Company Overview

Company Name: AZ Cyber Security Solutions, Inc.

Business Type: Private, Small Business

CAGE Code: 7GZR0

DUNS: 080030137

Unique Entity ID (UEI): LJLEDTH713G9

Tax ID: 47-2227096

Headquarters: 13520 McLearen Rd, Suite 711193, Herndon, VA 20171

Point of Contact: Zekeria (Zack) Sheikh

Phone: 443-790-0649

Email: zack@azcybersecurity.com

Website: www.azcybersecurity.com

NAICS codes:

  • 423430 Computer and Computer Peripheral Equipment and Software Merchant Wholesalers
  • 511210 Software Publishers
  • 518210 Data Processing, Hosting, and Related Services
  • 541199 All Other Legal Services
  • 541330 Engineering Services
  • 541511 Custom Computer Programming Services
  • 541512 Computer Systems Design Services
  • 541513 Computer Facilities Management Services
  • 541519 Other Computer Related Services
  • 541690 Other Scientific and Technical Consulting Services
  • 541990 All Other Professional, Scientific, and Technical Services
  • 561611 Investigation Services
  • 611420 Computer Training

Contract vehicles, quality certifications, and clearances:

  • GSA Multiple Award Schedule (MAS) Highly Adaptive Cybersecurity Services (HACS) Special Item Number (SIN) 54151HACS, Contract No. 47QTCA24D00CP
  • Other contract vehicles and Special Item Numbers available on request
  • Quality: ISO 9001 certified
  • Facility clearance: Top Secret
  • Personnel clearances: staff cleared at Secret, Top Secret, and higher levels; DOE L and Q handled where required; HSPD-12 compliant

Core Cybersecurity Capabilities

Governance, Risk, and Compliance

  • Risk Management Framework (RMF) execution to NIST SP 800-37 Rev. 2 and NIST SP 800-53 Rev. 5
  • Security Assessment and Authorization (A&A) and Authorization to Operate (ATO) support: SSP, BIA, FIPS 199, CMP, contingency and incident response plans, and package development through authorization
  • Independent Security Control Assessment (SCA) with firewalled separation from package development
  • Privacy assessments: Privacy Threshold Analysis (PTA) and Privacy Impact Assessment (PIA)
  • System, boundary, and program risk assessments and ongoing risk management to NIST SP 800-30
  • FISMA compliance reporting and OMB and OCIO data-call support
  • POA&M management, risk registers, and continuous monitoring to NIST SP 800-137
  • Cybersecurity Supply Chain Risk Management (C-SCRM) to NIST SP 800-161 and Software Bill of Materials (SBOM) review
  • IT security policy development and regulatory compliance

Security Operations and Threat Hunting

  • Security operations support and continuous monitoring
  • Security information and event management (SIEM) engineering, content development, and data onboarding
  • Intrusion detection and prevention (IDS/IPS) design, deployment, and tuning
  • Behavioral analytics and MITRE ATT&CK mapping
  • Insider threat detection and advanced persistent threat investigations
  • Log management and audit-log review

Incident Response and Digital Forensics

We deliver full-lifecycle incident response, prepare, detect, respond, and recover, for public and private sector organizations of all sizes.

  • Prepare: incident readiness assessments, executive and technical tabletop exercises, and incident command structures
  • Detect and respond to ransomware, business email compromise (BEC), malware, insider threat, and cloud intrusions, to NIST SP 800-61
  • Cloud and enterprise incident response across AWS, Azure, Microsoft 365, Entra ID, on-premises, and multi-cloud environments
  • Digital, memory, and mobile-device forensics to NIST SP 800-86 using court-defensible methods and strict chain of custody
  • Malware analysis, including static, dynamic, and code analysis of evasive malware, and malicious-document analysis
  • Data exfiltration and sensitive-data investigations with defensible findings for counsel, cyber insurers, and executives
  • Recover: business restoration, remediation validation, control hardening, and tailored resilience roadmaps

Vulnerability and Threat Management

  • Continuous vulnerability scanning and validation
  • Risk-based prioritization and remediation tracking to CISA and agency timelines
  • Patch management and secure configuration baselines to CIS Benchmarks
  • Penetration testing and coordination of enterprise test programs

Security Engineering

  • Design, deployment, and tuning of security infrastructure, including intrusion detection and prevention, next-generation firewalls, and web application firewalls
  • SIEM engineering: Splunk Enterprise Security with clustered indexers, forwarders, dashboards, and alerts
  • Privileged access management with CyberArk to randomize local administrator passwords, prevent pass-the-hash, and manage service accounts
  • Endpoint detection and response deployment, tuning, and upgrades across successive tools
  • Secure baselines for Windows, Linux, and firewalls, audited with configuration tools
  • Zero Trust architecture using jump boxes, two-factor authentication, and least-privilege access, aligned to OMB Memorandum M-22-09

IT and Cloud Engineering

  • Systems architecture, engineering, development, and life-cycle management
  • Cloud infrastructure engineering: virtual machine deployment from standardized templates, automated scaling, resource tagging, and continuous monitoring across AWS and Azure
  • Cloud security and FedRAMP package review across AWS, Azure, and Microsoft 365
  • Zero Trust architecture aligned to NIST SP 800-207
  • Server, virtualization, network, and workstation operations and maintenance
  • Agile and DevSecOps delivery using ITIL service transition practices
  • Secure configuration, hardening, patching, backups, and system documentation
  • System decommissioning and media sanitization to NIST SP 800-88

IT Operations and End-User Support

  • Operations and maintenance aligned to the Information Technology Infrastructure Library (ITIL), with proactive monitoring, documented escalation paths, and recurring service reviews
  • Multi-channel helpdesk through an integrated ticketing system by phone, email, portal, or in person, supporting more than 1,500 end users in comparable environments
  • Section 508 accessibility and assistive-technology support for end users
  • Deskside and white-glove VIP support, including executive teleconferencing and conference-room audiovisual setup
  • Standard desktop, laptop, and mobile-device imaging, configuration, and patching under formal change control
  • Asset lifecycle management with warranty, age, and end-of-life tracking to plan refreshes and forecast budget
  • Documentation management for procedures, SOPs, and credentials using tools such as IT Glue

Systems Administration

  • Windows and Linux server administration with standardized, security-baselined configurations to NIST and FISMA
  • Patch and software management through a Remote Monitoring and Management (RMM) platform with scheduled scans, prioritization, and automated remediation
  • Active Directory and Microsoft Entra ID identity, authentication, and domain services: account provisioning and deprovisioning, Organizational Units, forests, trusts, and replication monitoring
  • Role-based access control with quarterly access audits to reduce insider-threat risk
  • Internal and external Domain Name System (DNS) management with dynamic updates, monitoring, and alerting
  • Microsoft 365 and Azure administration: conditional access, multi-factor authentication, Advanced Threat Protection, and capacity planning across Exchange Online, SharePoint, and OneDrive
  • Backups, recovery testing, and business continuity planning against defined recovery time and recovery point objectives

Application Development and Section 508 Compliance

  • Web application development and maintenance using Agile and scrum delivery
  • Microsoft-based stack:ASP.NETCore, MVC, and Entity Framework with MS SQL Server, and Angular, jQuery, and Bootstrap front ends
  • Content management with Drupal, WordPress, and SharePoint
  • Continuous integration and deployment with source control, automated testing, and release management
  • Section 508 accessibility compliance for websites and documents, aligned to FISMA and NIST controls

Managed Cyber Defense

  • Continuous monitoring, expert-led alert triage, and point-of-escalation support
  • Threat hunting, investigation, and root-cause analysis
  • Detection engineering, content tuning, security automation, and response orchestration
  • Operational reporting and continuous service improvement
  • Managed and co-managed service models for public and private sector organizations

Training and Advisory

  • Cybersecurity awareness and role-based training
  • RMF and GRC training, templates, and standard operating procedures
  • Strategic security advising and program maturity assessments