Scott Kennedy Email and Phone Number
Scott Kennedy work email
- Valid
Scott Kennedy personal email
- Valid
Scott Kennedy phone numbers
Experienced Information Security Executive with a proven track record of building and leading large-scale global security programs.- Successfully guided multiple SaaS businesses through security and compliance program development, achieving 5+ SOC 2 Type 2 audits from inception to maturity.- Implemented Product Security, Secure Software Development Lifecycle (SSDLC), and DevSecOps strategies to reduce risk and improve application security resilience in production.- Directed comprehensive security, compliance, & privacy initiatives for a leading Artificial Intelligence (AI) platform and suite of products.- Expertise in full-stack security, governance, risk management, compliance, IoT security, cloud security, application security, & DevSecOps.- Agile mindset and accomplished at building consensus across organizations, with a focus on fostering security awareness at all levels.- Extensive startup experience in roles such as VP of Information Security & Privacy, Director of Cybersecurity, Head of Cloud Security, Security Architect, and Lead Security Engineer.- Certifications: CCISO, DDN-QTE, CISSP, CCSP, CSSLP, CISM, CISA, CCSK, GPEN, GWAPT.- Proven track record of building & leading security programs to maintain compliance with SOC 2, ISO 27001, GDPR, CCPA, PCI, FedRAMP, HIPAA, NIST 800-53, & NIST CSF.- Passionate about the intersection of innovation & security, always learning & always seeking to solve problems with creativity & out-of-the-box thinking.- vCISO, GRC SME, Innovative Security Solutions Architect, Servant Leader, Trusted Advisor, Resiliency Advocate, Pioneer, Strategist, Visionary, Entrepreneur, “Tip of the spear”---Highlights:-Security Leadership: Deep experience in guiding SaaS and AI platforms through compliance, privacy, and full-stack security.-Innovation-Driven: Passionate about the intersection of Innovation & Security. Always seeking to apply creative solutions to complex security challenges.-Trusted Expertise: A seasoned security professional with a broad range of experience across industries and organizational sizes, from startups to large enterprises.-Current Certifications: CCISO, DDN-QTE, CISSP, CCSP, CSSLP, CISM, CISA, CCSK, GPEN, GWAPT-Start-up Veteran: Adept at scaling security in agile, fast-paced environments.
-
Agentics Security ResearcherAgentics FoundationCary, Nc, Us -
Vp, Information Security & PrivacyButterflymx® Oct 2023 - PresentNew York, UsI was brought on to develop & lead information security & privacy for ButterflyMX, a complete property access solution that provides a secure, convenient, & affordable way to manage & grant access on the go. Since 2015, ButterflyMX solutions have been implemented into more than 15,000 properties, empowering residents & building staff to open doors, gates, & elevators with an elevated mobile experience.As VP of Information Security & Privacy, my vision is to cultivate a culture of trust & resilience by integrating security & privacy into the fabric of the organization. With an agile & strategic approach I proactively manage risks, safeguard customer & employee data, & foster innovation, ensuring the business thrives securely in a dynamic environment. I seek to ensure adoption of innovative, right fit, right time, right size, right priced security & privacy solutions that will scale & grow with the company as it grows.-Information Security & Privacy Leadership @ a Series D Prop Tech startup-Intersection of IoT + SaaS + Web Application + Mobile Application & Information Security + Privacy-Initiating -> Developing Cyber Resilience-Building out/up Governance, Risk, Compliance, Security & Privacy-Policy, Procedure, & Technical Control assessment, audit, development, implementation & management-Head of Security, Data Privacy Officer-Product Security, Device Security, IoT Security, Cloud Security, SaaS Security, Penetration Testing, Threat Modeling, Cyber Risk Assessment -> Cyber Risk Quantification, Privacy Assessment-Hiring, Budgeting, Planning, Roadmap development-Supporting Customer Success & Sales with customer facing security, privacy & compliance related inquires -
Senior Director, Information Security & PrivacyButterflymx® Oct 2023 - Mar 2024New York, Us -
Vciso, Principal Security ConsultantInformation Security Innovation Group Nov 2013 - Present-Information security advisory consulting services & solutions for startups, small, medium, & enterprise businesses-Information Security Innovation, Research & enablement -Cybersecurity startup advisor enabling multiple early stage startups with product development, feedback, ideation & more-vCISO, "Chief Information Security Officer as a Service", Fractional CISO, vcisos.com, cybersecuritypros.com-Development & Execution of Startup to Enterprise Information Security Programs-Security Leadership & Alignment with the Business-GRC, Privacy, Regulatory, & Security Frameworks (NIST, HIPAA, SOC2T2, PCI, ISO, GDPR, CCPA)-Cross-Functional Stakeholder, Third-Party Partnerships & Relationship builder-Product Security Engineering, Cloud Security Architecture, Cloud Compliance Management, Application Security & DevSecOps Subject Matter Expert -SOC2 Audit & Compliance Leadership-Enabling Continuous Security & Continuous Compliance via automation & innovative solutions -Managed Security Services Provider, Managed Cloud Protection, Managed Application Security Provider-Threat Modeling Rollout for multiple organizations-Tested, Implemented & Operationalized multiple CNAPP, CSPM, DSPM, ASPM, DLP, EDR, SIEM, GRC solutions
-
Founding Principal Security ArchitectInformation Security Innovation Group Dec 2022 - Jun 2023-Partnered with an early stage cloud security startup as a Founding Principal Security Architect to help kickstart & launch-Solution Design & Product Management including ideation, documentation, roadmap development & execution of services -Pre-sales engineering, PoCs for prospects -GTM strategy development -Provided Managed Cloud Security & Cloud Protection services-Managed CSPM & CNAPP solutions for clients -Secured AWS via remediation guidance & prioritization of identified cloud misconfigurations-Company acquired a seed stage round of funding after successfully achieving several paid clients within 90 days of joining
-
Founding MemberProfessional Association Of Cisos Nov 2024 - Present -
Director Of CybersecurityGrin Aug 2021 - Dec 2022Sacramento, California, Us-Head of Security, Compliance & Privacy at a hypergrowth startup in the Creator Economy space -Joined GRIN as the first security hire & then “blitzscaled” from Series A to 1 billion valuation, & 250 to 450 employees in less than 12 months-Built out security program from the ground up-Completed goal of successful SOC 2 Type 2 audit within 6 months of joining-Responsible for Cybersecurity Program, Cyber Risk Management, Strategy, Roadmap, Budgeting, Execution & Management-Provided presentations to the board on current state of Cybersecurity, Risks & Roadmap -Hired and managed a cybersecurity team-Partnered with engineering to secure the application stack & GRIN Platform-Partnered with EngOps (DevOps + SRE) team to secure cloud infrastructure & application delivery -Owned & managed third-party engagements for audits, pentests, MDR, MSSP-Partnered with Sales & Customer Success teams to support the security review process for prospects & new & existing customers-Responsible & accountable for Product Security, Application Security, Data Security, Data Privacy, Third Party Risk Management, Incident Management, Vulnerability Management, Threat Management, SaaS Security, Cloud Security, AWS Security -Partnered with Legal to ensure Data Privacy, GDPR & CCPA compliance -Partnered with IT on Corporate IT Security initiatives like security awareness, identity & access management, compliance automation, vendor management, mdm, Google Suite / Workspace Security, anti-phishing controls & more..-Researched, tested & deployed innovative security solutions - CSPM, SOAR, CNAPP, DSPM & more-Implemented Threat Modeling & Application Security-Managed Continuous Compliance, performed routine risk assessments, developed risk register -
Senior Principal Solutions ArchitectVeracode Feb 2020 - Aug 2021Burlington, Massachusetts, UsAs a Senior Principal Solutions Architect at Veracode I enabled large enterprise organizations to reduce risk by proactively securing applications via DevSecOps & secure software development. Day-to-day activities included meetings, demonstrations, presentations, integrations setup/testing, proof of values, discovery, research & strategic planning. Worked with clients to test & implement SAST, DAST & SCA into CICD pipelines to enable automated secure software development lifecycle. Researched, Resolved & remediated application security flaws as discovered. Implemented solutions & processes to facilitate threat modeling to proactively identify, qualify & ensure defenses against threats & risks to the application.DevSecOps Enablement, Application Security Solutions, Secure Software Development Lifecycle, Software Composition Analysis, Static Analysis / SAST, Dynamic Analysis / DAST, Interactive Analysis / IAST, Secure Development Education, eLearning, Application Security Pentesting, Application Security Program Management, Manual Pentesting, Threat Modeling, Solutions Architecture Development, Solutions engineer, Sales Engineer, Product Security, Secure Application Development. -
Senior Ai Security ArchitectIbm Sep 2017 - Jan 2020Armonk, New York, Ny, UsDefinitely a highlight in my career. This was an exciting opportunity working at intersection of Security, Privacy, Governance, Risk, Compliance & Artificial Intelligence on/in Cloud @ one of the largest tech companies. As a Senior AI Security Architect I led Watson AI & IBM Cloud security, compliance & risk management efforts. This was accomplished through much teamwork and collaboration with clients, sales teams, product/service/development teams, offering management, compliance & risk management, & senior leadership throughout IBM. -Responsible for Secure Architecture Design & Threat Modeling for Watson AI & IBM Cloud services-Advised, assessed, consulted, & enabled compliance efforts related to SOC2, ISO27001, HIPAA, GDPR, PCI, FedRAMP, IRAP.. etc.. -Implemented improvements to SDLC to incorporate SAST & IAST with the outcome of generating faster feedback loops to the developers for quicker remediation of application vulnerabilities-Developed & delivered security training for developers & security focals-Researched & advised on Container & Kubernetes security as IBM Cloud transitioned from Cloud Foundry to k8s-Lead a team of new hires from various development teams to develop a Watson AI product from idea to minimum viable product-In q4 of 2018 was part of a team focused on a 2 Billion opportunity that closed at $700 million with growth over 5 years-Cloud Security Architect, AI Security Architect, CISO Leadership Team, Product Security Engineering, -Artificial Intelligence Security ResearchAreas of Focus: Product Security, AI Security, Security Strategy, Secure Public Cloud, Secure Program Development, Security Metrics, Application Security, DevSecOps enablement, CI/CD, Secure Agile Development, Security Architecture Reviews, Threat modeling, SOC2, HIPAA, FedRAMP, Security & Privacy by Design, Automating Security & Compliance, Secure Innovation, Digital Transformation, Watson Artificial Intelligence -
Vice-President, Senior Cloud Security ArchitectWells Fargo Aug 2015 - Aug 2017San Francisco, California, Us-Executive Vice-President, Cloud Security Architect-Cloud Security Architecture, Design & Strategy Development at one of the largest Financial Services organizations.-Cloud Risk identification, analysis & solution/remediation development-Pioneered the development of Cloud Security Requirements, Cloud Security Strategy, & Cloud Security Target Architecture.-Research & focus areas included Cloud Security solutions, Cloud services & architectures of all types, DevSecOps, Containers, Application Security, Azure, AWS, IoT, AI ...-Member of Enterprise Information Security Architecture team-Key Contributor to Cloud Security Center of Excellence -
Lead Cloud Security EngineerGenesys | Interactive Intelligence Jul 2014 - Jul 2015Indianapolis, Indiana, Us-Lead a talented team to engineer a Continuous Security, Compliance & Risk Management program for a SaaS being developed on Amazon Web Services (AWS) IaaS & PaaS in an agile development environment leveraging CI/CD-Cloud Security Architecture research & design-Managed Governance, Risk & Compliance program development-DevSecOps research & enablement-Partnered & fostered collaboration with business, application, development, DevOps, IT, & executive management teams-Audit & Assessment Management for SOC2, HIPAA, PCI, FedRamp, ISO2700x etc..-Research focused on Cloud Security, application security, threat intel, defenses, attack methods, vulnerabilities, exploits, etc..-Cloud Security solution research & development with Dome9, SumoLogic, Alienvault, Threatstack, TrendMicro, OSSEC, Security Compass, Nessus & more.. -Cloud oriented/focused Policy & Procedure development -
Account ExecutiveAccuvant Apr 2012 - Nov 2013Denver, Co, UsFirst Account exec based out of Raleigh for Accuvant. Information Security consulting, advisory services, & strategic solution provider in the Carolinas. Utilized a vast portfolio of 150+ Vendor Products & 100+ Security Services to provide custom Information Security Solutions to client business challenges. Projects included Managed Security Services, Cloud Security, Incident Response, SIEM, DLP, NGFW, IPS, NAC, Forensics, Application Security Assessments, Penetration Testing, End-point Security, Encryption, WAFs, & MDM. -
Security Solutions ArchitectForsythe Mar 2010 - Apr 2012Skokie, Illinois, UsTrusted advisor providing pre-sales consulting & security leadership within large enterprises throughout North Carolina to facilitate the improvement of their Information Security programs, infrastructures, & postures. This was accomplished through successful architecture design, consulting services delivery, solution development, implementation, monitoring and management. My day to day tasks predominantly focused on customer/client interactions as I worked intimately with them as a member of their team for their success.Worked on projects & initiatives involving Cloud Security, Data Loss Prevention, Mobile Security, SIEM, Next Generation Firewalls, Virtualization, PCI Compliance, ISO2700x, Identity Management, Multi-factor Authentication, Compliance & Risk Management, Data Protection, Threat Assessments, Web Application Firewalls, e-Discovery, Remote Access, NAC, Encryption, Wireless Security, Intrusion Prevention, Incident response, Forensics, Malware Strategy, Endpoint Security... nearly everything an enterprise would encounter or be challenged with involving Information Security. -
Senior Security ConsultantForsythe Sep 2006 - Apr 2012Skokie, Illinois, UsSuccessfully consulted, advised, and executed professional consulting services engagements as the principal & Senior Consultant assigned to Information Security Assessments. My predominant area of speciality was Penetration Testing, Ethical Hacking & Vulnerability Assessments. I also was very successful in performing Audits and Assessments based on ISO2700x, PCI, & NIST standards & ultimately improving organizations Information Security Programs. Became SME for DLP technologies through executing on Data Loss Risk Assessments utilizing Symantec (Vontu), McAfee, and RSA DLP solutions.Enjoyed developing and maturing the Forsythe Information Security offerings & the Forsythe Information Security go-to-market strategy. Supported pre-sales efforts for selling security services by providing presentations & SOW development. -
Senior Security ConsultantUsps 2004 - 2006Washington, D.C., UsAs a key member on the CISO's team my area of responsibilities included Penetration Testing, Vulnerability Management, CISP (now known as PCI) Compliance, deployment/testing/configuration of 150+ Cisco Firewall Enclaves, ISS IPS, Incident Response, Malware Response, Network Forensics, Wireless Rouge AP Testing, War-dialing, & developing Hardening Standards. Participated in the Change Management Review Board to review IT architecture proposals and provide recommendations on information security best practices. -
Senior Security ConsultantBti Communications 2001 - 2004Downers Grove, Illinois, UsDesign, Deployment, and Management of secure networks for SMB & Mid-Market Businesses. Primarily worked with Cisco routers, switches, & firewalls with some Netopia and Adtran in the mix. As part of the deployment and ongoing monitoring of firewalls I utilized What's Up Gold, MRTG, Knoppix-STD & Nessus. Initially worked for US Datacom (Cisco VAR) which was acquired by BTI, then ITC Deltacom. -
Large Enterprise Wan EngineerMci 1999 - 2001Basking Ridge, Nj, UsSupported Large Enterprise clients with management & monitoring of their Cisco & Nortel based WANs. -
Ibm Commercial Desktop EngineerIbm Product Reviews Lab 1997 - 1999Armonk, New York, Ny, UsOne of the coolest jobs ever... I worked in a lab right next to the development team at IBM and was responsible for beta-testing and tweaking Commercial Desktops before going to publications for testing. The publications (like PC Magazine) would test the Desktop, benchmark it and write an article to print near the same time as the PC would be available to the market. Also built systems that went to hollywood as part of the brand development and marketing efforts. Eventually had a stint in the Cross Brand Configuration Center at IBM, which had me working to develop & tweak Custom OS images for Large Enterprise clients. During that time I gained great experience with NT, Linux, Cisco Switches, and Wireless as we began testing these large environment massive installs and recreating them in our lab. -
Internet Support EngineerMci/Worldcom 1995 - 1997Provided Tier 3 support for Internet MCI to business users.
Scott Kennedy Education Details
-
Campbell UniversityReligion/Religious Studies -
Certifications
Frequently Asked Questions about Scott Kennedy
What company does Scott Kennedy work for?
Scott Kennedy works for Agentics Foundation
What is Scott Kennedy's role at the current company?
Scott Kennedy's current role is Agentics Security Researcher.
What is Scott Kennedy's email address?
Scott Kennedy's email address is js****@****ail.com
What is Scott Kennedy's direct phone number?
Scott Kennedy's direct phone number is +191938*****
What schools did Scott Kennedy attend?
Scott Kennedy attended Campbell University, Certifications.
Free Chrome Extension
Find emails, phones & company data instantly
Aero Online
Your AI prospecting assistant
Select data to include:
0 records × $0.02 per record
Download 750 million emails and 100 million phone numbers
Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.
Start your free trial