SOC 2 certification in 6 months at Lynx.MD
The situation
A healthcare data company needed SOC 2 certification within 9 months to close enterprise deals — with no compliance program in place, no owner for the process and controls that existed only informally inside engineering.
What I did
I owned the process end-to-end: gathered the requirements, coordinated across security, legal and engineering, and implemented the technical controls myself — encryption at rest and in transit, and access-role separation across AWS RDS and the surrounding services — so the evidence came from how the system actually ran, not from a spreadsheet.
- Certified three months ahead of plan
- Unblocked enterprise deals waiting on SOC 2
- Encryption and role separation enforced across AWS
- Security program embedded in day-to-day engineering
Compliance sticks when the controls are part of how engineers already work — not a parallel process bolted on before the audit.