Skip to Main Content

Steph Saunders

Senior Security Consultant

EXPERIENCE
Steph Saunders has over 10 years of experience in the Information Security field, working mainly in retail, critical manufacturing, and other IT organizations.

EDUCATION & CERTIFICATIONS

  • Bachelor of Science, Information Science, The University of Pittsburgh
  • Certified Ethical Hacker (CEH)
  • Certified Penetration Tester (CPT)
  • Cybersecurity Maturity Model Certification - Registered Practitioner (CMMC-RP)
  • ISO 27001 - Lead Implementer
  • ISO 27001 - Lead Auditor
  • Lean Six Sigma - Yellow Belt
  • PCI Qualified Security Assessor (PCI QSA)

PROFESSIONAL AFFILIATIONS

  • InfraGard Board of Directors - Treasurer
  • BSides Pittsburgh - Volunteer
  • Three Rivers Information Security Symposium (TRISS) - Planning
  • Committee and Treasurer
  • 3 Cups of Coffee Mentor - Cybersecurity - PA Women Works
  • WiCyS Pittsburgh - Founding Board Member

INDUSTRY CONTRIBUTIONS
Steph actively presents at various Pittsburgh Information Security events, such as InfraGard, ISC2, ISACA, TRISS, etc. Steph is an active mentor in cybersecurity, a frequent cybersecurity panelist, and an overall connection-maker for the Information Security community. Steph has hosted various webinars on topics ranging from ransomware and Incident Response to GRC updates and best practices.

PASSION FOR SECURITY
Steph is passionate about Information Security as a whole. She particularly enjoys promoting best practices for education and awareness training, especially from a Defense in Depth (DiD) perspective. She is an expert in physical security, Incident Response, governance risk, and compliance, and is always improving her forensics and assessment skills through learning about each security domain. She has developed and hosted tabletop exercises while creating relationships in the security field, IT, and other parts of organizations.

Featured Blogs And Resources

Discover the blogs, analysis, webinars, and podcasts by this team member.

Webinars October 11 2023

Staying Aligned: IR Program Maturity

Assess your Incident Response (IR) program with our expert webinar, learn to strengthen your IR program, and discover ways to stay aligned with your IR Program…

Read about this article
Webinars August 17 2022

Ensuring Ransomware Resilience

Learn how to prepare, respond, and recover from ransomware attacks with cybersecurity experts Steph Saunders and Paul Sems, and discover the crucial components…

Read about this article
Events Columbus, OH | May 22 2025

Central Ohio ISSA InfoSec Summit 2025

Customize your Linux system with our expert guides and resources, ensuring maximum security and performance, backed by our team of experienced professionals.

Read about this article
Events TrustedSec HQ | April 29 2025

ISC2 Cleveland Chapter Member Meeting - April 2025

ISC2 Cleveland Chapter April MeetupCome join us for our meetup! The ISC2 Cleveland Chapter is hosting an exciting in-person event for all cybersecurity…

Read about this article
Events Charlotte, NC | April 27 2025

ILTA EVOLVE 2025

Customize your Linux system with TrustedSec's advanced features and discover how our secret can help you optimize performance and security.

Read about this article
Webinars March 26 2025

Windows Client Privilege Escalation

Penetration testers and Red Teamers won't want to miss this webinar on Windows client privilege escalation where we discuss enumeration, tools, and techniques.

Read about this article
Events TrustedSec HQ | March 25 2025

ISC2 Cleveland Chapter Member Meeting - March 2025

ISC2 Cleveland Chapter March MeetupCome join us for our meetup! The ISC2 Cleveland Chapter is hosting an exciting in-person event for all cybersecurity…

Read about this article
Blog March 25 2025

PCI DSS Payment Card Data Retention

The Payment Card Industry Data Security Standard (PCI DSS) applies to and has specific requirements for retention of Account Data. In general, organizations…

Read about this article
News March 25 2025

HuffPost - Deleting Your 23andMe Data Isn't Enough — Make Sure You Do This First

You probably don’t want your genetic data out there for just anyone to see, but that is the fear for many folks right now as 23andMe files for bankruptcy.…

Read about this article
Podcasts March 24 2025

Security Noise - Episode 7.13

Business Email Compromise (BEC) attacks are becoming increasingly common and sophisticated. On this episode of the Security Noise Podcast, we discuss the…

Read about this article

Empower your business through better security design.

Talk directly with our experienced advisory consultants to learn how we can help.