About FEDLIN
FEDLIN builds and runs security for regulated teams: the controls, the compliance program, the remediation backlog, and the specialized engineering underneath. A compliance platform watches controls that already exist. FEDLIN builds those controls (IAM, pipeline gates, secrets management, infrastructure hardening, and the NIST AI RMF layer for agentic systems) and runs them as the client's embedded security architect, built to attestation grade.
FEDLIN meets a company where it is, all of it built on the NIST 800-53 control substrate the frameworks map back to, drawing on the principal's security work inside regulated environments: identity and access management at Wells Fargo, Charter/Spectrum, and Carolinas HealthCare System, under PCI-DSS and HIPAA; enterprise vulnerability management and security operations at Dollar General; critical-infrastructure cryptographic-controls remediation at Southwest Power Pool under NERC/FERC-CIP; and the enterprise SOC 2 review. Because the work is engineered at the control layer, the same depth carries into what a growing team needs next: FISMA and the 800-53 baseline for selling into government. And where a team is shipping AI, FEDLIN secures that surface too, from agentic pipelines to NIST AI RMF. The throughline across FEDLIN's client work is AI-native SaaS: an education platform in a SOC 2 engagement underway on Vanta; hybrid X25519+ML-KEM-768 key exchange deployed at the edge and SLH-DSA (FIPS 205) implemented for long-lived signatures; and the web, API, and authentication surface underneath: authorization review, OWASP Top 10 remediation, and Cloudflare edge hardening.
A decade across IAM, SecOps, vulnerability management, and GRC inside the security programs of regulated organizations: healthcare, financial services, energy, telecom, retail, and corporate enterprise. His background spans both sides of the work: enterprise IAM and access governance at scale, and the hands-on control implementation and evidence pipeline delivery that makes audits close cleanly. He builds the controls and instruments the infrastructure.
He came to AI as a skeptic, more worried about its risk than its value. What changed was a deliberate decision to build with it directly, and the recognition that teams shipping agentic systems still have to prove the controls underneath them hold. Securing that shift, at attestation grade, is what FEDLIN is built on.
That foundation (security work across HIPAA-, PCI-DSS-, SOX-, and NERC/FERC-CIP-regulated environments, on the NIST 800-53 substrate they map back to) now pairs with the AI-native, post-quantum, and sovereign-infrastructure engineering FEDLIN builds and runs. GRC-platform-agnostic (certified on Vanta, registered on Drata), with the engineering as the product.
LinkedInWho We're For
Teams that are regulated, running a modern stack, and open to governed AI in their environment. Most often one of two shapes:
Commercial, under PCI DSS
The v4.0.1 requirement for a documented cryptographic inventory (Requirement 12.3.3, in force since March 2025) put your cipher suites and protocols on a clock. A CBOM and a sequenced migration plan is the answer.
Federal and their subcontractors, under FISMA
CNSA 2.0 and the post-quantum timeline set the deadline. FEDLIN delivers the crypto-readiness engineering behind your prime.
When a mandate, an audit question, or a customer requirement puts your cryptography on a deadline, that is the conversation to have.
How We Work
FEDLIN is a principal-led security-engineering practice, and it is AI-native by method. Frontier coding assistants and large language models are part of how the work gets delivered, run under governed, in-boundary controls: the same NIST AI RMF discipline we build for you. We performed these engagements before these tools existed. The tools multiply proven judgment. The judgment came first.
We work inside your boundary, with governed AI in the toolchain, and we adapt to your own infrastructure. It's how a lean team moves fast and deep inside a regulated environment. Where your environment can't accommodate governed AI, we work within its limits.
How FEDLIN Engages
Map and Migrate the Cryptography
The spine of the engagement. FEDLIN inventories a system's live cryptography as a CBOM and delivers a sequenced post-quantum migration (ML-KEM and ML-DSA), mapped to CNSA 2.0 and PCI DSS Requirement 12.3.3, and engineered for crypto-agility so the next migration is a configuration change.
Stand Up and Run the GRC Program
FEDLIN builds and runs the compliance program: controls deployed at the infrastructure layer, evidence wired to each requirement, and the program kept continuously audit-ready between windows. SOC 2 today, with ISO 42001 the AI-governance target as a team builds out AI, and the NIST AI RMF layer where it ships agents. On Vanta by default, other platforms where a client requires it.
Engineer Around It: Backlog and Deep Work
The engineering around the cryptography. FEDLIN takes ownership of the remediation backlog and drives it to closure, and delivers the point engagements where depth decides the outcome: web and API security including agentic and MCP surfaces, penetration testing, and secure-infrastructure engineering and DevSecOps (hardened CI/CD, pipeline security gates, secrets management, and IaC hardening). Delivered on their own, or folded into the program.
The Approach
Controls are implemented at the infrastructure layer (deployed and running in the environment) and every control produces continuous evidence linked to the specific framework requirement it satisfies. Evidence that holds between audit windows, produced continuously as living artifacts.
Engagements start with a scoping call that establishes which gate the client is entering on and sequences the track from there.
FEDLIN works both directly and as the engineering arm behind primes, partners, and advisors: direct engagements, subcontracting, and teaming as the work calls for it. Built on Vanta by default, other platforms where a client requires it, with the engineering as the product.
Clear the gate that gates your revenue.
A customer's security review, an audit, a compliance deadline: whatever's holding up the business, FEDLIN builds the controls, runs the program, and clears it, so you can focus on what you do best. Start with a scoping call to set the track.
