Senior cybersecurity leader with over a decade of experience across enterprise security operations, GRC, cyber threat intelligence, risk management, vulnerability management, and incident response. I help organizations build resilient, tailored security programs without the overhead of a full-time CISO.
Serving small and mid-sized businesses, nonprofits, and startups that desire enterprise-quality security guidance.
Practical, outcome-focused engagements tailored to your organization's size, risk profile, and maturity level.
Governance, risk, and compliance program development. Control frameworks, policy libraries, risk register design, and preparedness centered in NIST RMF, NIST CSF, ISO 27001, CMMC, and more.
Executive-level strategic guidance for aligning security investments to business objectives. Budgeting, prioritization, and board-ready communication of cyber risk posture.
Building or maturing a security program from the ground up; people, process, and technology. Policies, procedures, organizational structure, and operating models.
CTI program design to include identification of threat actors targeting your industry, intelligence lifecycle management, integration with SOC and IR operations, tailoring the goals of the program to align with business needs, and more.
IR plan development, tabletop exercise facilitation, playbook design, and post-incident review. Preparation before, and guidance through, a security event.
Structured assessment of your current security posture against a target framework, with a prioritized, practical roadmap for improvement tied to business risk.
Independent evaluation of security products and vendors. RFP support, proof-of-concept criteria, tool stack rationalization, and unbiased recommendations free of vendor relationships.
Program design and maturation for vulnerability identification, prioritization, and remediation. Scanning strategy, risk-based prioritization frameworks, SLA development, and integration with broader risk and patch management operations.
People are both the greatest risk and the strongest defense. Advisory on security awareness programs, phishing simulation strategy, insider threat frameworks, behavioral risk indicators, and building a security culture that actually sticks.
A focused, point-in-time security review designed specifically for small and mid-sized businesses. You'll receive a clear, prioritized set of actionable recommendations for building cost-effective resilience. No jargon, no vendor upsells, just honest guidance. Ideal for organizations that need expert eyes but don't have a dedicated security team.
Curated engagements for organizations ready to take a focused step forward.
Organizations that want to understand the threat landscape specific to their industry, not a generic feed of headlines.
A structured intelligence report profiling the threat actors, attack techniques, and indicators most relevant to your sector and business profile, written for both technical and executive audiences. Every report includes a follow-on conversation to discuss findings and identify next steps for continuous monitoring, proactive defense, and long-term threat resilience.
Organizations that recognize their people are both their greatest vulnerability and their strongest potential defense.
A security awareness strategy and program design tailored to your workforce, including phishing simulation recommendations, training content guidance, and behavioral risk indicators to watch for. Built around changing behavior, not just checking a box. Ongoing advisory retainers are available for organizations that want to keep their human risk program current, their workforce sharp, and their leadership informed on a regular cadence.
Organizations that want an honest, independent look at where their security program stands today.
A structured assessment of your current security posture mapped against a recognized framework, a prioritized gap analysis, and a clear picture of where to focus next, delivered in plain language. For organizations ready to act on what they find, advisory support is available to help prioritize and work through the roadmap findings, whether that means building out a security program, addressing specific gaps, or preparing for a compliance milestone.
Organizations that have existing cybersecurity and IT governance structures in place but aren't confident they reflect current standards, regulatory expectations, or the actual risk posture of the business. This engagement is also well-suited for organizations that don't yet have formal governance in place and are looking for a structured starting point.
A point-in-time review of your existing governance, risk, and compliance program assessed against recognized industry frameworks and standards. You'll receive a clear picture of where your current policies, controls, and risk management practices stand, along with a prioritized set of opportunities for revision, new governance development, and alignment with the standards most relevant to your organization. For organizations starting from scratch, governance documentation can be developed from the ground up, tailored to fit your environment rather than copied from a generic template.
The natural follow-on for this engagement is an ongoing advisory relationship to work through revision and alignment priorities, whether that means updating existing policies, building new governance structures, or preparing for a formal audit or certification milestone.
Joshua Caldwell
Independent Cybersecurity Advisor
I'm a senior cybersecurity professional with over a decade of hands-on experience building and leading security programs in complex enterprise environments. My career spans security operations, incident response, cyber threat intelligence, GRC, vulnerability management, AI security, risk management, and insider threat analytics.
Through Atlas Cyber Solutions, I make that enterprise-level expertise accessible to organizations that deserve serious security guidance without the cost of a full-time senior hire or the inefficiency of a large consulting engagement. Whether you're a growing mid-market company, a small business building your security foundation, or an established organization with a specific challenge to solve, I'm here to help you mature your security posture in a way that actually fits your organization.
I'm also active in the professional community as a member of the ISACA CISM Certification Working Group Advisory Board and the GIAC Advisory Board, and I mentor the next generation of security professionals through ISACA. I welcome inquiries from organizations seeking an experienced cybersecurity practitioner for board or advisory committee roles.
Whether you're evaluating a specific need or just want a candid conversation about your security posture, I'm happy to connect.
Proudly serving small and mid-sized businesses, nonprofits, and startups.