Current
Ivalua
Change Management Manager
FedRAMP Moderate · SOC 1 Type 2 · SOC 2 Type 2 · ISO 27001 · Australian Government ISM · self-managed infrastructure
Ivalua is an enterprise source-to-pay and procurement platform serving customers in defense, government and financial services. Its security program is built on NIST SP 800-53 and ISO/IEC 27001, and it holds SOC 1 Type 2 (SSAE 18 / ISAE 3402), SOC 2 Type 2 and ISO 27001, certified in November 2022 and audited by Schellman.
The detail that makes the change-control problem genuinely hard here is the infrastructure. Ivalua does not run on a hyperscaler. It operates its own environment across nine data-centre providers in four geographic regions — Montreal, Washington DC, Chicago, San Francisco, Seattle, Paris and Singapore. Coordinating a change across that estate is not a pipeline concern; it is a scheduling, sequencing and evidence problem across independent facilities.
The SOC 1 is the part most engineers underestimate. It exists because customers' own auditors rely on Ivalua's change controls when forming an opinion on those customers' financial reporting. A weak change record here does not just fail an internal audit — it propagates into somebody else's SOX opinion.
The federal work sits on top of that. I led a FedRAMP Moderate authorization through an Agency ATO on Azure Government (GCC). That covered defining the authorization boundary and its architecture diagrams, implementing controls against NIST SP 800-53, hardening to DISA STIG and CIS Level 1 and Level 2 benchmarks, implementing zero-trust networking, enforcing FIPS-validated (CMVP) cryptography for data at rest and in transit, authoring the SSP and its control narratives, driving POA&M remediation and the exception process, and standing up continuous monitoring along with the operational firefighting rotation that keeps it honest after the ATO letter.
In 2025 I also led ISM readiness and remediation advisory for selling into Australian government, at the OFFICIAL classification level — roughly six months from build through audit to authorization.
- Sector
- Enterprise source-to-pay, procurement
- Control environment
- SOC 1 Type 2, SOC 2 Type 2, ISO 27001
- Framework basis
- NIST SP 800-53, ISO/IEC 27001
- FedRAMP
- Moderate, Agency ATO, Azure Government (GCC)
- ISM
- Readiness and remediation advisory, OFFICIAL, 2025
- Infrastructure
- Self-managed, nine providers, four regions