$ modulo --status [ok] fractional ciso ..... security and compliance leadership [ok] ai enablement ....... guardrails · owasp llm top 10 · secure by default [ok] offensive ........... pentest · threat model · code review [ok] compliance .......... soc 2 · iso 27001/42001 · fedramp · pci · hipaa · gdpr principal: matthew marji // toronto, canada
available for engagements

Security that ships
with the product.

You are shipping fast, and your engineers are already using AI everywhere. I find where that leaves you exposed, fix it alongside your team, and set the defaults that keep you secure after I step back.

You are not buying advice. I get in the weeds on the architecture and build it with your team.

clients and security roles
[01] · how an engagement works

find the risk, fix it, then stay secure

Most companies know roughly where they are weak. Very few have the time to go and prove it, then close it properly.

You are moving fast, your engineers are using AI everywhere, and nobody has mapped what that actually exposes. None of this is a template, because the work is built against the architecture you actually have.

// 01

Find where the risk actually is

I get inside how you build and ship, then map where your weakest links are.

weakest linksweek 1
prod db reachable from stagingcritical
agent key with org-wide scopecritical
no review on agent-authored PRshigh
your actual setup, not a generic checklist
// 02

Fix it with your team

You are not buying a report. I work in the architecture decisions and in the code, so the fixes land.

fixes shippedwith your team
$ git log --author=marji
✓ scope agent keys per service
✓ authz boundary on billing-api
I write the fix, not a list of recommendations
// 03

Make the secure path the normal path

Engineers should not have to pick the safe option. I build the baseline so the normal path is already the right one.

the normal path
$ create service billing-api
✓ tls, secrets manager, authz scaffold
✓ audit logging wired
secure because it is the default, not a choice
// 04

Stay secure after I step back

Security review runs on every release, so code from a person and code from an agent meet the same standard.

pull request checks#4821
security-reviewhuman
security-reviewagent
secrets scanclean
same gate, same depth — no separate track for the machine
A generic checklist is something anybody can run. The work that matters is built on how your company is actually put together.
[02]

what i do

Most engagements start with one or two of these and grow into the others.

// 01

Fractional CISO

Senior security leadership for teams that need a roadmap and someone accountable, without a full-time executive.

  • Board and customer-facing security narrative
  • Roadmap, budget, and hiring plan
  • Risk register that engineering actually reads
risk registerq3
enforce SSO org-wideeng · oct 3
vendor access reviewops · oct 10
prod access tieringclosed
owned and dated — the register engineering actually reads
// 02

AI enablement & security

Your engineers already use AI. I make that safe without banning it, and keep the bill predictable while you do.

  • Tool-agnostic guardrails, enforced in CI/CD
  • OWASP Top 10 for LLMs, threat modeled
  • Financial guardrails on AI consumption

Read how this works ›

guardrail coverage
copilotenforced
cursorenforced
claude codeenforced
controls live in your pipeline, not in a vendor
// 03

Penetration testing

Testing that finds what is genuinely exploitable, written for the engineer who has to close the ticket.

  • Web app, API, and cloud infrastructure
  • Authentication and authorization depth
  • Retest included once fixes land
findings · web + apiretest incl.
3critical
12high
28medium
ordered by exploitability, not CVSS score
// 04

Security program build

The first-security-hire work, without the hire. I have done this from zero more than once.

  • Secure SDLC and paved roads
  • IAM, access review, vendor management
  • Incident response you have actually rehearsed
program · series a
secure sdlc & paved roadsrunning
iam & access reviewrunning
incident responserehearsed
left operable by your team after I step back
// 05

Compliance & certification

Audits turned into real security instead of a screenshot exercise. I have owned SOC 2 Type 2, PCI SAQ-D, HIPAA, and GDPR.

    • SOC 2
    • ISO 27001
    • ISO 42001
    • FedRAMP
    • PCI
    • HIPAA
    • GDPR
    • Readiness, evidence automation, audit management
    • Framework choice: what you need, not everything
    evidence, collected once
    security program
    SOC 2type 2
    ISO 27001certified
    HIPAAattested
    one control set, mapped to every framework
    // 06

    Security automation

    Agents absorb the tedious security work and triage first, so your people spend their time on what matters.

    • Autonomous vulnerability triage and fix PRs
    • Bug bounty tier-1 handling
    • Cloud finding validation against live environments
    agent runlast 24h
    findings triaged142
    fix PRs opened18
    escalated to a human4
    a human only where judgment is required
    [03]

    who you are working with

    Matthew Marji. Software engineer by training, over a decade writing code and securing software, and a security leader for the last five years. Most recently the first security hire at WorkOS, the identity platform behind OpenAI and Plaid, where I grew the function from one person to eight. Before that I owned the security engineering roadmap at Narvar, and spent three years on product security at Auth0, through the Okta acquisition.

    Security works best when it is built with engineering instead of imposed on it, and what matters most is meeting a company where it actually is. I treat every engagement as if the business were mine, which means learning how you operate before recommending anything. I have agents in production today doing real security work.

    More background at matthewmarji.com.

    [04]

    start a conversation

    $ modulo --contact

    Tell me where things stand and what you want help with.

    No sales pitch. I want a real understanding of your current state first, and then I will be straight about what I can help with. If someone else is better suited to the problem, I will say so and point you to them.