What does "fractional" mean?
Senior expertise on a part-time, ongoing basis. Typically a few days per month rather than a full-time executive hire.
How are engagements structured?
Most engagements are monthly retainers with a clear scope and expected time commitment. This typically ranges from one day per month for advisory work to several days per month for hands-on leadership during critical projects. Some engagements are fixed-scope instead of a retainer, scoped up front with a written deliverable and a clear endpoint. Architecture & Migration Assessments and AI Governance both work this way. We agree on the structure upfront, and it can adjust as your needs change.
I'm not ready for a retainer. Can you do a one-time assessment?
Yes. Two engagements work this way. Architecture & Migration Assessments are fixed-scope, fixed-fee engagements that produce a written assessment of your Azure environment or migration path, and typically run two to four weeks. AI Governance is also fixed-scope, either an assessment of how your team is already using AI tools or a full program build that produces the policies and review process. No retainer required for either. If the work uncovers something larger, there's a clear path to a fractional engagement, but it's optional, not a sales funnel.
Do you write code yourself, or just provide direction?
My role over the past decade has been primarily architectural. Designing systems and guiding development teams rather than writing production code daily. That said, I have a solid understanding of the full stack, front-end to back-end, and can roll up my sleeves when needed. For modernization and new development engagements, I typically architect the solution and work with developers (yours or contractors) to build it.
What does application modernization typically involve?
Depends on what you have and where you need to go. Some applications can be migrated to Azure with minimal changes. Others need incremental refactoring or targeted rewrites. Sometimes the right answer is building something new alongside what already exists, especially when off-the-shelf tools don't fit your workflow. I help you assess what you have, build the business case, define the roadmap, and lead the execution.
What compliance frameworks do you have experience with?
Primarily SOC 2. Four consecutive SOC 2 audits with zero findings, three of them Type 2, and information security programs built from the ground up.
Do you handle security questionnaires?
Yes. I've responded to many client security questionnaires, and can help you implement the controls you're missing.
Can you help us meet cyber insurance requirements?
Yes. Cyber insurers ask about the same controls a security program is built on, and I can help you implement them and document the evidence.
Do you implement security controls yourself, or define requirements for others?
Either, depending on your situation. If you have an IT team, I can define the requirements and guide implementation. If not, I can implement controls directly. Azure policies, Defender configurations, Key Vault, network security, and so on.
What's your Azure experience?
I've architected production Azure environments from the ground up, including App Services, Functions, SQL Managed Instances, Azure Data Factory, Key Vault, Application Gateway with WAF, Azure Firewall, Redis Cache, and Application Insights. I handle both the initial design and ongoing governance.
Do you work with companies outside the Microsoft ecosystem?
Yes, for most of what I do. Fractional CTO, security program, and AI governance engagements aren't stack-dependent. That work is roadmap ownership, architecture judgment, policies, controls, and audit readiness, and none of it changes because your platform runs on AWS or GCP. The Microsoft qualifier applies to hands-on work. My deepest hands-on experience is Azure, .NET, and SQL Server, so Azure architecture, migration, and .NET modernization engagements are where the direct fit lives. On other stacks I take the architecture and engagement-leadership role rather than writing the code.
Can you help us figure out where AI fits in our business?
Yes. Technology leadership engagements cover where AI adds practical value and where it adds risk. Governing the tools your team already uses is a dedicated AI Governance engagement.
What's the first step?
Start a conversation. Tell me about your situation and I'll let you know if I can help, and what an engagement might look like.
Still have a question?
Start a Conversation