We work across sectors, but the deepest experience is concentrated where reliability and regulatory pressure are highest.
Substation networks, OT/ICS segmentation, FortiGate fleets, Cisco Catalyst 9K, NERC CIP-005/CIP-007/CIP-010 evidence pipelines, VXLAN-over-IPsec for legacy DCS traffic.
Multi-region AWS landing zones, Transit Gateway, Secrets Manager rollouts, compliance-aware Terraform workflows. Audit-ready by design, SOC 2 path-friendly.
HIPAA-aware infrastructure work, particularly around identity, segmentation, audit logging. Selective on ePHI-handling engagements; happy on supporting infrastructure.
Plant-floor OT segmentation, IEC 62443 alignment, vendor remote-access brokering, IT/OT convergence patterns that respect plant uptime.
Distributed branch networks at scale, SD-WAN rollouts, PCI-aware segmentation, store-floor edge with low-touch zero-touch provisioning.
Water, gas, transportation, and other ICS environments where OT-aware engineering applies: hardened firewalls, monitored ports, scheduled-window changes, full rollback plans.
Platform automation, secrets management, GitLab/GitHub CI hardening, pragmatic CloudFront + ACM patterns for marketing and product surfaces. Mid-market through Series-C/D scale.
Law, accounting, and consulting firm IT modernization. Identity hardening, MFA enforcement, audit-ready logging without disrupting partner workflows.
High-throughput edge delivery, content workflow automation, secure remote-collaboration networking for distributed production teams.
The engineering travels. If the work involves networks, cloud, identity, or compliance, we can probably help.