Practical cybersecurity consulting for cloud, software, and payment-driven companies.
ControlSolid helps growing companies build security programs that hold up to customer, auditor, and attacker scrutiny — without unnecessary complexity.
Kelvin brings senior-level expertise from leadership roles at Trustwave and Amazon Web Services (AWS), plus other leading organizations in payment security and cloud application security. He has helped fintech, SaaS, and payment companies successfully navigate customer security reviews, compliance audits, and complex architectural risks.
His work spans application and cloud security reviews, security assessments, web application penetration testing, and advisory and customer assurance for teams preparing for the next stage of growth.
Key Experience
- Former Principal Security Consultant at Trustwave, focused on PCI DSS, PCI PIN, PA-DSS, and P2PE programs.
- Senior application security leadership at Amazon Web Services (AWS) in large-scale cloud environments.
- Qualified Security Assessor (QSA) experience.
- Hands-on expertise in web application penetration testing, threat modeling, and secure SDLC, aligned with NIST, CIS, SOC 2, and customer security assurance.
- Speaker, author, and executive-level communicator.
Education & Credentials
- Master of Science in Technical Management — Johns Hopkins University
- Bachelor of Science in Computer Science — University of Puerto Rico
- CISSP • GCIH • CISA • AWS Security & Architecture Certifications • Former QSA
Senior expertise, applied directly to your environment.
Kelvin applies battle-tested lessons from prior roles in payment security consulting and enterprise application security directly to your environment — delivering clear, actionable outcomes.
Practical
Findings, recommendations, and roadmaps your team can actually execute.
Senior
Engagements led by experienced consultants — not handed off to juniors.
Focused
Deep specialization in cloud, application, and payment security.
Need a clear view of your security gaps?
Start with a focused readiness call. We'll discuss your customer pressure, compliance goals, application risk, and the best next step.