Professional resume

Stephen M Abbott

Cybersecurity and AI Executive

Cybersecurity and AI executive. Director-level at Fortune 100 payments: CTEM, board risk, and a security engineering org of up to 26.

Enterprise systems and security
16 years
Cybersecurity
11 years
Enterprise experience
Fortune 100
Engineers led
Up to 26

Professional experience

Director, Cybersecurity

Board risk · Enterprise CTEM · Governed AI

2024-2026

  • Led enterprise CTEM and remediation operations with an 11-person team.
  • Introduced risk prioritization, quantification, and governed AI-assisted remediation with executive leadership.
  • Shaped risk-appetite measures and KRIs for board and executive reporting.
  • Cut open-source dependencies more than 75% and improved ownership through engagement and preventative controls.
  • Grew security leaders who advanced to senior and director roles.

Director, Security Data & Risk Intelligence

Sensitive-data protection · Risk intelligence · Supply-chain intelligence

2021-2024

  • Led an engineering organization of up to 26 delivering sensitive-data detection, composition intelligence, and repository enrichment.
  • Cut sensitive-data findings 92%, tripled detection coverage, and raised fidelity through automation with human review.
  • Owned application risk assessments, BIA, DR, and resilience planning for critical platforms.
  • Drove executive decisions, prioritization, and governance through risk-intelligence platforms.
  • Hardened IaC pipelines and encryption with cloud and identity teams; advanced engineers to senior roles.

Senior Cybersecurity Engineer, Application Security

Enterprise AppSec · SDLC integration · Quantified risk reduction

2019-2021

  • Owned enterprise AppSec across static, dynamic, mobile, and software-composition analysis.
  • Set testing strategy, drove SDLC adoption, and quantified program effectiveness.
  • Embedded scalable application-risk reduction into engineering workflows.

Senior Security Engineer, Detection & Infrastructure

SIEM · Network visibility · Detection telemetry

2014-2019

  • Built SIEM, full-packet-capture, and centralized logging platforms that powered enterprise detection.
  • Expanded network visibility and threat-detection coverage through encrypted-traffic inspection.
  • Deployed globally distributed, highly available security infrastructure across data centers.
  • Delivered incident-response detections from logs, network telemetry, IDS/IPS, and endpoint signals.

Senior Infrastructure Engineer

Transaction platforms · 99.99%

2010-2014

  • Operated backend services for business-critical transaction systems in a regulated environment.
  • Sustained 99.99% availability through performance monitoring and automated CI/CD deployments.
  • Delivered DR and resilience programs for high-stakes systems.

Focus areas

Security leadership

Board risk, program cadence, and the security org.

AppSec and software supply chain

SBOMs, dependencies, remediation that someone owns.

Governed AI

AI the business can run: named owner, human approval, evidence, a way to roll it back.

Product delivery

I also ship the product, not just the slide.

Founder-built portfolio

Wire Hold

vCISO and AI controls.

The firm I own. Site is going up at wirehold.com.

  • NIST CSF 2.0
  • NIST AI RMF
  • ISO 42001

security-recipes.ai

Turn CVE intelligence into verified, evidence-backed remediation…

Open, self-hostable knowledge layer linking source-backed CVE research to bounded remediation recipes, required evidence, rollback guidance, and human-reviewed outcomes—built for security…

  • Python
  • Eleventy
  • FastMCP
  • Nunjucks

OSS Dependency Explorer

Map multi-ecosystem dependencies and surface supply-chain risk…

Supply-chain visibility for security and engineering leaders: maps package dependencies across eight ecosystems and combines vulnerability, repository health, license, and SBOM analysis so…

  • Go
  • JavaScript
  • Gorilla Mux
  • Redis

Technical breadth

Languages
TypeScript, Python, JavaScript, Go, and C#
AI and agents
OpenAI, Anthropic, Google, xAI, Ollama, MCP, tool orchestration, and local model workflows
Security
SAST, SCA, DAST, secret-detection engineering, container and image scanning, secure CI/CD pipeline orchestration, CVE and CISA KEV intelligence, OSV, OpenSSF Scorecard, dependency analysis, SBOMs, and evidence-driven remediation
Product platforms
Next.js, React, Django, FastMCP, Docker, GitHub Actions, Playwright, SQLite, Redis, WinForms, and OpenCL
Frameworks
NIST CSF 2.0, ISO/IEC 27001, SOC 2, CIS Controls v8, FAIR, NIST AI RMF, ISO/IEC 42001, OWASP ASVS, and NIST SSDF

Enterprise platforms

Application security
PortSwigger Burp Suite, DefectDojo, Sonatype Nexus, JFrog Artifactory, and GitHub Advanced Security
Delivery and source
GitHub Enterprise, GitHub Actions, Dependabot, Jenkins, ArgoCD, and Kubernetes
Exposure and operations
Zafran CTEM, NetWitness, and ServiceNow
Workflow and enablement
Jira, Confluence, and ChatGPT Enterprise

Credentials

Education
BA, Walter Cronkite School of Journalism, Arizona State University
Certifications
Offensive Security Certified Professional (OSCP) · AWS Certified Cloud Practitioner
Training
CRISC Bootcamp · SpecterOps Adversary Tactics
Leadership development
Harvard Leadership Training Course · Duke University Accelerate Your Growth leadership training course

Additional ventures & products

  • Stevo.AIGoverned AI operations that critique, revise, and ship only…
  • Pro ResponseImprove enterprise writing quality inside Slack—without adding…
  • Spare CyclesOrchestrate multi-provider inference through one front…
  • Tiny Book Buddies AIIdea to illustrated, narrated children's storybook—entirely in…
  • Sonny’s WorldA bilingual English–Spanish learning playground for a small…
  • mouseclicker.appRecord, replay, and humanize Windows click workflows from a…