Professional resume
Stephen M Abbott
Cybersecurity and AI Executive
Cybersecurity and AI executive. Director-level at Fortune 100 payments: CTEM, board risk, and a security engineering org of up to 26.
- +1 (775) 599-7046
- Enterprise systems and security
- 16 years
- Cybersecurity
- 11 years
- Enterprise experience
- Fortune 100
- Engineers led
- Up to 26
Professional experience
Director, Cybersecurity
Board risk · Enterprise CTEM · Governed AI
2024-2026
- Led enterprise CTEM and remediation operations with an 11-person team.
- Introduced risk prioritization, quantification, and governed AI-assisted remediation with executive leadership.
- Shaped risk-appetite measures and KRIs for board and executive reporting.
- Cut open-source dependencies more than 75% and improved ownership through engagement and preventative controls.
- Grew security leaders who advanced to senior and director roles.
Director, Security Data & Risk Intelligence
Sensitive-data protection · Risk intelligence · Supply-chain intelligence
2021-2024
- Led an engineering organization of up to 26 delivering sensitive-data detection, composition intelligence, and repository enrichment.
- Cut sensitive-data findings 92%, tripled detection coverage, and raised fidelity through automation with human review.
- Owned application risk assessments, BIA, DR, and resilience planning for critical platforms.
- Drove executive decisions, prioritization, and governance through risk-intelligence platforms.
- Hardened IaC pipelines and encryption with cloud and identity teams; advanced engineers to senior roles.
Senior Cybersecurity Engineer, Application Security
Enterprise AppSec · SDLC integration · Quantified risk reduction
2019-2021
- Owned enterprise AppSec across static, dynamic, mobile, and software-composition analysis.
- Set testing strategy, drove SDLC adoption, and quantified program effectiveness.
- Embedded scalable application-risk reduction into engineering workflows.
Senior Security Engineer, Detection & Infrastructure
SIEM · Network visibility · Detection telemetry
2014-2019
- Built SIEM, full-packet-capture, and centralized logging platforms that powered enterprise detection.
- Expanded network visibility and threat-detection coverage through encrypted-traffic inspection.
- Deployed globally distributed, highly available security infrastructure across data centers.
- Delivered incident-response detections from logs, network telemetry, IDS/IPS, and endpoint signals.
Senior Infrastructure Engineer
Transaction platforms · 99.99%
2010-2014
- Operated backend services for business-critical transaction systems in a regulated environment.
- Sustained 99.99% availability through performance monitoring and automated CI/CD deployments.
- Delivered DR and resilience programs for high-stakes systems.
Focus areas
Security leadership
Board risk, program cadence, and the security org.
AppSec and software supply chain
SBOMs, dependencies, remediation that someone owns.
Governed AI
AI the business can run: named owner, human approval, evidence, a way to roll it back.
Product delivery
I also ship the product, not just the slide.
Founder-built portfolio
Wire Hold
vCISO and AI controls.
The firm I own. Site is going up at wirehold.com.
- NIST CSF 2.0
- NIST AI RMF
- ISO 42001
security-recipes.ai
Turn CVE intelligence into verified, evidence-backed remediation…
Open, self-hostable knowledge layer linking source-backed CVE research to bounded remediation recipes, required evidence, rollback guidance, and human-reviewed outcomes—built for security…
- Python
- Eleventy
- FastMCP
- Nunjucks
OSS Dependency Explorer
Map multi-ecosystem dependencies and surface supply-chain risk…
Supply-chain visibility for security and engineering leaders: maps package dependencies across eight ecosystems and combines vulnerability, repository health, license, and SBOM analysis so…
- Go
- JavaScript
- Gorilla Mux
- Redis
Technical breadth
- Languages
- TypeScript, Python, JavaScript, Go, and C#
- AI and agents
- OpenAI, Anthropic, Google, xAI, Ollama, MCP, tool orchestration, and local model workflows
- Security
- SAST, SCA, DAST, secret-detection engineering, container and image scanning, secure CI/CD pipeline orchestration, CVE and CISA KEV intelligence, OSV, OpenSSF Scorecard, dependency analysis, SBOMs, and evidence-driven remediation
- Product platforms
- Next.js, React, Django, FastMCP, Docker, GitHub Actions, Playwright, SQLite, Redis, WinForms, and OpenCL
- Frameworks
- NIST CSF 2.0, ISO/IEC 27001, SOC 2, CIS Controls v8, FAIR, NIST AI RMF, ISO/IEC 42001, OWASP ASVS, and NIST SSDF
Enterprise platforms
- Application security
- PortSwigger Burp Suite, DefectDojo, Sonatype Nexus, JFrog Artifactory, and GitHub Advanced Security
- Delivery and source
- GitHub Enterprise, GitHub Actions, Dependabot, Jenkins, ArgoCD, and Kubernetes
- Exposure and operations
- Zafran CTEM, NetWitness, and ServiceNow
- Workflow and enablement
- Jira, Confluence, and ChatGPT Enterprise
Credentials
- Education
- BA, Walter Cronkite School of Journalism, Arizona State University
- Certifications
- Offensive Security Certified Professional (OSCP) · AWS Certified Cloud Practitioner
- Training
- CRISC Bootcamp · SpecterOps Adversary Tactics
- Leadership development
- Harvard Leadership Training Course · Duke University Accelerate Your Growth leadership training course
Additional ventures & products
- Stevo.AIGoverned AI operations that critique, revise, and ship only…
- Pro ResponseImprove enterprise writing quality inside Slack—without adding…
- Spare CyclesOrchestrate multi-provider inference through one front…
- Tiny Book Buddies AIIdea to illustrated, narrated children's storybook—entirely in…
- Sonny’s WorldA bilingual English–Spanish learning playground for a small…
- mouseclicker.appRecord, replay, and humanize Windows click workflows from a…