For companies without a security team

Lay the groundwork. Get certified. Keep shipping.

Modern security and compliance for small and midsize businesses that need SOC 2, HITRUST, ISO 27001, or FedRAMP to win customers — without pausing the product or hiring a full-time CISO.

SOC 2 HITRUST ISO 27001 FedRAMP readiness HIPAA CISSP · CISA · CPA ex-Deloitte IT auditor 15+ years GRC

The problem

Enterprise buyers want proof. You need a program, not a binder.

Most growing companies hit the same wall: a customer sends a security questionnaire, a SOC 2 ask, or a HITRUST requirement — and there is nobody on staff whose job is to own it. Groundwork is the missing layer: we build the cloud and process foundation first, then run the certification path on top of it.

01

Cloud infrastructure that is already audit-shaped

Identity, logging, encryption, backups, MDM, and alerting get installed as a baseline — CIS-benchmarked on AWS, GCP, or Azure — so evidence exists before an auditor asks for it.

02

Certification without a full-time security hire

Fractional CISO, policy suite, control owners, vendor risk, and auditor handoff. Built for teams that need HITRUST, SOC 2, ISO 27001, or FedRAMP to close deals.

03

AI and automation that keep the program alive

Questionnaires, control mapping, evidence collection, and cloud findings should not live in a spreadsheet. We wire smart connections so compliance does not decay after the first audit.

Services

Two ways in. One program.

Advisory when you need a CISO seat. Engineering when the cloud and tooling have to actually exist. Most clients use both.

Line A

Fractional CISO & GRC

vCISO retainer: strategy, customer questionnaires, vendor risk, IR tabletops, MDM / IAM / DLP oversight, monthly KRI dashboard.

Certification sprints for SOC 2, HITRUST, ISO 27001, HIPAA, and FedRAMP readiness — scoping, policies, control implementation, evidence automation, and auditor selection.

Internal audit and GRC co-sourcing for teams that already have auditors and need an operator in the middle.

Line B

Security engineering & automation

Cloud security baseline builds: GuardDuty or Security Command Center, DLP, IAM-change alarms, TLS hardening, endpoint encryption, Workspace labels, ticketed vuln remediation.

Custom security tooling: CI hooks, GitHub Actions hardening, evidence bots, internal dashboards, Cloud Functions.

AI-assisted ops: auditor copilots, control-mapping pipelines, and agentic automations that sit on top of the program we install.

Engagements

A first 90 days that leave something standing.

Readiness sprint

Fixed-scope path to SOC 2, HITRUST, or ISO 27001 audit-ready: scope, policies, owners, evidence playbook, auditor shortlist.

Cloud baseline

CIS-benchmarked AWS or GCP groundwork, detection, DLP, MDM, alerting, and an IR tabletop so the program is real, not theoretical.

vCISO seat

Monthly operating cadence for companies that need a security leader on the other side of questionnaires, vendors, and the board.

FedRAMP readiness

Boundary definition, control inheritance, SSP scaffolding, and 3PAO prep. Honest scoping — FedRAMP is a program, not a weekend.

Selected outcomes

Proof from the work, without naming the clients.

First SOC 2 for a Series A SaaS

AWS hardening in parallel with the audit path: GuardDuty, IAM-change alarms, CloudFront TLS, Macie DLP, MDM, Workspace classification, vuln tickets, IR/DR tabletop. Type I ready in about 90 days.

HIPAA + HITRUST in healthcare

HIPAA risk analysis in ServiceNow with quantified likelihood and impact across ePHI. Policies aligned to SOX, NIST, CMS, HITRUST, and HIPAA. KRI metrics to the CIO.

SOC 2 + ISO 27001 for global SaaS

Stood up certification, Azure and AWS controls with infrastructure, automated training and phishing, and an engineering-aligned risk register so questionnaires stopped being a fire drill.

Jonathan Welzbacher, founder of Groundwork Security & Compliance, standing indoors in a green shirt
Jonathan Welzbacher · Founder · CISSP, CISA, CPA

About

A CISO who still ships the work.

I’m Jonathan Welzbacher. I started as an IT auditor at Deloitte, then spent a decade inside companies as IT Audit Manager, Director of Information Security GRC, and Information Security Program Manager. I hold CISSP, CISA, and CPA credentials, and a B.S. and Master of Accountancy from the University of Missouri-Columbia.

I also own a real business — June’s Breakfast + Patio in Shiloh, Illinois. I feel every dollar a security program costs, which is why Groundwork is scoped the way I would want it scoped for myself: fixed outcomes, cloud that actually exists, and automation so the program does not depend on one hero employee.

Groundwork is the practice I built for companies that need enterprise-grade proof without enterprise-grade headcount. I both audit and build — including CloudSecurityAnalyzer, a multi-cloud scanner that maps findings to CIS, NIST CSF, SOC 2, and ISO 27001.

CISSP CISA CPA Sumo Logic SIEM AWS · GCP · Azure

Questions

Straight answers before we get on a call.

Do you replace a full-time CISO?

For most small and midsize companies, yes — as a fractional seat. If you later hire in-house, Groundwork can hand off a living program instead of a pile of documents.

Can you get us FedRAMP authorized?

We do FedRAMP readiness: boundary, controls, inheritance, documentation, and 3PAO prep. Authorization still depends on your agency path, 3PAO, and operating budget. We will tell you if you are not ready rather than sell a fantasy timeline.

Do you work remotely?

Yes. Based in the St. Louis metro (Belleville, Illinois) and work with teams nationwide. On-site tabletops and workshops are available when they earn their travel.

How fast can we start?

Most readiness sprints begin within two weeks of a scoped proposal. Send the customer ask or questionnaire with your note and you will get a reply within one business day.

What are you aiming for?

By submitting, you agree we may use this information to reply about Groundwork services. Read the privacy notice.