Hengky Sandycontact
selected-work

Fasset · Series B fintech

ISO 27001 + 27017, first attempt

Led both certifications end-to-end as the primary internal owner, partnering with an external consultant — at a regulated digital-asset fintech where licensing depended on it.

1st

Attempt external audit pass

2

Certifications: ISO 27001 + ISO 27017

4

Control domains: access · change · incident · infra

Context

At a regulated digital-asset fintech, ISO certification isn’t a badge — it gates licensing. As the sole DevOps engineer, I was the primary internal owner for both ISO 27001 and ISO 27017, working with an external vendor consultant.

What I did

Defined and implemented controls across access management, change management, incident response, and infrastructure. Coordinated cross-functional work spanning engineering, security, legal, and ops, and drove the process through the external audit.

Outcome

Passed the external audit on the first attempt, unlocking regulatory licensing for the business.

ISO 27001ISO 27017IAMVaultAudit coordination