About FEDLIN
FEDLIN builds and runs security for regulated teams: the controls, the compliance program, the remediation backlog, and the specialized engineering underneath. A compliance platform watches controls that already exist. FEDLIN builds those controls (IAM, pipeline gates, secrets management, infrastructure hardening, and the NIST AI RMF layer for agentic systems) and runs them as the client's embedded security architect, built to attestation grade.
FEDLIN meets a company where it is, all of it built on the NIST 800-53 control substrate the frameworks map back to, drawing on the principal's security work inside regulated environments: identity and access management at Wells Fargo, Charter/Spectrum, and Carolinas HealthCare System, under PCI-DSS and HIPAA; enterprise vulnerability management and security operations at Dollar General; critical-infrastructure vulnerability remediation at Southwest Power Pool under NERC/FERC-CIP; and the enterprise SOC 2 review. Because the work is engineered at the control layer, the same depth carries into what a growing team needs next: FISMA and the 800-53 baseline for selling into government. And where a team is shipping AI, FEDLIN secures that surface too, from agentic pipelines to NIST AI RMF. The throughline across FEDLIN's client work is AI-native SaaS: an education platform taken through its SOC 2 on Vanta; hybrid post-quantum key exchange and SLH-DSA signing running in production on a digital-evidence platform; and the web, API, and authentication surface underneath: authorization review, OWASP Top 10 remediation, and Cloudflare edge hardening.
A decade across IAM, SecOps, vulnerability management, and GRC inside the security programs of regulated organizations: healthcare, financial services, energy, telecom, retail, and corporate enterprise. His background spans both sides of the work: enterprise IAM and access governance at scale, and the hands-on control implementation and evidence pipeline delivery that makes audits close cleanly. He builds the controls and instruments the infrastructure.
He came to AI as a skeptic, more worried about its risk than its value. What changed was a deliberate decision to build with it directly, and the recognition that teams shipping agentic systems still have to prove the controls underneath them hold. Securing that shift, at attestation grade, is what FEDLIN is built on.
That foundation (security work across HIPAA-, PCI-DSS-, SOX-, and NERC/FERC-CIP-regulated environments, on the NIST 800-53 substrate they map back to) now pairs with the AI-native, post-quantum, and sovereign-infrastructure engineering FEDLIN builds and runs. GRC-platform-agnostic (certified on Vanta, registered on Drata), with the engineering as the product.
LinkedInHow FEDLIN Engages
Own the Vulnerability Backlog
FEDLIN takes ownership of the remediation backlog and drives it down: triage, prioritization, and the fixes themselves, tracked to closure. The findings a scan or a pentest surfaces become work that gets done, with the evidence to show it.
Stand Up and Run the GRC Program
FEDLIN builds and runs the compliance program: controls deployed at the infrastructure layer, evidence wired to each requirement, and the program kept continuously audit-ready between windows. SOC 2 today, with ISO 42001 the AI-governance target as a team builds out AI, and the NIST AI RMF layer where it ships agents. On Vanta by default, other platforms where a client requires it.
Deliver Specialized Projects
Point engagements where depth decides the outcome: post-quantum and crypto-agility (cryptographic inventory, ML-KEM and ML-DSA migration), web and API security including agentic and MCP surfaces, penetration testing, and secure-infrastructure engineering and DevSecOps: hardened CI/CD, pipeline security gates, secrets management, and IaC hardening. Scoped and delivered on their own, or folded into the program.
The Approach
Controls are implemented at the infrastructure layer (deployed and running in the environment) and every control produces continuous evidence linked to the specific framework requirement it satisfies. Evidence that holds between audit windows, produced continuously as living artifacts.
Engagements start with a scoping call that establishes which gate the client is entering on and sequences the track from there.
FEDLIN works both directly and as the engineering arm behind primes, partners, and advisors: direct engagements, subcontracting, and teaming as the work calls for it. Built on Vanta by default, other platforms where a client requires it, with the engineering as the product.
Clear the gate that gates your revenue.
A customer's security review, an audit, a compliance deadline: whatever's holding up the business, FEDLIN builds the controls, runs the program, and clears it, so you can focus on what you do best. Start with a scoping call to set the track.