Cloud infrastructure that is already audit-shaped
Identity, logging, encryption, backups, MDM, and alerting get installed as a baseline — CIS-benchmarked on AWS, GCP, or Azure — so evidence exists before an auditor asks for it.
For companies without a security team
Modern security and compliance for small and midsize businesses that need SOC 2, HITRUST, ISO 27001, or FedRAMP to win customers — without pausing the product or hiring a full-time CISO.
The problem
Most growing companies hit the same wall: a customer sends a security questionnaire, a SOC 2 ask, or a HITRUST requirement — and there is nobody on staff whose job is to own it. Groundwork is the missing layer: we build the cloud and process foundation first, then run the certification path on top of it.
Identity, logging, encryption, backups, MDM, and alerting get installed as a baseline — CIS-benchmarked on AWS, GCP, or Azure — so evidence exists before an auditor asks for it.
Fractional CISO, policy suite, control owners, vendor risk, and auditor handoff. Built for teams that need HITRUST, SOC 2, ISO 27001, or FedRAMP to close deals.
Questionnaires, control mapping, evidence collection, and cloud findings should not live in a spreadsheet. We wire smart connections so compliance does not decay after the first audit.
Services
Advisory when you need a CISO seat. Engineering when the cloud and tooling have to actually exist. Most clients use both.
Line A
vCISO retainer: strategy, customer questionnaires, vendor risk, IR tabletops, MDM / IAM / DLP oversight, monthly KRI dashboard.
Certification sprints for SOC 2, HITRUST, ISO 27001, HIPAA, and FedRAMP readiness — scoping, policies, control implementation, evidence automation, and auditor selection.
Internal audit and GRC co-sourcing for teams that already have auditors and need an operator in the middle.
Line B
Cloud security baseline builds: GuardDuty or Security Command Center, DLP, IAM-change alarms, TLS hardening, endpoint encryption, Workspace labels, ticketed vuln remediation.
Custom security tooling: CI hooks, GitHub Actions hardening, evidence bots, internal dashboards, Cloud Functions.
AI-assisted ops: auditor copilots, control-mapping pipelines, and agentic automations that sit on top of the program we install.
Engagements
Fixed-scope path to SOC 2, HITRUST, or ISO 27001 audit-ready: scope, policies, owners, evidence playbook, auditor shortlist.
CIS-benchmarked AWS or GCP groundwork, detection, DLP, MDM, alerting, and an IR tabletop so the program is real, not theoretical.
Monthly operating cadence for companies that need a security leader on the other side of questionnaires, vendors, and the board.
Boundary definition, control inheritance, SSP scaffolding, and 3PAO prep. Honest scoping — FedRAMP is a program, not a weekend.
Selected outcomes
AWS hardening in parallel with the audit path: GuardDuty, IAM-change alarms, CloudFront TLS, Macie DLP, MDM, Workspace classification, vuln tickets, IR/DR tabletop. Type I ready in about 90 days.
HIPAA risk analysis in ServiceNow with quantified likelihood and impact across ePHI. Policies aligned to SOX, NIST, CMS, HITRUST, and HIPAA. KRI metrics to the CIO.
Stood up certification, Azure and AWS controls with infrastructure, automated training and phishing, and an engineering-aligned risk register so questionnaires stopped being a fire drill.
About
I’m Jonathan Welzbacher. I started as an IT auditor at Deloitte, then spent a decade inside companies as IT Audit Manager, Director of Information Security GRC, and Information Security Program Manager. I hold CISSP, CISA, and CPA credentials, and a B.S. and Master of Accountancy from the University of Missouri-Columbia.
I also own a real business — June’s Breakfast + Patio in Shiloh, Illinois. I feel every dollar a security program costs, which is why Groundwork is scoped the way I would want it scoped for myself: fixed outcomes, cloud that actually exists, and automation so the program does not depend on one hero employee.
Groundwork is the practice I built for companies that need enterprise-grade proof without enterprise-grade headcount. I both audit and build — including CloudSecurityAnalyzer, a multi-cloud scanner that maps findings to CIS, NIST CSF, SOC 2, and ISO 27001.
Questions
For most small and midsize companies, yes — as a fractional seat. If you later hire in-house, Groundwork can hand off a living program instead of a pile of documents.
We do FedRAMP readiness: boundary, controls, inheritance, documentation, and 3PAO prep. Authorization still depends on your agency path, 3PAO, and operating budget. We will tell you if you are not ready rather than sell a fantasy timeline.
Yes. Based in the St. Louis metro (Belleville, Illinois) and work with teams nationwide. On-site tabletops and workshops are available when they earn their travel.
Most readiness sprints begin within two weeks of a scoped proposal. Send the customer ask or questionnaire with your note and you will get a reply within one business day.