Accepting a limited number of engagements

Security Advisory

Shane Blaufuss, CISSP

I've spent 25 years working inside the infrastructure most advisors have only read about — banking systems, classified DoD weather intelligence, satellite telemetry for national weather programs, PCI-compliant payment platforms, and enterprise cloud at scale. I know what failure looks like.

The Challenge

The thing about security risks —
they don't announce themselves.

The credentials sitting in a git commit. The IAM role that's been overprivileged for two years. The database cluster that's one crash away from a bad week. None of these look like threats until they become incidents.

In 20+ years on incident response teams, the pattern is consistent: companies don't lack protection — they lack an accurate picture of what they actually have and where they're actually exposed.

"You can't make good security decisions about things you don't know exist. That's what the work is, before anything else."

Services

Where I can help.

01

Security Architecture

How systems should be designed — trust boundaries, data flows, access patterns, encryption decisions. Design-level input before problems get built in, or a structured review of what already exists.

02

DevSecOps

Security embedded in how your team ships. Pipeline hardening, cloud posture, IAM hygiene, IaC scanning, secrets management. Built into the process — not discovered during an audit.

03

Compliance & Governance

I've been the technical point of contact with auditors across multiple sectors. Controls that reflect how you actually operate — not how a framework template assumes you do.

04

vCISO

Strategic security leadership without the full-time headcount. A consistent cadence, a clear priority list, and someone who can translate security risk into language the board can act on.

Background

Every environment teaches you something different.

25+ years in infrastructure
& security
CISSP certified since 2005 · cert #78827
fewer than 160k holders worldwide
6 sectors: banking, defense,
satellite, fintech, retail, agtech
20+ years continuous
CERT/CIRT

Banking at First National of Omaha — where early CERT work included forensic investigations into datacenter customer intrusions and a developer network compromise that involved the FBI. Classified DoD weather intelligence at Northrop-Grumman/AFWA, satellite telemetry processing for the NASA/NOAA JPSS program at Raytheon, fintech payments at PaymentSpring, e-commerce at The Buckle, and agricultural R&D at Corteva — each sector has its own security pressures, its own compliance demands, and its own version of the problem.

Large organizations have consistently brought me in to become the subject-matter expert on whatever the hardest technical problem was. That's the context behind the advice I give.

In Practice

Three stories from the last decade.

Corteva Agriscience

25+ multi-region AWS accounts, all of them protecting proprietary agricultural research that took decades to produce. Vendor tooling kept generating noise; I built what was actually needed in Python and Go. Working directly with engineering teams, we cut through 25,000+ findings and moved overall posture from below 85% to 93%.

The more interesting moment: an S3 honeypot I instrumented with XDR telemetry caught a legitimate employee who couldn't resist clicking on a tantalizingly named bucket. He admitted he was just being nosy. I explained we were trying to catch intruders using stolen credentials to exfiltrate secrets — which is exactly why the bucket had that name.

The Buckle

Five years on the same platform — long enough to see what accumulates when security is treated as a compliance checkbox. Ran five consecutive SOC 2 and SOX cycles; cut audit prep time by 60% by building evidence pipelines into GitLab instead of recreating the chaos each year.

The closest call wasn't an audit — it was a MariaDB/Galera cluster that had been quietly degrading for months. Executed a full migration to modern HA architecture across six new servers before it took production down with it. It was close.

PaymentSpring (Nelnet)

When you're building PCI-DSS Level 1 infrastructure at a startup, there's no prior version to reference — I built it right the first time because there wasn't a second chance. HSMs, a five-shard geographically-distributed key custodian program, quarterly pen testing. We passed the first audit. A lot of that work was also just explaining cryptographic key management to people who'd never had to care about it before.

The most memorable afternoon there: the CISO and one of our own infosec engineers came to town without telling anyone and tried to walk into our office as part of a red team exercise across three locations. I caught them. We were the only office that did. The CTO heard about it.

How I Work

I don't arrive with a predetermined framework.

Frameworks are useful reference points. They're terrible starting guns. Every engagement starts with understanding what you actually have — your systems, your team, your constraints, and your actual risk tolerance. Assumptions are expensive in this work.

A prioritized plan you can execute with the team you have. Not a 200-page report nobody reads.
01

Understand

Your environment, your team, your actual risk — not the NIST CSF template of your risk.

02

Map the Exposure

What's real, what's theoretical, what's a priority. An honest picture of where you stand.

03

Prioritize

A ranked, actionable list. What to fix first, what can wait, what the tradeoffs are.

04

Execute (optional)

I can stay involved to guide remediation, validate controls, and prepare for audits.

Working Together

I keep a short client list on purpose.

Boutique means each engagement gets real attention. That means I'm selective.

Who I work with
  • Growth-stage companies (20–300 people) Facing customer security scrutiny, heading toward audits, or building cloud-native products.
  • SMBs in regulated industries Handling customer data where security needs to be real, not performative.
  • CTOs, COOs, founders Who want clear answers — not vendor recommendations dressed up as advice.
What I'm not
  • A commodity auditor If you need the fastest SOC 2 checkbox at the lowest price, I'm not the right fit.
  • An outsourced ops team I advise and guide. I don't run tickets.
  • A vendor or reseller Guidance is grounded in your environment, not a product roadmap.

Contact

Let's figure out
if I can help.

Start with a 15-minute call. Tell me what you're dealing with — I'll tell you honestly whether I'm the right fit and what a useful first step looks like.

Book a 15-min clarity call

If you know what you need: include company size, cloud stack, compliance goals, and current concerns.

scroll, or click here →