Case Study
SOC 2 & PCI DSS Compliance Program
Led an org-wide SOC 2 Type II certification effort alongside PCI DSS controls, with continuous monitoring and automated compliance.
Challenge
The organization needed SOC 2 Type II certification and PCI DSS compliance for payment-handling systems — both of which require demonstrable, continuously operating security controls, not a one-time audit checklist, across infrastructure, endpoints and monitoring.
Architecture / Approach
Deployed Wazuh for real-time SOC 2 and PCI DSS compliance monitoring, alerting and vulnerability tracking. Rolled out FleetDM for endpoint management across PCs and Macs with automated onboarding and offboarding. Built CI/CD security gates with SonarQube, Trivy, OWASP ZAP and Snyk on top of GitHub Actions, and codified infrastructure provisioning in Terraform Cloud.
My Role
Directed the security controls, monitoring stack and endpoint management program underpinning both certifications.
Outcome
Established continuous compliance monitoring and automated controls supporting both SOC 2 Type II and PCI DSS requirements, replacing manual, point-in-time checks with ongoing enforcement.
Technologies
- Wazuh
- FleetDM
- SonarQube
- Trivy
- OWASP ZAP
- Snyk
- Terraform Cloud
- PCI DSS
Next case study
Multi-Environment EKS GitOps Platform →