SSuraj Sah
All work

Case Study

SOC 2 & PCI DSS Compliance Program

Led an org-wide SOC 2 Type II certification effort alongside PCI DSS controls, with continuous monitoring and automated compliance.

Challenge

The organization needed SOC 2 Type II certification and PCI DSS compliance for payment-handling systems — both of which require demonstrable, continuously operating security controls, not a one-time audit checklist, across infrastructure, endpoints and monitoring.

Architecture / Approach

Deployed Wazuh for real-time SOC 2 and PCI DSS compliance monitoring, alerting and vulnerability tracking. Rolled out FleetDM for endpoint management across PCs and Macs with automated onboarding and offboarding. Built CI/CD security gates with SonarQube, Trivy, OWASP ZAP and Snyk on top of GitHub Actions, and codified infrastructure provisioning in Terraform Cloud.

My Role

Directed the security controls, monitoring stack and endpoint management program underpinning both certifications.

Outcome

Established continuous compliance monitoring and automated controls supporting both SOC 2 Type II and PCI DSS requirements, replacing manual, point-in-time checks with ongoing enforcement.

Technologies

  • Wazuh
  • FleetDM
  • SonarQube
  • Trivy
  • OWASP ZAP
  • Snyk
  • Terraform Cloud
  • PCI DSS
Endpoints + Infrastructure
Wazuh Monitoring
CI Security Gates
SOC 2 / PCI DSS Evidence

Next case study

Multi-Environment EKS GitOps Platform