Skip to Main Content

Steph Saunders

Senior Security Consultant

EXPERIENCE
Steph Saunders has over 10 years of experience in the Information Security field, working mainly in retail, critical manufacturing, and other IT organizations.

EDUCATION & CERTIFICATIONS

  • Bachelor of Science, Information Science, The University of Pittsburgh
  • Certified Ethical Hacker (CEH)
  • Certified Penetration Tester (CPT)
  • Cybersecurity Maturity Model Certification - Registered Practitioner (CMMC-RP)
  • ISO 27001 - Lead Implementer
  • ISO 27001 - Lead Auditor
  • Lean Six Sigma - Yellow Belt
  • PCI Qualified Security Assessor (PCI QSA)

PROFESSIONAL AFFILIATIONS

  • InfraGard Board of Directors - Treasurer
  • BSides Pittsburgh - Volunteer
  • Three Rivers Information Security Symposium (TRISS) - Planning
  • Committee and Treasurer
  • 3 Cups of Coffee Mentor - Cybersecurity - PA Women Works
  • WiCyS Pittsburgh - Founding Board Member

INDUSTRY CONTRIBUTIONS
Steph actively presents at various Pittsburgh Information Security events, such as InfraGard, ISC2, ISACA, TRISS, etc. Steph is an active mentor in cybersecurity, a frequent cybersecurity panelist, and an overall connection-maker for the Information Security community. Steph has hosted various webinars on topics ranging from ransomware and Incident Response to GRC updates and best practices.

PASSION FOR SECURITY
Steph is passionate about Information Security as a whole. She particularly enjoys promoting best practices for education and awareness training, especially from a Defense in Depth (DiD) perspective. She is an expert in physical security, Incident Response, governance risk, and compliance, and is always improving her forensics and assessment skills through learning about each security domain. She has developed and hosted tabletop exercises while creating relationships in the security field, IT, and other parts of organizations.

Featured Blogs And Resources

Discover the blogs, analysis, webinars, and podcasts by this team member.

Webinars October 11 2023

Staying Aligned: IR Program Maturity

Join Senior Security Consultant Steph Saunders (CEH, CPT, CMMC-RP) to discover ways you can stay aligned with your IR Program Maturity.

Read about this article
Webinars August 17 2022

Ensuring Ransomware Resilience

In this insightful and interactive discussion, you’ll hear cyber security experts Steph Saunders and Paul Sems discuss the relevant components of how you…

Read about this article
Webinars December 18 2024

The Lost Underground

Join TrustedSec Principal Security Consultant Mike Felch for an eye-opening journey into the lost underground, where ingenuity, disobedience, and complexity…

Read about this article
Webinars December 04 2024

BEC Basics: Your First Step to Thwarting Email Scams

Join Senior Security Consultant Steven Erwin and Security Consultant Caroline Fenstermacher as they cover the basics of BEC analysis, providing participants…

Read about this article
Blog December 03 2024

Discovering a Deserialization Vulnerability in LINQPad

Like most red teamers, I spend quite a lot of time looking for novel vulnerabilities that could be used for initial access or lateral movement. Recently, my…

Read about this article
Blog November 21 2024

A 5-Minute Guide to HTTP Response Codes

If you've done any network scanning or application testing, you've run into your fair share of HTTP response codes. If not, these codes will show up in most…

Read about this article
Events TrustedSec HQ | November 20 2024

WiCyS Ransomware Panel & Networking Event

Join us for an insightful discussion with the Women in Cyber Security (WiCyS) Northeast Ohio Affiliate members!

Read about this article
Webinars November 20 2024

Navigating Compliance: FCI and CUI Requirements for Federal Contractors

TrustedSec Advisory Compliance Services Practice Lead Chris Camejo provides a comprehensive overview of the definition, scope, and protection requirements for…

Read about this article
News November 19 2024

TrustedSec Tech Brief - November 2024

Director of Security Intelligence Carlos Perez covers vulnerabilities and zero days for November 2024.

Read about this article
Podcasts November 15 2024

Security Noise - Episode 7.6

Ghost in The Machine: Hardware Hacking w/ Rob Simon

Read about this article

Empower your business through better security design.

Talk directly with our experienced advisory consultants to learn how we can help.