Anonymized client · Cybersecurity SaaS
Translated a CTO’s cybersecurity vision into the product he had been trying to build
The inherited agency build contained code, but the intended assessment and risk model was still being lost between stakeholder conversations and implementation.

What I inherited
The situation behind the visible symptom.
Cybersecurity assessments are temporal and relational: the same asset, service, finding, or vulnerability can change across successive scans. The agency foundation did not yet encode the CTO’s intended operating model clearly enough to support that lifecycle.
I became the CTO’s technical counterpart, learned the domain, reworked the MVP around its real data lifecycle, and stayed accountable through releases, recovery, repair, and continued delivery.
Specific work
Changes that moved the system toward control.
- 01
Mapped recurring assessment periods, assets, attack surfaces, findings, vulnerabilities, remediation, and reports into explicit product rules.
- 02
Normalized multiple scan sources and moved heavy ingestion and reporting into visible background work.
- 03
Established development, demo, production, and isolated backfill paths with monitoring, backups, and restore validation.
Technical ownership
The decisions were part of the implementation.
- 01
Made domain discovery part of engineering through repeated working sessions and explicit agreements.
- 02
Defined period-aware state and relationships instead of treating each scanner output as an isolated snapshot.
- 03
Created operational homes for ingestion, reports, workers, releases, backups, restore checks, and historical repair.
- 04
Kept a short feedback loop from CTO decision to working data, report, or dashboard behavior.
Verified result
What the available evidence supports.
The handover became long-term technical ownership of an operating platform designed for large, recurring assessment datasets and continued production change.