Professional resume
Stephen M Abbott
Stevo.AI · Cybersecurity & AI enablement
Cybersecurity and engineering leader with 16 years building and scaling security programs in highly regulated enterprise environments. Combines risk governance, exposure management, application and supply-chain security, sensitive-data protection, governed AI-assisted remediation, and hands-on product engineering.
- Email available on request
- GitHubstevologic
- YouTube@MadeItHappenDaily
- X@MadeItHappenX
- TwitchMadeithappen
- Discordmadeithappen3
- Enterprise systems and security
- 16 years
- Engineers led
- Up to 26
- Sensitive-data reduction
- 92%
- Open-source dependency reduction
- 75%+
01
Executive profile
Stephen's career progresses from resilient transaction systems through detection engineering, application security, security data platforms, and enterprise risk leadership. He combines hands-on technical depth with experience scaling teams, advising executives, and turning complex security signals into decisions that leaders and engineers can act on.
His public work extends that operating model into governed agent systems, open security intelligence, software supply-chain research, and polished end-user products. The consistent pattern is powerful capability bounded by evidence, human review, clear ownership, and useful delivery.
02
Professional experience
Director, Cybersecurity
Exposure management · Remediation operations · Developer security
2024-2026
- Led an 11-person team responsible for remediation operations and Continuous Threat Exposure Management at enterprise scale.
- Introduced risk-based prioritization, risk quantification, and governed AI-assisted remediation in partnership with executive security leadership.
- Contributed to enterprise risk-appetite measures and Key Risk Indicators used in recurring board and executive reporting.
- Built developer-engagement and preventative-control programs that improved ownership and reduced open-source dependencies in source code by more than 75%.
- Developed security leaders, with team members advancing into senior and director-level positions.
Director, Security Data & Risk Intelligence
Security data platforms · Supply-chain intelligence · Sensitive-data protection
2021-2024
- Led an engineering organization of up to 26 people delivering platforms for sensitive-data detection, software-composition intelligence, and repository enrichment.
- Reduced sensitive-data findings in source code by 92%, tripled detection coverage, and improved fidelity through automation with human review.
- Owned application risk assessments, business-impact analysis, disaster-recovery requirements, and resilience planning for critical platforms.
- Built risk-intelligence platforms and analytics that strengthened prioritization, governance, and executive decision-making.
- Partnered across cloud and identity teams to secure infrastructure-as-code pipelines, apply encryption controls, and grow engineers into senior technical roles.
Senior Cybersecurity Engineer, Application Security
SAST · DAST · Mobile testing · Software composition analysis
2019-2021
- Managed an enterprise application-security tooling portfolio spanning static, dynamic, mobile, and software-composition analysis.
- Led testing strategy, adoption, process integration, and effectiveness measurement throughout the software-development lifecycle.
- Embedded scalable application-risk reduction practices directly into engineering workflows.
Senior Security Engineer, Detection & Infrastructure
SIEM · Network visibility · Centralized telemetry
2014-2019
- Engineered SIEM, full-packet-capture, and centralized logging platforms supporting enterprise threat detection and security operations.
- Enabled encrypted-traffic inspection to improve network visibility and threat-detection coverage.
- Deployed globally distributed, highly available security infrastructure across enterprise data centers.
- Developed incident-response detections from logs, network telemetry, IDS/IPS events, and endpoint-security signals.
Senior Infrastructure Engineer, Resilient Transaction Platforms
Backend services · Operational resilience · Automated delivery
2010-2014
- Supported backend services for business-critical transaction systems in a highly regulated environment.
- Maintained performance monitoring for 99.99% availability and helped automate application deployments through CI/CD.
- Supported disaster-recovery and business-resilience programs for high-stakes systems, building the operational foundation for later security leadership.
03
Focus areas
Governed AI adoption
Designing AI workflows around bounded context, human approval, evidence, rollback, and clear ownership.
AI agent architecture
Building practical agent systems with tool orchestration, MCP, memory, scheduling, browser control, and local-first operation.
Application and supply-chain security
Connecting vulnerability intelligence, dependency analysis, license review, SBOMs, and secure remediation workflows.
AI product engineering
Turning emerging model capabilities into polished web, desktop, API, and command-line products that people can use.
04
Representative work
security-recipes.ai
Open security infrastructure
An open, self-hostable knowledge layer that connects CVE intelligence to reviewed recipes, playbooks, proof requirements, rollback guidance, and bounded agent context.
- Python
- FastMCP
- CVE intelligence
- Governed action
Shiba Studio
Local-first agent workspace
A desktop-grade environment for orchestrating agents with code editing, browser control, integrations, scheduling, memory, and auditable workflows.
- TypeScript
- Next.js
- SQLite
- Playwright
OSS Dependency Explorer
Software supply-chain research
A dependency intelligence platform spanning eight package ecosystems, with vulnerability triage, OpenSSF data, license review, SBOM exports, APIs, and MCP access.
- Go
- JavaScript
- OSV
- SBOM
Pro Response
Multi-provider AI assistant
An AI writing assistant for Slack that also runs as an HTTP API, command-line tool, and Python library, with support for modern hosted model providers.
- Python
- Slack
- OpenAI
- Anthropic
05
Technical breadth
- Languages
- TypeScript, Python, JavaScript, Go, and C#
- AI and agents
- OpenAI, Anthropic, Google, xAI, Ollama, MCP, tool orchestration, and local model workflows
- Security
- CVE and CISA KEV intelligence, OSV, OpenSSF Scorecard, dependency analysis, SBOMs, and evidence-driven remediation
- Product platforms
- Next.js, React, Django, FastMCP, Docker, Playwright, SQLite, Redis, WinForms, and OpenCL
- Frameworks
- NIST CSF 2.0, ISO/IEC 27001, SOC 2, CIS Controls v8, FAIR, NIST AI RMF, ISO/IEC 42001, OWASP ASVS, and NIST SSDF
06
Credentials
- Education
- BA, Walter Cronkite School of Journalism, Arizona State University
- Security certification
- Offensive Security Certified Professional (OSCP)
- Cloud and risk
- AWS Certified Cloud Practitioner · Formal CRISC training
- Leadership development
- Harvard and Duke University leadership training programs
07
Additional shipped products
- Tiny Book Buddies AIMulti-provider generative storytelling studio
- DOGE Commerce KitNon-custodial commerce toolkit
- DOGE MINERFull-stack mining software and telemetry dashboard
- Mouse ClickerPortable Windows automation application