Johnny Vaughan, LLC — Chesapeake, Virginia
Third-party risk assessments, compliance readiness, and security documentation. Fixed scopes, defined deliverables, exclusions in writing before work starts.
CRISCCTPRP8+ years GRC and IT audit40+ vendor assessmentsFinancial services, healthcare, federal
Who this is for
A customer sent a security questionnaire, a contract added a compliance requirement, or an insurer asked questions you cannot currently answer. You need the work done correctly the first time, without hiring a full-time compliance function.
Or you are a consultancy with signed compliance work and more of it than your team can deliver this quarter. You need someone who can execute inside your methodology without training.
The work below is grounded in eight years of practice across financial services, healthcare, and federal environments, including Big Four technology risk consulting and federal authorization documentation under NIST SP 800-53.
Service 01
I have performed more than 40 vendor security assessments end to end: intake, scoping, questionnaire and SIG review, SOC report and evidence analysis, control evaluation, risk rating, findings, and remediation validation.
Questionnaire analysis, evidence review, documented risk rating, and findings for one vendor.
Fixed quote based on criticality and evidence volume
Execution inside your existing methodology and tooling, with weekly capacity agreed in advance.
Hourly, quoted per inquiry
Review of intake, tiering, assessment, and remediation processes with a prioritized improvement roadmap.
Fixed quote after scoping
What this is not
This is risk assessment and advisory, not an audit opinion, a certification, a penetration test, or a legal determination. Assessments rely on the evidence the vendor provides. I document evidence gaps rather than work around them.
Service 02
I assess organizations against NIST SP 800-53, NIST CSF, ISO 27001, SOC 2, SOX ITGC, PCI DSS, GLBA, FFIEC, and HIPAA. The difference from a checklist exercise is that I evaluate the evidence itself, the way an assessor will.
Control-gap analysis against your target framework, evidence-quality review, and a remediation roadmap prioritized by risk and implementation effort.
Fixed quote based on framework and system scope
PBC tracking, evidence collection and indexing, control narratives, and issue-response support through fieldwork.
Fixed quote per sprint
User and privileged access reviews, entitlement reconciliation, exception investigation, and a complete audit evidence package.
Fixed quote per review cycle
What this is not
This is audit support and readiness advisory, not independent assurance or attestation. Framework, systems in scope, evidence population, and exclusions are defined in writing before any fixed price is quoted. Production system changes remain with your administrators.
Service 03
Generic templates fail evidence review because they describe an organization that does not exist. I write documentation from interviews with the people who perform the work, validated against how the process actually operates.
Federal experience includes System Security Plans, FIPS 199 categorizations, privacy documentation, and NIST SP 800-53 control statements through the Revision 4 to Revision 5 transition.
Built from process-owner interviews and validated against current practice.
Quoted per document
A scoped set covering a framework's documentation requirements, sequenced so each document references the others correctly.
Priced by document count after scoping
SSP and control-statement updates, artifact quality review, evidence mapping, and POA&M maintenance for integrators and subcontractors.
Hourly, quoted per inquiry
What this is not
I do not resell templates as tailored work. For federal engagements: I am not a 3PAO, do not hold assessor-of-record authority, and do not represent clearance status. Support is documentation and evidence quality, not authorization decisions.
Background
Fixed scope where the work permits, hourly where it does not. Every engagement starts with the deliverable, the quote, and the exclusions in writing. I would rather decline work I cannot deliver defensibly than produce a report that fails review.
I also build compliance automation in Python and Terraform. That work is public, along with a longer record of my background.
Contact
Describe what you are facing, the framework if you know it, and the deadline. I respond within two business days with a scoped approach.