Join
Osdire Logo

I will design or independently audit your enterprise security program

J Damien Scott
Recently Online|8:17pm local time

Single Unit Program Audit

Independent audit of an existing program across one business unit or site group.

Delivery Time
21 Days

Service details

I design corporate security programs and I audit the ones you already have. Twenty-one years directing enterprise security, including a 238-site, 28-state footprint, a $24M operating portfolio, and eight years embedded inside Ericsson and the Inter-American Development Bank as their accountable in-country security leader.

Most security programs are not underfunded. They are disconnected. Physical security, information security, investigations, travel risk, and continuity each report somewhere different, each hold a piece of the picture, and nobody holds the whole board. An independent audit finds the seams. A program design closes them.

What you receive: a current-state assessment across physical security, protective operations, GSOC and monitoring, investigations, travel risk, and continuity. A governance model covering accountability, escalation thresholds, and executive reporting. Standards alignment to ISO 31030, ISO 31000, and ISO 22301 where applicable. A program architecture with staffing, technology, and vendor implications. A board-ready summary written for a non-security executive audience.

How I work: I start with documents and interviews, not a template. I read your existing policy set, incident history, and organizational structure before I form a view, and I test that view against the people who run the program day to day. Findings are rated by business impact rather than by control count, so you can see what to fix first and what can wait.

Who this is for: organizations with security spread across more than one function or more than one site, and an executive who needs a single accountable picture. Common triggers are a new security leader, a merger, a serious incident, a board question nobody could answer, or a program that grew by accretion and no longer has a clear owner.

I am independent. I do not sell guards, cameras, software, or monitoring, so the recommendation you receive is the one the evidence supports.

Key details

  • Service Type
    Vulnerability ManagementIncident ResponseSecurity Monitoring
  • Expertise
    Network SecurityIncident ResponseSecurity Architecture
  • Tech Scope
    Cloud Infrastructure (Iaas/Paas/SaaS)NetworksEndpoints & DevicesIdentity & Access Management (Iam)
  • Compliance / Regulation
    GdprHipaaSox
  • Framework / Standard
    Nist Cybersecurity Framework (Csf)Nist 800-53Iso/Iec 27001Soc 2
Special note from freelancer
Twenty-one years directing enterprise security, including a 238-site, 28-state footprint and a $24M operating portfolio. I sell no guards, cameras, or software, so the recommendation is independent of any product.

FAQs

Yes, and that is the more common engagement. An audit is more useful when the auditor has no stake in the original design. If you want the target-state design and governance model as well, that is scoped and quoted separately.
J Damien Scott

J Damien Scott

Security & Risk Consultant |ISO 27001 Lead Auditor & Compliance Consultant |Executive Protection & Threat Assessment

21 years directing security programs across 14 countries, from a 238-site, 28-state US footprint to embedded country security roles with Ericsson and the Inter-American Development Bank. I work across the line most organizations draw between physical and cyber. Accredited ISO/IEC 27001 Lead Auditor, five OCEG credentials, and a Technical Committee seat on the Board of Executive Protection Professionals, which authored ANSI/BEP EPS 2026. Assessments, audits, policy, program design.

Launch Offer Earn up to $500* extra on your first 10 offers created

Terms and conditions apply