Skip to Main Content

Steve Maxwell

Senior Security Consultant

EXPERIENCE
Steve Maxwell has 25 years of technical experience ranging from software development to software quality, performance engineering, Information Security, and audit. Before TrustedSec, Steve performed a number of IT functions supporting security initiatives across multiple industries. He has presented to hundreds on topics of automation, performance engineering, and information security.

EDUCATION & CERTIFICATIONS

  • Bachelor of Science, University of Utah
  • Certified Information Systems Security Professional (CISSP)
  • Qualified Security Assessor (QSA)
  • Certified Information Systems Auditor (CISA)
  • Certified Data Privacy Solutions Engineer (CDPSE)
  • ISO 27001 Lead Auditor
  • CMMC Registered Practitioner

PROFESSIONAL AFFILIATIONS
Information Systems Audit and Control Association (ISACA)

PASSION FOR SECURITY
Steve’s passion for security is in helping his clients to improve their security and in preparing them to be ‘the smartest in the room’.

Featured Blogs And Resources

Discover the blogs, analysis, webinars, and podcasts by this team member.

Blog November 14 2023

Book Review - The Definitive Guide to PCI DSS Version 4

As a PCI QSA, I have answered numerous questions about the new PCI DSS Version 4. With over 500 total controls, and at least 100 of them unique to this…

Read about this article
Webinars July 24 2019

Network Segmentation for the Rest of Us! How to get your segmentation project moving toward zero trust.

Implementing network segmentation can limit internal movement, improve access control, and slow down attacks, allowing for more time to react and reducing…

Read about this article
Blog March 30 2021

Strength Training With Transport Cryptology: Part 2

Review the latest PCI Security Standards Council (PCI-SSC) guidelines for evaluating application cipher suites and ensure compliance with version 4.0 standards…

Read about this article
Blog April 16 2026

Dungeons and Daemons

Play Roll for Initiative. Hack the Planet.Dungeons & Daemons is a cybersecurity RPG that drops you into the boots of a Red Team operator on a live…

Read about this article
Webinars April 15 2026

You Had Us at the First Alert: A Guide to Finding Frequently Missed Detections

Join us for this webinar to get a clearer picture of where your detection coverage has blind spots and a practical roadmap for closing them before a real…

Read about this article
Blog April 14 2026

Benchmarking Self-Hosted LLMs for Offensive Security

We put LLMs to the test—let's find out how good AI is at hacking! We walk through six simple challenges with intentionally naïve setups to test how capable…

Read about this article
Events April 09 2026

TrustedSec Livestream - AMA: Detection Engineering in 2026 and Beyond with John Dwyer

Come prepared with your questions and walk away with actionable knowledge to sharpen your detection capabilities.

Read about this article
Blog April 09 2026

IAM the Captain Now – Hijacking Azure Identity Access

I decided to spend some research time diving in depth into Identity and Access Management (IAM) within Microsoft Azure. I am going to show you within this blog…

Read about this article
Blog April 07 2026

Building a Detection Foundation: Part 5 - Correlation in Practice

From Data Sources to DetectionWe've covered a lot of ground in this series: Windows Security events for logon tracking and process execution; PowerShell…

Read about this article
Podcasts April 06 2026

Security Noise - A Goblin, a Ghost, and a Ninja Walk into the Azure Bar

On this episode, Geoff and Skyler are joined by NyxGeek to discuss his suite of Azure bypass techniques. Since these techniques leave no trace, what does it…

Read about this article

Empower your business through better security design.

Talk directly with our experienced advisory consultants to learn how we can help.