Skip to content

SECURITY CONSULTING

For teams building and running apps and web services

Turn security priorities
into working code.

CISSP knowledge, hands-on engineering and CTO experience. I help you review designs and improve code and configuration, with your business impact and budget in mind.

  • Apps
  • Front-end
  • Back-end
  • Infrastructure

Focused improvements or ongoing advisory. Independent service, individually quoted.

FROM REVIEW TO IMPLEMENTATION

What we work on together

A plan your team
can put to work.

  1. 01
    Issues and prioritiesWhat to address first
  2. 02
    Code and configurationWhat to change and how to test it
  3. 03
    Ongoing adviceSomeone to discuss design and operations with

Example deliverables. We agree on the scope for your project.

CISSPThe same engineer, from decisions to implementation.

What is holding up your next step?

  • You need security improvements, but are unsure what to prioritize alongside development.
  • You have review findings, but not enough people to implement and verify the fixes.
  • Permissions and operating rules depend too much on individual judgment.

01 / SERVICES

Start with the support you need now.

For small businesses and development teams without a dedicated security engineer. Work with me on a specific issue, or get ongoing advice as your product develops.

01REVIEW

Review the design, code and configuration. Decide what to fix first.

Authentication, permissions, APIs, cloud settings and dependencies. I look at how your apps and infrastructure fit together, agree on the review scope, and prioritize changes by impact and effort. You can also bring new features for review before implementation.

Example deliverables

A prioritized improvement list, with the review scope and findings

02IMPLEMENT

Make the changes in code and configuration.

Permission checks, dependency updates and infrastructure settings. I implement and review changes in manageable steps, considering existing features, tests and the checks needed when deploying to production.

Example deliverables

Pull requests or proposed configuration changes, test results and remaining issues

03ADVISORY

Have an engineer to consult as development continues.

Get ongoing input on feature designs, pull requests and configuration changes. I work with business leaders and developers to set priorities around your budget, business impact and development plans.

Example deliverables

Design and review comments, updated priorities and operating procedures

We agree on deliverables, validation methods and working environments before starting. These examples are not a package that automatically includes every item.

02 / HOW WE WORK

Start with what concerns you.

No source code or confidential documents are needed for the first inquiry. After discussing the situation, we agree on what information is needed and how to share it.

  1. 01

    Share the situation

    Tell me about your service, what concerns you and your preferred timing. You do not need a technical brief to get in touch.

  2. 02

    Agree on scope and an estimate

    We discuss the environments to review, access needed, deliverables, fees and schedule. I also confirm whether I can take on the work.

  3. 03

    Review, improve and hand over

    I work within the agreed scope and share the changes and test results. Outstanding issues are recorded so you can decide what to do next.

Fees and timing

Quoted for your project

The estimate depends on system size, review scope and implementation needs. Work starts after we agree on the scope, fees and schedule.

Discuss your project

SCOPE

Agree on the boundaries before we start.

Apps, web services and the systems behind them

Work can cover the front-end, back-end and infrastructure. We confirm that you have authority over the systems and that the work is authorized. Before production changes, we review the impact and deployment procedure.

Emergency response, penetration testing and continuous monitoring are outside the scope

The service does not include immediate incident response, forensics or 24-hour monitoring. It also does not cover personal computer repairs, malware removal or account recovery.

Reviews and improvements are limited to the agreed scope. They do not guarantee that every vulnerability will be found or that incidents and damage will be prevented.

Masanori TakanoMASANORI TAKANO

03 / YOUR ENGINEER

Masanori Takano CISSP / Engineer / CTO

I connect business decisions with hands-on engineering.

I am the CTO of NEARIZE and work on MAMORIO and MAMORIO Biz. My work spans development and operations across apps, front-end, back-end and infrastructure.

Business impact, budget and development priorities all matter. Drawing on the structured knowledge of CISSP and my experience as a CTO, I listen to both business leaders and developers, then help decide where to start and how far to go.

Recognition for a service I helped develop (company name at the time)MAMORIO, by MAMORIO Inc.
Ruby biz Grand Prix 2019 — Special Prize

I provide this service independently as Masanori Takano. It is not an official service of my employer.

View my profile and projects

FAQ

Before you get in touch.

What if I am not sure what to ask for?

Start with what prompted the concern: a customer asking about security measures, or uncertainty about access permissions, for example. We can work out what needs reviewing first.

How do focused improvements and ongoing advisory differ?

A focused engagement covers an agreed review or set of changes. Ongoing advisory provides design input, reviews and updates to improvement priorities as development continues. We agree on the frequency, scope of implementation and fees for your team.

How much does it cost, and how long does it take?

I provide an individual estimate based on the size of the system, the review scope and whether implementation is included. Sending an inquiry does not create a contract or start work.

Can you respond to an active security incident?

This is not an emergency incident response service. For an active incident, contact your existing support or incident response provider first. You can consult me about design and operational changes to help prevent recurrence.

LET’S TALK

Tell me what is on your mind.

A brief description of your service, your concerns and your preferred timing is enough to start. Please share only information you can make public.

An inquiry does not commit you to a contract. We first confirm availability, scope and fees.

Contact Masanori Takano

Send an email inquiry

takamasa1222@gmail.com

If your email app does not open, write to this address with the subject “Security consulting inquiry”.

Use the Google Form

Please do not send passwords, private keys, customer personal data or details of undisclosed vulnerabilities. We agree on document sharing and handling arrangements individually.

Email opens your own email app. The form is hosted by Google, and Google’s Privacy Policy also applies when you use it.