Your finding inventory, worked to closure. Vulnerability Remediation
FEDLIN is the technical implementation layer that closes security findings: from post-pentest backlogs and incident hardening queues to pre-M&A cleanup and compliance audit preparation.
We work the platforms and infrastructure you have, whatever the framework or toolchain. Findings close with auditable evidence, and status reports back to whoever is running the engagement. Delivered by a principal whose vulnerability-management background runs through NERC/FERC-CIP-regulated critical infrastructure and OT/ICS penetration-test remediation, where a finding disposition has to survive an audit.
Engineered by Jeremiah Coakley, Principal Security Architect
What needs to be closed?
Where this fits
The closure engine for the ladder.
Findings come from everywhere: a penetration test, a self-hosted AI security assessment, or the review that a node build clears. This is the engagement that drives that backlog to closed, with evidence, and updates your Risk Register as each finding is disposed.
When You Need This
Four contexts. The same workflow.
The engagement is structured the same way regardless of what generated the finding inventory. The intake source, the environment, and the output format vary; the workflow does not.
Post-assessment or post-pentest
The assessment or test delivered the finding inventory. Implementation help is what it takes to close it, not more advisory output. We work from any prior engagement: an assessment, third-party pentest, internal scan, or GRC platform export.
Post-incident hardening
A breach, near-miss, or security event produced a finding list. The window before the next exposure is the constraint: the backlog needs to close, not be documented.
Pre-M&A / due diligence
Transaction timeline requires a defensible posture picture. Findings on the board before close create risk for both sides. A scoped sprint closes what needs to close before the conversation happens.
Compliance deadline
Framework audit in scope: SOC 2, NIST 800-53, NIST 800-171, NIST AI RMF, NERC/FERC CIP, ISO 27001. Finding queue needs to move before fieldwork begins. Evidence must be at the fidelity the auditor will require, beyond a status update in the platform.
Engagement Structure
Four shapes. Scope confirmed at kickoff.
Where the findings come from and the environment they land in shapes the engagement. The workflow is the same: intake, triage, remediation, validation. Price is set by your register, per finding, below.
Which scanners & GRC platforms?Scanner / GRC platform
Control Closure
A scanner or GRC-platform backlog (Archer, ServiceNow, Vanta, Drata) worked down against the standing program: each control failure engineered to pass and wired to evidence, so the platform reflects what is actually deployed.
OWASP WSTG / API Top 10
Pentest Closure — Web App / API
Findings from a web application or API pentest, closed against the same coverage the test ran: authentication and session handling, access control, injection, and business-logic fixes, each remediated, verified, and evidenced.
Cloud-native / Kubernetes
Pentest Closure — Your Infrastructure
Findings from a partner-delivered pentest, closed on infrastructure you operate yourself: cloud-native, Kubernetes, or hybrid. The same workflow FEDLIN runs on its own Kubernetes cluster, remediated end to end with an external pentest partner.
Critical infrastructure
Pentest Closure — OT/ICS
Pentest findings closed inside a live OT/ICS environment, under the change-control and OT/IT boundary constraints critical infrastructure requires: no disruptive patching in a live process environment, compensating controls where a fix cannot be applied in place.
Any of the four against a named audit deadline? The same workflow runs compressed to your audit window: Framework Readiness applies across all four shapes, scope confirmed against the date.
Assessment
$5,000
Fixed base, ~1 week, for when you don't yet have an inventory. Plain-language findings plus a client-owned Risk Register that prices every finding: the cost to fix it and the cost to leave it. One environment; larger estates scope up per unit.
Remediation
Itemized
Priced per finding off that register; you approve what gets worked before anything is touched, so you never pay for scope you don't have. Milestone-billed, Net 15, delivered as the sprint above that fits the inventory.
Already have a finding inventory (from a pentest, scan, or GRC export)? We work from it directly and skip straight to remediation; the assessment step is only there for when no register exists yet. Either way, scope is confirmed on a short scoping call before anything starts.
For MSP, staffing, and bench partners
Embedded remediation capacity, hourly or sprint-based
The engagements above are fixed-scope, billed direct to the client. A different shape applies when a fractional CIO, MSP, or staffing partner needs a security engineer embedded into an existing backlog or team, priced and structured the way that arrangement already works.
Hourly or fixed scope?FEDLIN is also available as embedded remediation capacity: hourly or time-boxed, subcontracted through your MSP, staffing, or bench relationship rather than a fixed-scope client engagement. Rate and term are set per program, the way subcontracted staffing arrangements already work.
The Workflow
Intake to closure: structured, traceable, evidence-backed.
Every engagement runs four stages. What varies is the backlog size, the environments in scope, and the platforms we're working in.
Intake
We ingest the existing finding inventory (from Archer, ServiceNow, Vanta, Drata, Tenable, Qualys, Jira, or a spreadsheet) and establish the working baseline. Every item is accounted for and attributed to a technical control, risk classification, or framework requirement before remediation begins.
Triage
Findings are prioritized by risk impact and remediation sequence. Blocked items are flagged. Quick wins that move the posture most are sequenced first. By the end of triage, the client and partner have a confirmed working order with estimated closure timelines per priority tier.
Remediation
We work findings. Reconfiguring cloud IAM, patching Kubernetes RBAC, correcting misconfigurations at the infrastructure layer, updating access records, closing GRC platform items with evidence. Status updates flow to the partner or engagement lead on the agreed cadence.
Validation
Closed findings are validated against the control or risk requirement. Evidence is confirmed at the fidelity the context requires: auditor-grade where a framework is in scope, technical closure documentation where one is not. A before/after posture snapshot is produced at delivery.
Environments & Platforms
We work where the findings are.
Remediation is executed inside the actual environment using the platforms you already have. No scanner requirement, no platform change as a condition of the engagement.
Cloud
GCP, AWS, Azure: IAM findings, misconfigured services, overprivileged roles, storage exposure.
VPC / Private Cloud
Network segmentation, ingress/egress exposure, internal service reachability.
Kubernetes
RBAC findings, network policy gaps, runtime detection coverage, node-level hardening.
On-Premises / Hybrid
Legacy infrastructure, mixed-trust zones, patch governance, host hardening.
OT / ICS
Critical infrastructure environments with strict change control, OT/IT boundary requirements, and post-pentest finding closure.
SaaS Stack
Identity and access hygiene, admin privilege exposure, OAuth app governance, integration surface.
Platforms
Where This Leads
Closed findings open the next engagement.
A remediation sprint produces a clean posture baseline: the right starting point for adversarial validation, AI security depth, or surface-layer control deployment.
Penetration Testing
Findings closed and controls hardened. Validate that the remediation held under adversarial pressure. A pentest after a remediation sprint tests the actual posture, not the posture as-documented.
Penetration Testing →Self-Hosted AI Security
If the engagement surfaced AI infrastructure (LLM integrations, MCP servers, agentic pipelines) as an exposure area, that surface has a dedicated engagement. Boundary controls, access scope, and audit logging for AI-native components.
Self-Hosted AI Security →Edge Security
Surface-layer findings from an assessment or pentest: headers, TLS posture, WAF coverage, and DMARC feed directly into the Edge Security engagement. Controls deployed at the edge, fast.
Edge Security →Questions about the engagement
How is this different from vulnerability management?
Vulnerability management is an ongoing operational discipline: continuous scanning, triage workflows, ownership cadence, and remediation tracking as a standing program. Vulnerability Remediation is a scoped engagement: a contractual commitment against a named CVE and finding inventory, each item worked to closure or an explicit risk decision, with documentation attached at delivery. The commitment shape is different (sprint vs. retainer), the deliverable is different (closed queue with evidence vs. running program), and the price model reflects it. If the vulnerability management program does not exist yet, GRC Engineering builds it. If it exists and the queue is stalled, that is this engagement.
How is this different from a vCISO engagement?
A vCISO advises: gap identification, risk prioritization, policy decisions, POA&M ownership. Vulnerability Remediation implements. We work from whatever the advisory layer produces (a gap report, a finding export, a prioritized backlog) and close items at the technical level: reconfiguring controls, producing evidence, updating GRC records, validating closure. The roles do not overlap; neither do the deliverables. MSSPs deliver continuous scanning, alert triage, and managed detection: an ongoing operational service. This engagement is scoped, finite, and ends with a closed queue and a documented posture snapshot. One sprint, one deliverable.
Does this require a compliance framework to be in scope?
No. Compliance is one context where the engagement applies, not a prerequisite. Post-pentest backlogs, incident hardening queues, pre-M&A posture cleanup, and board-driven security remediation all run the same workflow (intake, triage, remediation, validation) with documentation appropriate to the context. Framework mapping is included where one is in scope; when no framework applies, closure documentation focuses on the technical finding and the control it addresses.
Do you require us to use a specific scanner or GRC platform?
No. We work the platforms you already have: Archer GRC, ServiceNow GRC and ITSM, Vanta, Drata, FutureFeed, Tenable, Qualys, Jira. We do not bring our own scanner or require platform changes as a condition of the engagement. If the finding inventory lives in a spreadsheet, that works too.
What environments do you work in?
Cloud environments (GCP, AWS, Azure), VPC and private cloud, Kubernetes clusters and containerized workloads, on-premises and hybrid infrastructure, OT/ICS environments with strict change control, and SaaS stack access hygiene. The workflow is the same across environments; what varies is the technical surface and the tooling we use to validate closure.
Can vCISO partners white-label this?
Yes. Delivery goes to the partner first: status updates, closure reports, and evidence packages flow to you. The client relationship stays yours. If you run multiple client engagements, contact us through the partner program for volume arrangements.
Do you work hourly, or only fixed-scope sprints?
Direct-client engagements are fixed-scope: a flat assessment fee and itemized, per-finding remediation billing. A separate model applies for MSP, staffing, and bench partners who need embedded remediation capacity inside an existing program or team: hourly or time-boxed, priced and termed per arrangement rather than published as a rate card.
What frameworks do you remediate against?
SOC 2, NIST 800-53, NIST 800-171, NIST AI RMF, NERC/FERC CIP, and ISO 27001. Most engagements span more than one framework; findings are triaged and closed with evidence mapped to all applicable frameworks simultaneously. Engagements without a compliance driver produce closure documentation tied to the technical control and risk classification instead.
Do you remediate findings from an OT/ICS penetration test?
Yes. OT/ICS pentest findings close under the same workflow, with the change-control and OT/IT boundary constraints that critical infrastructure requires: no disruptive patching in live process environments, compensating controls where a fix can't be applied in place, and validation methods appropriate to the equipment. The principal's own background includes NERC/FERC-CIP-regulated remediation and OT security pentest remediation, not just IT-side findings.
What does a typical Sprint deliverable look like?
Closed findings with evidence attached, a before/after posture snapshot showing which items moved from open to closed, and documentation confirming what changed and why it closes the gap. Where a compliance framework is in scope, findings are mapped to the relevant controls. Where one is not, documentation reflects the technical finding, the remediation applied, and the validation method.
What's the difference between this and GRC Engineering?
GRC Engineering builds a compliance program: GRC platform setup, control deployment, evidence pipeline, SSP development, and continuous monitoring. Vulnerability Remediation closes gaps in a security posture, with or without a compliance program in the picture. If the sprint reveals the program infrastructure needs to be built from scratch, GRC Engineering is the path forward.
Ready to move the queue?
Book a scoping call. We'll review the finding inventory, confirm the environments and frameworks in scope, and structure the engagement from there.
From the Blog
From the field notes

How the 2026 Water-Utility Attacks Worked
The July attacks on water systems turned on internet-exposed controllers reachable with no novel exploit. An account of the compromise, how the access worked, and what closes it.

How Araptus' PNPM Security Scanner Caught Malware in My Dependencies
Self-hosting Araptus' PNPM Supply Chain Security Scanner led to discovering protest-ware hiding in transitive dependencies—before it reached production.

Anthropic's Mythos is Coming. Is your business ready?
Mythos autonomously discovers and chains zero-day vulnerabilities. The barrier to sophisticated exploitation has collapsed — and the pool of actors who can target your organization has expanded to match.
What needs to get closed?
Tell us what's open and we'll scope the remediation from there.