Security & Compliance Consulting

Security From the Ground Up

Security and compliance consulting for lean teams that need right-sized, risk-based protection.

Let's Talk
Frameworks I Work With
ISO 27001 Information Security
ISO 42001 AI Management
SOC 2 Type II Trust Services
SOC 1 Type 1 Financial Controls

How I Help

From audit prep to AI governance, I bring clarity and structure to your security and compliance program.

Audit Readiness Assessment

Evaluate your current posture against target frameworks and get a clear, prioritized roadmap to audit-ready.

Agentic AI Governance

Design and deploy agentic workflows with the right level of human-in-the-loop controls to manage risk without killing speed.

DR / Incident Response Tabletop

Stress-test your incident response and disaster recovery plans through realistic, facilitated scenario exercises.

BCP / DR Planning

Design and document business continuity and disaster recovery plans that hold up under real pressure.

Policy & Program Design

Build security policies, standards, and program documentation tailored to your organization, not generic templates.

Process Audit

Deep-dive review of your operational and security processes to identify inefficiencies, gaps, and risk.

IT Security Consulting

Hands-on guidance across your IT security landscape, from architecture reviews to controls implementation.

Third-Party Risk Management

Establish and operationalize your TPRM program including vendor assessments, due diligence, and ongoing monitoring.

AI Security Governance

Navigate the emerging landscape of AI risk with governance frameworks, policies, and ISO 42001 readiness.

Questionnaire and RFI Automation

Build a custom AI agent that drafts RFI and customer questionnaire responses automatically and accurately, cutting manual effort so your team focuses on high-value tasks.

About Carrot Consulting

Big 4 trained, with nearly a decade embedded inside startups, high-growth companies, and SaaS environments. I specialize in designing security and compliance programs right-sized to your company and stage. Processes that hold up under scrutiny, scale without friction, and keep your team moving. I work with organizations that need security built properly, not just checked off a list.

Based in Canada. Working globally.

Let's Talk

Ready to get started? Drop me a message and I'll be in touch.

alex@carrotconsulting.ca