John Stevenson

John Stevenson Email and Phone Number

Managing Director, Cloud & AI Security Lead at Protiviti @ Protiviti
About John Stevenson

Seasoned and results-oriented technology executive with distinguished career developing information security and information technology programs for top global companies and government entities. Extensive and in-depth knowledge of complex security and regulatory requirements governing sensitive company data. Leverage combination of technical aptitude and business acumen to develop long-range plans guiding IT / IS strategy, infrastructure, compliance, policies / procedures, and operations. Areas of Expertise:• Effective Long-term Technology Planning• Nationwide & Global Experience• Executive- / Board-level Influencing• Disaster Recovery / Business Continuity• Entrepreneurial / High-growth Organizations • Risk Assessment / Risk Management• Business Transformation / Reengineering• Regulatory / Industry Standard Compliance• Incident Response / Threat Remediation• Win-Win Contract / Partnership NegotiationsProfessional Development Certifications: C|CISO, CISA, CGEIT, CRISCAffiliations & Activities: Leading Member of Participating Organization, PCI Security Standards Council, Member, ISSA CISO Executive Group • Member & Speaking Committee Member, ISACA • Presenter, Sarbanes-Oxley Symposiums • Member, CIO Executive Council • Member, Payments Processing Information Processing Council (PPISC) / FS-ISACTechnical Proficiencies / Standards: NIST, PCI DSS, PA DSS, HIPAA, HITECH, OCR, OCC, OIC, OWASP, ITIL, ISO, SSAE16, SAS-70, SOX, Cloud Computing, Virtualization, Windows, UNIX, Solaris, Linux, Imperva, HSM, Encryption, Dukpt, Cisco Routers, Cisco Switches, Cisco PIX & ASA Firewalls, Checkpoint Firewalls, Palo Alto Firewalls, F5 load balancers, Tripwire, Arcsight, Splunk & RSA EnVision SIEM, RSA Data Loss Prevention, BackTrack, Kali Linux, Metasploit Pro, Symantec Endpoint Protection & Altiris, NIDS, HIDS, Nessus / McAfee / Foundstone, Qualys & Rapid7 Vulnerability Scanners, Checkpoint, Skybox, Perl, Korn Shell, CSH, various Firewall Appliances.

John Stevenson's Current Company Details
Protiviti

Protiviti

View
Managing Director, Cloud & AI Security Lead at Protiviti
John Stevenson Work Experience Details
  • Protiviti
    Managing Director, Cloud & Ai Security Lead
    Protiviti Mar 2021 - Present
    Menlo Park, California, Us
  • Pwc
    Managing Director, Cloud Security Lead
    Pwc Aug 2017 - Mar 2021
    Gb
  • Accenture
    Senior Manager - North America Retail & Payment Security Lead
    Accenture Sep 2013 - Aug 2017
    Dublin 2, Ie
    ♦ Lead large team responsible for designing and delivering a World Class, leading edge 100% cloud based (Microsoft Azure) ecommerce system for high speed dynamic transactions.♦ Invented and filed two US Patents for Cloud Security Frameworks and Cloud Security Threat Intelligence♦ Lead large teams for Accenture’s top clients and set strategic direction for Retail & Payment Security offerings.♦ Successfully lead large Information Security team & efforts related to divestiture of $24B Bank & Credit Card Issuer, which included discovery, planning & analysis of existing environments as well as design & integration of new standalone publicly traded entity.♦ Effectively sold and delivered multi-million dollar engagement to assess and revitalize Payment Processors with PCI DSS 3.0 requirements, IT operational components, software development modernization and additional security enhancements.♦ Lead efforts on several RFP’s relating to information security managed service and compliance offerings.
  • First American Payment Systems
    Vice President Of Information Security & Compliance
    First American Payment Systems Feb 2012 - Aug 2013
    CISO level role responsible for Information Security and Compliance teams at a large ACH & payment card processor with multiple subsidiaries & global presence. Subsidiaries include: iATS Payments, Govolution, GoEmerchant, Certified Payment Processing “CPP”, Elliot Management Group “EMG”, TransTech Metchant Group “TMG-360”, Summit Merchant Solutions “SMS-360”, CeresNational, 1stPayGateway. Current specific duties & selected accomplishments: ♦ Oversee all aspects of strategic planning including goals, metrics, budgeting & organizational objectives.♦ Create & deliver successful Information Security and Compliance program that includes 3-5 year roadmap, various technology implementations, risk management, governance & business continuity.♦ Establish and maintain comprehensive audits for adherence to PCI DSS, PA DSS, SSAE16, NIST, ITIL and various other industry standards. Includes four separate PCI DSS compliance audits annually.♦ Develop, implement and monitor enterprise security policies & procedures as they relate to the parent organization as well as subsidiaries.♦ Responsible for internal and external relationship management with various business leaders, the Board of Directors & vendors of all organizations.♦ Maintain daily security operations of the organization.♦ Wrote the business plan for Executive Management to launch a new mobile (M+Terminal) & tablet (1stPayPOS) P2PE payment platform which included researching competitors, creating map of competitive advantages & identifying barriers to entry.♦ Lead technology efforts to design and integrate mobile P2PE payments platform. This included researching mobile swipe readers from ID TECH, MagTek, FutureX and others. Gateway integration, encryption at the swipe, key injection, audit considerations and HSM decryption were all part of the scope.♦ Completed over 90 specific projects in the first 12 months of service all of which were within budget thresholds.
  • Hp / Federal Reserve Bank
    Information Security Officer Consultant
    Hp / Federal Reserve Bank Feb 2011 - Feb 2012
    Lead development, implementation, and management of robust security infrastructure and services handling trillions of dollars in transactions annually. Serve as key liaison with executives, managers, and end-users, as well as representatives from various government agencies, including the Department of the Treasury branches and Federal Reserve System employees. Selected Accomplishments:♦ Initiated and led system-wide information security self-assessment to determine maturity level following Gartner research recommendations.♦ Responsible for compliance and information security of National Critical Infrastructure applications such as Debit Gateway, Pay,Gov, various IRS applications, various ACH & Funds Transfer applications and other Governmental payment applications.♦ Assisted with security & compliance design of integrated Social Security System fraud checks & balance applications for the U.S. Government.♦ Established and launched long-term strategy to increase Capability Maturity Model (CMM) level to meet industry standards, best practices, and corporate vision / objectives.♦ Facilitated and supported federal government audits, Attorney General audits, Treasury and Financial Management Service Audits, PCI Level 1 audits, National Critical Infrastructure audits, Government Accountability Office audits, SA&A Certification & Accreditation audits, and internal audits.♦ Cultivated excellent professional relationships with Federal Reserve and Department of the Treasury personnel to drive expansion and improvement of security model and ensured alignment with NIST, PCI, OWASP, ITIL, and ISO 27001 / 27002 industry standards.♦ Managed team in developing technical requirements / design baselines, program execution plans, technical risk assessments, scope / configuration management, schedules, and budgets.
  • Accelerated Security, Inc.
    Partner
    Accelerated Security, Inc. Nov 2003 - Mar 2011
    Led business operations, client relations, contracting, cost control, and strategic planning for start-up information security provider. Established strategic partnerships with professional organizations and companies to increase client base and strengthen brand. Designed and implemented client-specific security policies, procedures, and awareness programs; managed numerous compliance projects; directed security administration and evaluations. Handled all aspects of technology including, planning, implementation, support, information security, daily operations, technology audits and reporting to Board of Directors and executives management. Selected Engagements & Accomplishments:♦ Recruited and mentored top-performing, global team of 13 consultants, grew revenue to $800K, and maintained 53% profit margin within first eight months.♦ Negotiated and closed joint venture deals with accounting firms to perform Information Technology Audit and Security aspects of audit engagements.♦ Ensured compliance with PCI DSS, PA-DSS, SOX, OIC, OCR, HIPAA, HITECH, ITIL and ISO 27001/27002 requirements; identified and resolved gaps, implemented IT controls, assisted with remediation efforts and developed comprehensive plans to meet all governance requirements.♦ Collaborated with OCC to audit Pier 1 Imports Bank.♦ Managed flawless migration of $200M datacenter from Ashburn, VA to Plano, TX for a Fortune 500 financial company; oversaw security at Plano and assisted with security at Richmond, VA location.♦ Implemented effective strategy to increase marketing penetration for data networking services; negotiated numerous contracts valued at $2.2M annually ($16M+ over the life of the contract) ♦ Key clients included Lockheed Martin, PEMCO Mutual Insurance Company, PEMCO Technologies, McAfee, Mouser Electronics, Pier 1 Imports, Boeing, Lennox International, Ernst & Young, and Thermo Electron.
  • Accelerated Security, Inc.
    Partner & Chief Information Security Officer Consultant
    Accelerated Security, Inc. Feb 2010 - Feb 2011
    Consulted with diverse clients to devise, introduce, and deploy extensive Vulnerability Management Program meeting Payment Card Industry Data Security Standards (PCI DSS). Leveraged expertise to architect proven strategies to improve security operations with an emphasis on surpassing PCI DSS benchmarks. Acted as central point-of-contact for quarterly scans, remediation efforts, project support, and systems analysis. Managed and coordinated support for annual PCI audits. Selected Accomplishments:♦ Drove measurable improvements to vulnerability scanning and technical environment reporting.♦ Conducted enterprise-wide vulnerability scans and oversaw remediation process through implementation of patches and correction of configuration issues across multiple platforms.♦ Defined security baselines for individual system usage requirements and led development and documentation of corporate security standards.♦ Instrumental in assisting global corporation to achieve compliance to highly complex security standards, including PCI DSS, ITIL, and SOX.♦ Benchmarked several Information Security programs against ISO 27002, HIPAA, PCI, Sarbanes-Oxley and NIST industry standards to determine and remediate gaps.
  • Accelerated Security, Inc. For Pemco Corporation
    Partner & Chief Information Security Officer Consultant
    Accelerated Security, Inc. For Pemco Corporation Jun 2008 - Feb 2010
    Recruited to develop Information Security, Risk Management, and Corporate Compliance programs for PEMCO and subsidiaries. Partnered with executive management to lead strategic planning for innovative fully compliant security programs and policies. Managed team in all aspects of program / policy development, maintenance, training, and enforcement; directed response to security and fraud investigations. Created audit plans and internal controls to meet SAS-70 Type II and PCI Level 1 Payment Gateway audit requirements. Worked closely with Visa & MasterCard to adhere to various standards for custom Fraud Management systems along with PEMCO Technologies’ Issuing Bank policies / procedures. Ensured robust application security across all environments, including credit card payment systems and mainframes. Prepared regular reports on Risk Management and Compliance Program. Selected Accomplishments:♦ Instrumental in evaluating & recommending various virtualization, cloud computing, secure data center and cutting edge technologies with quick ROI and low total cost of ownership.♦ Championed transition from reactive to advanced proactive approach to Information Security program.♦ Designed and launched world-class enterprise Vulnerability Management Program for PEMCO and PEMCO Mutual Insurance Company.♦ Delivered 60+ Information Security and Compliance projects on time and under budget under an aggressive one-year timeframe.♦ Completely prepared infrastructure, compliance and security of PEMCO technologies for acquisition.♦ Worked actively with the Executive Management team to meet with several prospective buyers & ultimately sold PEMCO Technologies to Jack Henry & Associates.
  • Verizon
    Lead Security Architect
    Verizon 2002 - 2003
    Basking Ridge, Nj, Us
  • Bank Of America
    Senior It Security Specialist
    Bank Of America 2001 - 2002
    Charlotte, Nc, Us
  • Southwest Securities
    Senior Unix & Security Administrator
    Southwest Securities 2000 - 2000
    Dallas, Tx, Us

John Stevenson Skills

Information Security Security Information Security Management Disaster Recovery Pci Dss It Audit Risk Management Information Technology Business Continuity Network Security Cloud Computing Itil Data Center Vendor Management Management Governance Iso 27001 Vulnerability Management It Strategy It Management Computer Security Virtualization Sdlc Risk Assessment Program Management Business Analysis Cisa Cissp Enterprise Architecture Application Security Databases Encryption Security Management Business Intelligence Security Policy Cobit Enterprise Risk Management Vulnerability Assessment It Operations It Service Management Penetration Testing Security Audits Visio Payment Industry Incident Management Pmp Vmware Architecture Windows Server Identity Management

John Stevenson Education Details

  • Texas Christian University - M.J. Neeley School Of Business
    Texas Christian University - M.J. Neeley School Of Business
    General

Frequently Asked Questions about John Stevenson

What company does John Stevenson work for?

John Stevenson works for Protiviti

What is John Stevenson's role at the current company?

John Stevenson's current role is Managing Director, Cloud & AI Security Lead at Protiviti.

What is John Stevenson's email address?

John Stevenson's email address is js****@****ign.com

What is John Stevenson's direct phone number?

John Stevenson's direct phone number is +121440*****

What schools did John Stevenson attend?

John Stevenson attended Texas Christian University - M.j. Neeley School Of Business.

What skills is John Stevenson known for?

John Stevenson has skills like Information Security, Security, Information Security Management, Disaster Recovery, Pci Dss, It Audit, Risk Management, Information Technology, Business Continuity, Network Security, Cloud Computing, Itil.

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Aero Online

Your AI prospecting assistant

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.