Packages
Every engagement starts with the Tier 1 audit.
Tier 1
Infrastructure & Security Audit
Why start with an audit? You see our work for $500 before committing more. We see your stack before quoting. Nobody buys blind.
See exactly where you stand. Actionable findings in a week.
$500*one-time
Fahad personally reviews your CI/CD pipelines, cloud architecture and security surface, including AI-generated code vulnerability scanning.
Deliverables
- CI/CD pipeline analysis
- Cloud architecture review (AWS/GCP/Azure/DigitalOcean)
- Security surface assessment
- AI-generated code vulnerability scan
- Prioritised findings report
- Remediation roadmap
- 30-minute debrief call with Fahad
Week one
The full report and debrief call. Delivery in 5–7 business days.
Best for
Any company that wants to know where its gaps are before committing to a larger engagement. This is how every engagement starts.
*Book a project or retainer within 90 days of your audit and the $500 is credited to your first invoice.
Sample deliverable — infrastructure & security audit report (PDF, fictional company) DownloadTier 2
Project-Based
Custom-priced, scoped from the audit
DevOps Automation
From manual chaos to automated pipelines.
Custom — scoped per project
CI/CD pipelines built, apps containerised and cloud infrastructure provisioned — then handed back fully automated.
Deliverables
- CI/CD pipeline design and implementation
- Docker containerisation
- Kubernetes cluster setup (EKS/GKE/self-hosted)
- Cloud provisioning (AWS/GCP/DigitalOcean)
- Terraform IaC for all resources
- AI code vulnerability scanning in pipelines
- Full documentation and runbooks
- Week one
- Discovery and scoping based on the audit findings.
- Best for
- Teams with manual deployments, no pipelines, or developers SSH-ing into servers.
Security Hardening
Lock down every surface before attackers find the gaps.
Custom — scoped per project
End-to-end hardening — zero trust, IAM overhaul, secrets management, container security, pipeline security gates and AI code vulnerability detection.
Deliverables
- Zero trust architecture implementation
- IAM audit and least-privilege enforcement
- SAST/DAST/SCA integration into CI/CD
- Secrets management (Vault/AWS Secrets Manager)
- Container runtime security (Falco)
- AI-generated code vulnerability detection
- Verification pen test after implementation
- Week one
- Threat model and attack-surface mapping.
- Best for
- Companies that have infrastructure but no security posture.
Compliance Build-Out
From gap analysis to audit-ready.
Custom — scoped per project
Full implementation of SOC 2, HIPAA, GDPR or GLBA compliance — controls, policies, documentation, tooling and audit preparation.
Deliverables
- Control framework implementation
- Policy and procedure documentation
- Evidence collection automation
- Vendor and third-party risk management
- Security awareness training for your team
- Audit preparation and mock review
- Ongoing support through the audit
- Week one
- Gap analysis against the target framework.
- Best for
- Companies approaching a compliance audit or needing regulatory alignment.
Tier 3
Hire Fahad: Embedded CSO / Principal DevOps
Fahad joins your team as a fractional CSO or Principal DevOps engineer: direct communication, strategic oversight, hands-on execution.
Deliverables
- Direct access to Fahad — not a junior
- Strategic security and infrastructure leadership
- CI/CD pipeline ownership and optimisation
- AI code vulnerability governance
- Incident response and on-call support
- Monthly infrastructure and security reports
- Flexible hours that scale up or down
- Week one
- Onboarding into your systems, access setup, initial assessment.
- Best for
- Companies that need senior DevOps or security leadership without a full-time hire.
Tier 4
Streetlight Team
Managed DevOps Team
Your own certified DevOps team, fully managed.
From $8,000/month (3–5 person team)
A team of 3–5 certified DevOps engineers embedded in your workflow, hired and managed by Fahad.
Deliverables
- Full pipeline ownership
- 24/7 monitoring and alerting with an on-call rotation across the team
- Cloud infrastructure management
- Weekly standup and reporting
- Flexible team scaling
- Team shape
- 3–5 DevOps engineers; Fahad as technical lead and account manager
- Week one
- Team onboarding, system access, infrastructure audit, standup cadence established.
- Best for
- Companies that need ongoing DevOps capacity beyond one person.
Full DevSecOps Team
DevOps and security, combined. Fully managed by Fahad.
From $14,000/month
A combined DevOps and security team under Fahad's technical leadership.
Deliverables
- Full infrastructure and security ownership
- CI/CD + cloud + observability + security managed
- 24/7 monitoring and incident response (on-call rotation across the team)
- Quarterly strategy and roadmap sessions
- Compliance maintenance
- Team shape
- 2–3 DevOps engineers + 1–2 security engineers; Fahad as CISO/CTO equivalent
- Week one
- Full team onboarding, infrastructure and security baseline assessment, monitoring setup.
- Best for
- Companies that need DevOps and security handled as a single managed service.
Enterprise / Custom
Custom scope. SLA-backed. Priority everything.
Custom — contact for pricing
A tailored engagement with custom team configuration, SLA guarantees and dedicated strategic support.
Deliverables
- Defined SLAs (uptime, response time)
- Dedicated account management — Fahad directly
- Quarterly strategy sessions and roadmap planning
- Priority incident response (sub-1-hour SLA, on-call rotation across the team)
- Custom compliance frameworks
- Executive-level reporting
- Team shape
- Custom size and composition based on requirements
- Week one
- Scoping sessions, SLA negotiation, team assembly.
- Best for
- Larger organisations where predefined packages don't fit.
Start with a $500 audit.
See exactly where you stand. Actionable findings in a week.
The full report and debrief call. Delivery in 5–7 business days.