Skip to Main Content

Steph Saunders

Senior Security Consultant

EXPERIENCE
Steph Saunders has over 10 years of experience in the Information Security field, working mainly in retail, critical manufacturing, and other IT organizations.

EDUCATION & CERTIFICATIONS

  • Bachelor of Science, Information Science, The University of Pittsburgh
  • Certified Ethical Hacker (CEH)
  • Certified Penetration Tester (CPT)
  • Cybersecurity Maturity Model Certification - Registered Practitioner (CMMC-RP)
  • ISO 27001 - Lead Implementer
  • ISO 27001 - Lead Auditor
  • Lean Six Sigma - Yellow Belt
  • PCI Qualified Security Assessor (PCI QSA)

PROFESSIONAL AFFILIATIONS

  • InfraGard Board of Directors - Treasurer
  • BSides Pittsburgh - Volunteer
  • Three Rivers Information Security Symposium (TRISS) - Planning
  • Committee and Treasurer
  • 3 Cups of Coffee Mentor - Cybersecurity - PA Women Works
  • WiCyS Pittsburgh - Founding Board Member

INDUSTRY CONTRIBUTIONS
Steph actively presents at various Pittsburgh Information Security events, such as InfraGard, ISC2, ISACA, TRISS, etc. Steph is an active mentor in cybersecurity, a frequent cybersecurity panelist, and an overall connection-maker for the Information Security community. Steph has hosted various webinars on topics ranging from ransomware and Incident Response to GRC updates and best practices.

PASSION FOR SECURITY
Steph is passionate about Information Security as a whole. She particularly enjoys promoting best practices for education and awareness training, especially from a Defense in Depth (DiD) perspective. She is an expert in physical security, Incident Response, governance risk, and compliance, and is always improving her forensics and assessment skills through learning about each security domain. She has developed and hosted tabletop exercises while creating relationships in the security field, IT, and other parts of organizations.

Featured Blogs And Resources

Discover the blogs, analysis, webinars, and podcasts by this team member.

Webinars October 11 2023

Staying Aligned: IR Program Maturity

Assess your Incident Response (IR) program with our expert webinar, learn to strengthen your IR program, and discover ways to stay aligned with your IR Program…

Read about this article
Webinars August 17 2022

Ensuring Ransomware Resilience

Learn how to prepare, respond, and recover from ransomware attacks with cybersecurity experts Steph Saunders and Paul Sems, and discover the crucial components…

Read about this article
Blog April 16 2026

Dungeons and Daemons

Play Roll for Initiative. Hack the Planet.Dungeons & Daemons is a cybersecurity RPG that drops you into the boots of a Red Team operator on a live…

Read about this article
Webinars April 15 2026

You Had Us at the First Alert: A Guide to Finding Frequently Missed Detections

Join us for this webinar to get a clearer picture of where your detection coverage has blind spots and a practical roadmap for closing them before a real…

Read about this article
Blog April 14 2026

Benchmarking Self-Hosted LLMs for Offensive Security

We put LLMs to the test—let's find out how good AI is at hacking! We walk through six simple challenges with intentionally naïve setups to test how capable…

Read about this article
Events April 09 2026

TrustedSec Livestream - AMA: Detection Engineering in 2026 and Beyond with John Dwyer

Come prepared with your questions and walk away with actionable knowledge to sharpen your detection capabilities.

Read about this article
Blog April 09 2026

IAM the Captain Now – Hijacking Azure Identity Access

I decided to spend some research time diving in depth into Identity and Access Management (IAM) within Microsoft Azure. I am going to show you within this blog…

Read about this article
Blog April 07 2026

Building a Detection Foundation: Part 5 - Correlation in Practice

From Data Sources to DetectionWe've covered a lot of ground in this series: Windows Security events for logon tracking and process execution; PowerShell…

Read about this article
Podcasts April 06 2026

Security Noise - A Goblin, a Ghost, and a Ninja Walk into the Azure Bar

On this episode, Geoff and Skyler are joined by NyxGeek to discuss his suite of Azure bypass techniques. Since these techniques leave no trace, what does it…

Read about this article
Blog April 02 2026

Reduce Repetition and Free up Time With Mobile File Extractor

If you do the same thing three times, automate it. Introducing Mobile Data Extractor, a Python tool that handles the repetitive work of mobile app data…

Read about this article

Empower your business through better security design.

Talk directly with our experienced advisory consultants to learn how we can help.