Skip to Main Content
All Trimarc services are now delivered through TrustedSec! Learn more

Scott White

Director of Software Security

EXPERIENCE
Scott White is the Director of Software Security for TrustedSec. He joined TrustedSec’s founder, David Kennedy, after years of working together in both global corporate and consulting environments. Scott’s expertise in application security and penetration testing stems from his years of experience ranging from help desk support and system administration to web development and penetration testing.

Scott has been called upon not only academically but also professionally by the FBI and the United States Secret Service as a subject matter expert. Scott has developed several application security programs for large international organizations. As the global application security team lead for a Fortune 1000 company, Scott performed several hundred web application security assessments, including both dynamic and static code analysis, dynamic testing, and reverse engineering. He was instrumental in developing the entire process, from secure design to developer education and awareness, secure coding practices, and to final approval reviews for production.

BOOKS

  • “Metasploit: The Penetration Tester’s Guide” - Technical Editor
  • “The Basics of Web Hacking” - Technical Editor

EDUCATION & CERTIFICATIONS

  • Bachelor of Science, Computer Science, Ohio Northern University (with distinction)
  • Master of Science, Network Security, University of Advancing Technology (Summa Cum Laude)

INDUSTRY CONTRIBUTIONS

  • DerbyCon - CTF Founder & Organizer, Trainer
  • Defcon 16 speaker
  • Numerous publications and presentations to local and national organizations such as OWASP, ISSA, FBI InfraGard, ISACA, AZSPF, SWSPF, etc.

Featured Blogs And Resources

Discover the blogs, analysis, webinars, and podcasts by this team member.

Blog November 17 2017

Full Disclosure: Authenticated Command Execution Vulnerability in pfSense

TrustedSec discovers and responsibly discloses authenticated command injection vulnerability in pfSense, allowing authenticated users to execute commands as…

Read about this article
Blog September 13 2017

Ruby ERB Template Injection

Discovering Ruby/ERB Template Injection vulnerabilities, exploring their potential impact, and learning how to mitigate them.

Read about this article
Blog August 19 2015

Ashley Madison Hacked. Dump Released

The massive Ashley Madison data breach compromises 33 million users, exposing sensitive info, and highlights the site's poor security, forcing a reevaluation…

Read about this article
Webinars June 03 2020

Seeing the Entire Software Security Picture

Discover the entire software security picture with experts Scott White, Geoff Walton, and Rob Simon, providing practical tips and insights for a secure…

Read about this article
Webinars April 15 2026

You Had Us at the First Alert: A Guide to Finding Frequently Missed Detections

Join us for this webinar to get a clearer picture of where your detection coverage has blind spots and a practical roadmap for closing them before a real…

Read about this article
Events TrustedSec HQ | March 31 2026

ISC2 Cleveland Chapter Member Meeting - March 2026

ISC2 Cleveland Chapter March MeetupCome join us for our meetup! The ISC2 Cleveland Chapter is hosting an exciting in-person event for all cybersecurity…

Read about this article
Blog March 26 2026

Policy as Code: Stop Writing Policies and Start Compiling Them

The Problem Nobody Wants to Talk AboutLet me paint a picture most security leaders will recognize.You have 30+ policies living as Word documents on SharePoint.…

Read about this article
Blog March 24 2026

Building a Detection Foundation: Part 4 - Sysmon

Filling the Gaps Native Logging Can'tAt this point in our series, we have Windows Security events capturing logon sessions and process creation, and…

Read about this article
Podcasts March 24 2026

Security Noise - AI is Exploring The Deep Blue CVEs

On this episode of Security Noise, we explore the cutting-edge use of AI in vulnerability research, exploit development, and cybersecurity defense with guests…

Read about this article
News March 20 2026

ABC7 Chicago - March Madness betting, ticket scams targeting college basketball tournament fans

March Madness is in full swing and so are the scams, the latest being fake tickets sales and "bogus" bracket challenges. Advisory Solutions Director Alex…

Read about this article

Empower your business through better security design.

Talk directly with our experienced advisory consultants to learn how we can help.