Fasset · Series B fintech
ISO 27001 + 27017, first attempt
Led both certifications end-to-end as the primary internal owner, partnering with an external consultant — at a regulated digital-asset fintech where licensing depended on it.
- Defined and implemented controls across access management, change management, incident response, and infrastructure.
- Coordinated engineering, security, legal, and ops through the audit.
- Passed the external audit on the first attempt — unlocked regulatory licensing for the business.
1st
Attempt external audit pass
2
Certifications: ISO 27001 + ISO 27017
4
Control domains: access · change · incident · infra
Context
At a regulated digital-asset fintech, ISO certification isn’t a badge — it gates licensing. As the sole DevOps engineer, I was the primary internal owner for both ISO 27001 and ISO 27017, working with an external vendor consultant.
What I did
Defined and implemented controls across access management, change management, incident response, and infrastructure. Coordinated cross-functional work spanning engineering, security, legal, and ops, and drove the process through the external audit.
Outcome
Passed the external audit on the first attempt, unlocking regulatory licensing for the business.