Skip to Main Content

Steph Saunders

Senior Security Consultant

EXPERIENCE
Steph Saunders has over 14 years of experience in the Information Security field, working mainly in retail, critical manufacturing, and other IT organizations.

EDUCATION & CERTIFICATIONS

  • Bachelor of Science, Information Science, The University of Pittsburgh
  • Certified Ethical Hacker (CEH)
  • Certified Penetration Tester (CPT)
  • Cybersecurity Maturity Model Certification - Registered Practitioner (CMMC-RP)
  • ISO 27001 - Lead Implementer
  • ISO 27001 - Lead Auditor
  • Lean Six Sigma - Yellow Belt
  • PCI Qualified Security Assessor (PCI QSA)

PROFESSIONAL AFFILIATIONS

  • Three Rivers Information Security Symposium (TRISS) - Planning Committee and Treasurer
  • WiCyS Pittsburgh - Founding Board Member and Secretary
  • BSides Pittsburgh – Volunteer and awardee of the 2025 Black and Gold Badge
  • 3 Cups of Coffee Mentor - Cybersecurity - PA Women Works
  • InfraGard Board of Directors – Former Treasurer and Retail Sector Chief

INDUSTRY CONTRIBUTIONS
Steph actively presents at various Pittsburgh Information Security events, such as InfraGard, ISC2, ISACA, TRISS, BSides Pittsburgh, etc. Steph is an active mentor in cybersecurity, a frequent cybersecurity panelist and panel moderator, board member for various cyber security groups, and an overall connection-maker for the Information Security community. Steph has hosted various webinars and given talks on topics ranging from ransomware and Incident Response to GRC updates and best practices.

PASSION FOR SECURITY
Steph is passionate about Information Security as a whole. She particularly enjoys promoting best practices for education and awareness training, especially from a Defense in Depth (DiD) perspective. She is an expert in physical security, Incident Response, governance risk, and compliance, and is always improving her forensics and assessment skills through learning about each security domain. She has developed and hosted tabletop exercises while creating relationships in the security field, IT, and other parts of organizations.

Featured Blogs And Resources

Discover the blogs, analysis, webinars, and podcasts by this team member.

Blog May 07 2026

GRC in an AI World - Staying in the Fast Lane Without Losing the Race!

Artificial Intelligence (AI) is the new buzz word on the streets. It’s becoming “the best thing since sliced bread” in the IT world and is being used by…

Read about this article
Webinars December 03 2025

NIST CSF 2.0 - From Compliance to Confidence

During our next webinar, our experts will cover the latest evolution of the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF),…

Read about this article
Blog June 24 2025

NIST CSF 2.0 Ratings and Assessment Methodologies for Scorecards – When the Math isn’t “Mathing”

As a Senior Security Consultant and National Institute of Standards and Technology (NIST) expert, the question I get asked the most is, how do we compare…

Read about this article
Blog January 07 2025

Solving NIST Password Complexities: Guidance From a GRC Perspective

Understand NIST's Digital Identity Guidelines for secure password implementation and access control, ensuring risk-based authentication and minimizing breaches…

Read about this article
Webinars October 11 2023

Staying Aligned: IR Program Maturity

Assess your Incident Response (IR) program with our expert webinar, learn to strengthen your IR program, and discover ways to stay aligned with your IR Program…

Read about this article
Webinars August 17 2022

Ensuring Ransomware Resilience

Learn how to prepare, respond, and recover from ransomware attacks with cybersecurity experts Steph Saunders and Paul Sems, and discover the crucial components…

Read about this article

Empower your business through better security design.

Talk directly with our experienced advisory consultants to learn how we can help.