Skip to Main Content

Steve Maxwell

Senior Security Consultant

EXPERIENCE
Steve Maxwell has 25 years of technical experience ranging from software development to software quality, performance engineering, Information Security, and audit. Before TrustedSec, Steve performed a number of IT functions supporting security initiatives across multiple industries. He has presented to hundreds on topics of automation, performance engineering, and information security.

EDUCATION & CERTIFICATIONS

  • Bachelor of Science, University of Utah
  • Certified Information Systems Security Professional (CISSP)
  • Qualified Security Assessor (QSA)
  • Certified Information Systems Auditor (CISA)
  • Certified Data Privacy Solutions Engineer (CDPSE)
  • ISO 27001 Lead Auditor
  • CMMC Registered Practitioner

PROFESSIONAL AFFILIATIONS
Information Systems Audit and Control Association (ISACA)

PASSION FOR SECURITY
Steve’s passion for security is in helping his clients to improve their security and in preparing them to be ‘the smartest in the room’.

Featured Blogs And Resources

Discover the blogs, analysis, webinars, and podcasts by this team member.

Blog November 14 2023

Book Review - The Definitive Guide to PCI DSS Version 4

As a PCI QSA, I have answered numerous questions about the new PC DSS Version 4. With over 500 total controls, and at least 100 of them unique to this version,…

Read about this article
Webinars July 24 2019

Network Segmentation for the Rest of Us! How to get your segmentation project moving toward zero trust.

We will share information on both planning and execution to ensure a secure, efficient, and successful network segmentation process.

Read about this article
Blog March 30 2021

Strength Training With Transport Cryptology: Part 2

In part 1 of this blog series, we explored objective standards for evaluating application cipher suites using the National Institute of Standards and…

Read about this article
Events Mesa, AZ | February 14 2025

CactusCon 2025

TrustedSec is proud to sponsor and have a booth at CactusCon this year! Three of our consultants will be giving talks as well.

Read about this article
Webinars February 11 2025

2024 Conference Roundup

Join our panelists David Kennedy, Justin Elze, Jason Lang, and Oddvar Moe for their firsthand accounts and perspectives on what people were talking about at…

Read about this article
Blog February 06 2025

The Hidden Trap in the PCI DSS SAQ A Changes

The Payment Card Industry Security Standards Council (PCI SSC) just announced a change to Self Assessment Questionnaire A (SAQ A). The change eliminates two…

Read about this article
Podcasts February 04 2025

Security Noise - Episode 7.10

Authentication in 2025

Read about this article
Blog January 23 2025

Operating Inside the Interpreted: Offensive Python

IntroductionEvery once in a while, I get the urge to go back and revisit older techniques that used to be popular but have fallen out of favor with the…

Read about this article
News January 21 2025

TrustedSec Tech Brief - January 2025

Carlos Perez walks us through several major vulnerabilities and patches from early January 2025, including a critical Fortinet FortiGate zero-day vulnerability.

Read about this article
Podcasts January 17 2025

Security Noise - Episode 7.9

On this episode of the Security Noise Podcast, we discuss user enumeration on Azure and "presence data" in Microsoft Teams with nyxgeek.

Read about this article

Empower your business through better security design.

Talk directly with our experienced advisory consultants to learn how we can help.