Professional resume

Stephen M Abbott

Stevo.AI · Cybersecurity & AI enablement

Cybersecurity and engineering leader with 16 years building and scaling security programs in highly regulated enterprise environments. Combines risk governance, exposure management, application and supply-chain security, sensitive-data protection, governed AI-assisted remediation, and hands-on product engineering.

Enterprise systems and security
16 years
Engineers led
Up to 26
Sensitive-data reduction
92%
Open-source dependency reduction
75%+

01

Executive profile

Stephen's career progresses from resilient transaction systems through detection engineering, application security, security data platforms, and enterprise risk leadership. He combines hands-on technical depth with experience scaling teams, advising executives, and turning complex security signals into decisions that leaders and engineers can act on.

His public work extends that operating model into governed agent systems, open security intelligence, software supply-chain research, and polished end-user products. The consistent pattern is powerful capability bounded by evidence, human review, clear ownership, and useful delivery.

02

Professional experience

Director, Cybersecurity

Exposure management · Remediation operations · Developer security

2024-2026

  • Led an 11-person team responsible for remediation operations and Continuous Threat Exposure Management at enterprise scale.
  • Introduced risk-based prioritization, risk quantification, and governed AI-assisted remediation in partnership with executive security leadership.
  • Contributed to enterprise risk-appetite measures and Key Risk Indicators used in recurring board and executive reporting.
  • Built developer-engagement and preventative-control programs that improved ownership and reduced open-source dependencies in source code by more than 75%.
  • Developed security leaders, with team members advancing into senior and director-level positions.

Director, Security Data & Risk Intelligence

Security data platforms · Supply-chain intelligence · Sensitive-data protection

2021-2024

  • Led an engineering organization of up to 26 people delivering platforms for sensitive-data detection, software-composition intelligence, and repository enrichment.
  • Reduced sensitive-data findings in source code by 92%, tripled detection coverage, and improved fidelity through automation with human review.
  • Owned application risk assessments, business-impact analysis, disaster-recovery requirements, and resilience planning for critical platforms.
  • Built risk-intelligence platforms and analytics that strengthened prioritization, governance, and executive decision-making.
  • Partnered across cloud and identity teams to secure infrastructure-as-code pipelines, apply encryption controls, and grow engineers into senior technical roles.

Senior Cybersecurity Engineer, Application Security

SAST · DAST · Mobile testing · Software composition analysis

2019-2021

  • Managed an enterprise application-security tooling portfolio spanning static, dynamic, mobile, and software-composition analysis.
  • Led testing strategy, adoption, process integration, and effectiveness measurement throughout the software-development lifecycle.
  • Embedded scalable application-risk reduction practices directly into engineering workflows.

Senior Security Engineer, Detection & Infrastructure

SIEM · Network visibility · Centralized telemetry

2014-2019

  • Engineered SIEM, full-packet-capture, and centralized logging platforms supporting enterprise threat detection and security operations.
  • Enabled encrypted-traffic inspection to improve network visibility and threat-detection coverage.
  • Deployed globally distributed, highly available security infrastructure across enterprise data centers.
  • Developed incident-response detections from logs, network telemetry, IDS/IPS events, and endpoint-security signals.

Senior Infrastructure Engineer, Resilient Transaction Platforms

Backend services · Operational resilience · Automated delivery

2010-2014

  • Supported backend services for business-critical transaction systems in a highly regulated environment.
  • Maintained performance monitoring for 99.99% availability and helped automate application deployments through CI/CD.
  • Supported disaster-recovery and business-resilience programs for high-stakes systems, building the operational foundation for later security leadership.

03

Focus areas

Governed AI adoption

Designing AI workflows around bounded context, human approval, evidence, rollback, and clear ownership.

AI agent architecture

Building practical agent systems with tool orchestration, MCP, memory, scheduling, browser control, and local-first operation.

Application and supply-chain security

Connecting vulnerability intelligence, dependency analysis, license review, SBOMs, and secure remediation workflows.

AI product engineering

Turning emerging model capabilities into polished web, desktop, API, and command-line products that people can use.

04

Representative work

security-recipes.ai

Open security infrastructure

An open, self-hostable knowledge layer that connects CVE intelligence to reviewed recipes, playbooks, proof requirements, rollback guidance, and bounded agent context.

  • Python
  • FastMCP
  • CVE intelligence
  • Governed action

Shiba Studio

Local-first agent workspace

A desktop-grade environment for orchestrating agents with code editing, browser control, integrations, scheduling, memory, and auditable workflows.

  • TypeScript
  • Next.js
  • SQLite
  • Playwright

OSS Dependency Explorer

Software supply-chain research

A dependency intelligence platform spanning eight package ecosystems, with vulnerability triage, OpenSSF data, license review, SBOM exports, APIs, and MCP access.

  • Go
  • JavaScript
  • OSV
  • SBOM

Pro Response

Multi-provider AI assistant

An AI writing assistant for Slack that also runs as an HTTP API, command-line tool, and Python library, with support for modern hosted model providers.

  • Python
  • Slack
  • OpenAI
  • Anthropic

05

Technical breadth

Languages
TypeScript, Python, JavaScript, Go, and C#
AI and agents
OpenAI, Anthropic, Google, xAI, Ollama, MCP, tool orchestration, and local model workflows
Security
CVE and CISA KEV intelligence, OSV, OpenSSF Scorecard, dependency analysis, SBOMs, and evidence-driven remediation
Product platforms
Next.js, React, Django, FastMCP, Docker, Playwright, SQLite, Redis, WinForms, and OpenCL
Frameworks
NIST CSF 2.0, ISO/IEC 27001, SOC 2, CIS Controls v8, FAIR, NIST AI RMF, ISO/IEC 42001, OWASP ASVS, and NIST SSDF

06

Credentials

Education
BA, Walter Cronkite School of Journalism, Arizona State University
Security certification
Offensive Security Certified Professional (OSCP)
Cloud and risk
AWS Certified Cloud Practitioner · Formal CRISC training
Leadership development
Harvard and Duke University leadership training programs

07

Additional shipped products