Company Overview
Company Name: AZ Cyber Security Solutions, Inc.
Business Type: Private, Small Business
CAGE Code: 7GZR0
DUNS: 080030137
Unique Entity ID (UEI): LJLEDTH713G9
Tax ID: 47-2227096
Headquarters: 13520 McLearen Rd, Suite 711193, Herndon, VA 20171
Point of Contact: Zekeria (Zack) Sheikh
Phone: 443-790-0649
Email: zack@azcybersecurity.com
Website: www.azcybersecurity.com
NAICS codes:
- 423430 Computer and Computer Peripheral Equipment and Software Merchant Wholesalers
- 511210 Software Publishers
- 518210 Data Processing, Hosting, and Related Services
- 541199 All Other Legal Services
- 541330 Engineering Services
- 541511 Custom Computer Programming Services
- 541512 Computer Systems Design Services
- 541513 Computer Facilities Management Services
- 541519 Other Computer Related Services
- 541690 Other Scientific and Technical Consulting Services
- 541990 All Other Professional, Scientific, and Technical Services
- 561611 Investigation Services
- 611420 Computer Training
Contract vehicles, quality certifications, and clearances:
- GSA Multiple Award Schedule (MAS) Highly Adaptive Cybersecurity Services (HACS) Special Item Number (SIN) 54151HACS, Contract No. 47QTCA24D00CP
- Other contract vehicles and Special Item Numbers available on request
- Quality: ISO 9001 certified
- Facility clearance: Top Secret
- Personnel clearances: staff cleared at Secret, Top Secret, and higher levels; DOE L and Q handled where required; HSPD-12 compliant
Core Cybersecurity Capabilities
Governance, Risk, and Compliance
- Risk Management Framework (RMF) execution to NIST SP 800-37 Rev. 2 and NIST SP 800-53 Rev. 5
- Security Assessment and Authorization (A&A) and Authorization to Operate (ATO) support: SSP, BIA, FIPS 199, CMP, contingency and incident response plans, and package development through authorization
- Independent Security Control Assessment (SCA) with firewalled separation from package development
- Privacy assessments: Privacy Threshold Analysis (PTA) and Privacy Impact Assessment (PIA)
- System, boundary, and program risk assessments and ongoing risk management to NIST SP 800-30
- FISMA compliance reporting and OMB and OCIO data-call support
- POA&M management, risk registers, and continuous monitoring to NIST SP 800-137
- Cybersecurity Supply Chain Risk Management (C-SCRM) to NIST SP 800-161 and Software Bill of Materials (SBOM) review
- IT security policy development and regulatory compliance
Security Operations and Threat Hunting
- Security operations support and continuous monitoring
- Security information and event management (SIEM) engineering, content development, and data onboarding
- Intrusion detection and prevention (IDS/IPS) design, deployment, and tuning
- Behavioral analytics and MITRE ATT&CK mapping
- Insider threat detection and advanced persistent threat investigations
- Log management and audit-log review
Incident Response and Digital Forensics
We deliver full-lifecycle incident response, prepare, detect, respond, and recover, for public and private sector organizations of all sizes.
- Prepare: incident readiness assessments, executive and technical tabletop exercises, and incident command structures
- Detect and respond to ransomware, business email compromise (BEC), malware, insider threat, and cloud intrusions, to NIST SP 800-61
- Cloud and enterprise incident response across AWS, Azure, Microsoft 365, Entra ID, on-premises, and multi-cloud environments
- Digital, memory, and mobile-device forensics to NIST SP 800-86 using court-defensible methods and strict chain of custody
- Malware analysis, including static, dynamic, and code analysis of evasive malware, and malicious-document analysis
- Data exfiltration and sensitive-data investigations with defensible findings for counsel, cyber insurers, and executives
- Recover: business restoration, remediation validation, control hardening, and tailored resilience roadmaps
Vulnerability and Threat Management
- Continuous vulnerability scanning and validation
- Risk-based prioritization and remediation tracking to CISA and agency timelines
- Patch management and secure configuration baselines to CIS Benchmarks
- Penetration testing and coordination of enterprise test programs
Security Engineering
- Design, deployment, and tuning of security infrastructure, including intrusion detection and prevention, next-generation firewalls, and web application firewalls
- SIEM engineering: Splunk Enterprise Security with clustered indexers, forwarders, dashboards, and alerts
- Privileged access management with CyberArk to randomize local administrator passwords, prevent pass-the-hash, and manage service accounts
- Endpoint detection and response deployment, tuning, and upgrades across successive tools
- Secure baselines for Windows, Linux, and firewalls, audited with configuration tools
- Zero Trust architecture using jump boxes, two-factor authentication, and least-privilege access, aligned to OMB Memorandum M-22-09
IT and Cloud Engineering
- Systems architecture, engineering, development, and life-cycle management
- Cloud infrastructure engineering: virtual machine deployment from standardized templates, automated scaling, resource tagging, and continuous monitoring across AWS and Azure
- Cloud security and FedRAMP package review across AWS, Azure, and Microsoft 365
- Zero Trust architecture aligned to NIST SP 800-207
- Server, virtualization, network, and workstation operations and maintenance
- Agile and DevSecOps delivery using ITIL service transition practices
- Secure configuration, hardening, patching, backups, and system documentation
- System decommissioning and media sanitization to NIST SP 800-88
IT Operations and End-User Support
- Operations and maintenance aligned to the Information Technology Infrastructure Library (ITIL), with proactive monitoring, documented escalation paths, and recurring service reviews
- Multi-channel helpdesk through an integrated ticketing system by phone, email, portal, or in person, supporting more than 1,500 end users in comparable environments
- Section 508 accessibility and assistive-technology support for end users
- Deskside and white-glove VIP support, including executive teleconferencing and conference-room audiovisual setup
- Standard desktop, laptop, and mobile-device imaging, configuration, and patching under formal change control
- Asset lifecycle management with warranty, age, and end-of-life tracking to plan refreshes and forecast budget
- Documentation management for procedures, SOPs, and credentials using tools such as IT Glue
Systems Administration
- Windows and Linux server administration with standardized, security-baselined configurations to NIST and FISMA
- Patch and software management through a Remote Monitoring and Management (RMM) platform with scheduled scans, prioritization, and automated remediation
- Active Directory and Microsoft Entra ID identity, authentication, and domain services: account provisioning and deprovisioning, Organizational Units, forests, trusts, and replication monitoring
- Role-based access control with quarterly access audits to reduce insider-threat risk
- Internal and external Domain Name System (DNS) management with dynamic updates, monitoring, and alerting
- Microsoft 365 and Azure administration: conditional access, multi-factor authentication, Advanced Threat Protection, and capacity planning across Exchange Online, SharePoint, and OneDrive
- Backups, recovery testing, and business continuity planning against defined recovery time and recovery point objectives
Application Development and Section 508 Compliance
- Web application development and maintenance using Agile and scrum delivery
- Microsoft-based stack:ASP.NETCore, MVC, and Entity Framework with MS SQL Server, and Angular, jQuery, and Bootstrap front ends
- Content management with Drupal, WordPress, and SharePoint
- Continuous integration and deployment with source control, automated testing, and release management
- Section 508 accessibility compliance for websites and documents, aligned to FISMA and NIST controls
Managed Cyber Defense
- Continuous monitoring, expert-led alert triage, and point-of-escalation support
- Threat hunting, investigation, and root-cause analysis
- Detection engineering, content tuning, security automation, and response orchestration
- Operational reporting and continuous service improvement
- Managed and co-managed service models for public and private sector organizations
Training and Advisory
- Cybersecurity awareness and role-based training
- RMF and GRC training, templates, and standard operating procedures
- Strategic security advising and program maturity assessments