need the strategy, the roadmap, and someone accountable, but not a full-time executive. I own the program, run the vendor and audit relationships, and sit in the rooms where security decisions get made.

  • Board and customer-facing security narrative
  • Roadmap, budget, and hiring plan
  • Risk register that engineering actually reads
// 02

AI enablement & security

Your engineers are already using AI. The job is making that safe without banning it. I set the guardrails, review how models and agents touch your data, and build the approval paths so teams move fast inside a boundary instead of around it.

  • Tool-agnostic guardrails, enforced in CI/CD
  • OWASP Top 10 for LLMs, threat modeled
  • Security and financial guardrails together

Read how this works ›

// 03

Penetration testing

Testing that finds what is genuinely exploitable, then tells you what to fix first. Reports are written for the engineer who has to close the ticket, with a reproduction and a fix, not a scanner dump with severity labels attached.

  • Web app, API, and cloud infrastructure
  • Authentication and authorization depth
  • Retest included once fixes land
// 04

Security program build

The first-security-hire work, without the hire. I have done this from zero more than once: pick the controls that matter at your stage, get them running, and leave a program your team can operate after I step back.

  • Secure SDLC and paved roads
  • IAM, access review, vendor management
  • Incident response you have actually rehearsed
// 05

Compliance & certification

Audits turned into real security instead of a screenshot exercise. I have owned exception-free SOC 2 Type 2, PCI SAQ-D, HIPAA, and GDPR, and built the trust portal that answers customer questions before sales has to ask you.

  • SOC 2 · ISO 27001 · ISO 42001 · FedRAMP · PCI · HIPAA · GDPR
  • Readiness, evidence automation, audit management
  • Framework choice: what you need, not everything
// 06

Security automation

AI agents that do the tedious security work end to end. Vulnerability triage, dependency upgrades, cloud alert validation, and customer questionnaire answers, each with a human only where judgment is required.

  • Autonomous vulnerability triage and fix PRs
  • Bug bounty tier-1 handling
  • Cloud finding validation against live environments
[03]

who you are working with

Matthew Marji. Software engineer by training, a decade writing code, and a security leader since. Most recently the first security hire at WorkOS, the identity platform behind OpenAI and Plaid, where the function grew from one person to a team of eight. Before that, security engineering at Narvar and three years on product security at Auth0, through the Okta acquisition.

Security here is a collaborative function, built with engineering rather than imposed on it. AI-native in practice rather than in pitch: there are agents in production today doing real security work.

More background at matthewmarji.com.

WorkOSAuth0 / OktaNarvarSOC 2 Type 2ISO 27001ISO 42001FedRAMPPCI SAQ-DHIPAAGDPR
basedToronto, CA
workingNorth America / EU
certificationsCISSP · CEH
contactemail
[04]

start a conversation

$ modulo --contact

Tell me what you are building and what is worrying you.

If there is a fit I will say so, and if there is not I will tell you that too, usually with the name of someone better suited. No pitch deck, no discovery sequence.