521 Solutions Limited
Company no. 16976532 Hampshire, UK tom@521.solutions

Security engineering · contract

A control that is not evidenced did not happen.

I am Thomas Whalley. I build the security controls that regulated software has to pass through, and the evidence that proves they work, for the auditor, the notified body, or the client's security team who asks the awkward question.

Engagement
Outside IR35 via 521 Solutions Limited. Inside IR35 considered at an uplifted rate
Availability
December 2026
Working
Hampshire based, UK-wide, hybrid or on site
Clearance
SC held 2022 to 2024, now lapsed. Eligible for re-vetting

Practice

Three areas, deliberately narrow.

Not a general cloud consultancy. These are the places where the work is scarce, the failure modes are expensive, and somebody eventually has to prove the control was real.

Secrets and identity

Removing static credentials from pipelines and applications entirely. Dynamic secrets with short lifetimes, workload identity in place of stored keys, and just-in-time elevation instead of standing administrator rights.

VaultOpenBaoEntra ID and PIMOIDC federationFIDO2

Supply chain integrity

Knowing what you shipped, proving it came from your own build, and refusing anything that did not. Bills of materials that can be queried when a CVE lands rather than filed and forgotten, with signing and provenance enforced at the point of deployment.

SBOM and VEXSigstoreSLSA provenanceKyvernoKubernetes

Secure lifecycle, regulated

Building a development lifecycle that satisfies a named standard and produces the artefacts to demonstrate it. Medical devices, payments, public sector. Every control mapped to a specific requirement, never to good intentions.

IEC 81001-5-1IEC 62304ISO 27001NIST SSDFPCI DSS

Evidence

Open builds you can run yourself.

Client work is confidential, so these are public builds I own end to end. Each is runnable, documented, and explicit about what it does not cover. Read the code rather than taking my word for it.

Attestation gate

Kubernetes admission

A cluster that runs only images signed and attested by one specific build workflow, and rejects everything else.

What it demonstrates A negative test suite: the gate is proven to reject unsigned, wrongly signed and right-signature-wrong-workflow images, not merely to admit the good one.

github.com/twhalley/attestation-gate

Payments platform

PCI DSS reference build

A GitOps-delivered Kubernetes payments workload with layered scanning, supply chain enforcement, service mesh mTLS and infrastructure defined in Terraform. Runs end to end from a devcontainer.

What it demonstrates Two independent admission gates, default-deny networking and runtime syscall detection, with a unit test on every policy so a broken policy fails in CI rather than in production. Controls mapped to PCI DSS, ISO 27001 Annex A and NIST CSF 2.0, with the accepted trade-offs written down rather than omitted.

github.com/twhalley/payments-platform-poc

Golden image factory

Hardened OS pipeline

Versioned, tested and attested operating system images built from version-controlled definitions, rather than a hand-configured machine somebody snapshotted once.

What it demonstrates Assertions run against the built image, so hardened is a test result with a date on it and not a claim in a document.

github.com/twhalley/golden-image-factory

Record

Where the practice comes from.

Defence, regulated medical devices, and public sector. Environments where the paperwork is read by somebody whose job is to disbelieve it.

2026 –

Secure software development lifecycle

Medical device manufacturer · under NDA

Establishing the lifecycle for a regulated instrument: hardened build pipeline, bill of materials and vulnerability management, and the technical documentation that has to satisfy an external assessor first time.

2025 – 2026

Platform, identity and security engineering

UK local authority · 300 users, 550 hosts

Sole practitioner. Built the CI/CD platform from nothing with quality and security gates inside the pipeline rather than bolted alongside it. Rebuilt privileged access onto just-in-time activation across five control planes, removing standing global administrator from daily accounts. Built the organisation's cyber risk register from an authorised scan of every live host, and led its first Cyber Essentials assessment.

2024 – 2025

DevSecOps engineer

Mehal Technologies, Dublin · clinical edge devices

Secure platform for medical edge devices deployed into clinical environments. Hardened bootable container images with a full audit trail, and secrets governance across distributed infrastructure using short-lived credentials rendered at runtime, so rotation propagated without restarting the application.

2022 – 2024

DevOps engineer

BAE Systems, Portsmouth · classified programme

Under formal change control. Technical lead on software-defined datacentre automation, taking environment build time from days to hours and removing manual steps from bare-metal provisioning entirely. Architected the enterprise secrets management model adopted across the programme, and ran the policy design and team onboarding for it.

Method

The parts that are not negotiable.

These are the habits that stop a security change becoming an outage, and stop a compliance claim falling over when somebody finally checks it.

Audit before enforce

Report-only before on, detection before remediation, on anything that can break a user or a device.

Evidence over assertion

Every control points at an artefact: a pipeline run, a scan report, a signed attestation.

Pilot before fleet

Test device, pilot, ring, fleet. The pilot stays static until the build is proven end to end.

Named requirements

Findings map to a control ID. If a control has no real security value I will say so rather than build it.

Tested rollback

An untested rollback is a hope. Every change ships with one that has actually been run.

Handover is a deliverable

Runbooks, architecture documents and decision logs, so the work survives the engagement ending.

Contact

Available for outside IR35 contracts.

Currently engaged, with next availability in December 2026, and happy to talk earlier about work starting then. Direct and agency enquiries both welcome. Outside IR35 preferred; inside IR35 considered at an uplifted rate. Rate on application.

tom@521.solutions

How an engagement starts

  1. 01 Enquiry. Email the role or the problem. I reply the same or the next working day, and I will tell you if it is not a fit rather than take the call anyway.
  2. 02 Scoping call. Thirty minutes, no charge. What the deliverable is, what finished looks like, the constraints, and who signs it off.
  3. 03 Scope in writing. Deliverables and acceptance criteria agreed in writing before anything starts. This is what makes it a project rather than a pair of hands, and it is what both sides refer back to.
  4. 04 Start. Contract through your agency or direct with 521. Status review where relevant, insurance evidence on request, then work begins.