Six people, every one of them Azure-only.
No one on this team splits their attention across other cloud platforms — depth in one environment is the entire premise.
Eight years as a cloud security architect before founding CRBG in 2017. Still reviews every new client's initial baseline assessment personally.
Runs the 24/7 SOC and owns the alert-tuning process that keeps drift notifications meaningful instead of constant background noise.
Maps every client's CIS Benchmark posture to whatever compliance framework their auditors actually care about — NIST, ISO 27001, or PCI-DSS.
Designs the Azure Policy and guardrail implementations that make entire categories of misconfiguration difficult to introduce in the first place.
Manages onboarding and the monthly compliance review cadence, and is usually the first person a client hears from after a finding gets flagged.
Builds the custom detection logic behind CRBG's drift alerts and writes most of the remediation scripts the team ships to clients.
Curious what this team has learned securing Azure environments? Read Advisories, or get in touch directly.