AeroLeads people directory · profile

Michael Trofi Jr. Cissp, Cism, Cgeit Email & Phone Number

Security Leader | Founder | Board Advisor | CISO at Trofi Security and United States Holocaust Memorial Museum at United States Holocaust Memorial Museum
Location: Lafayette, Colorado, United States 19 work roles 2 schools
1 work email found @msn.com LinkedIn matched
✓ Verified August 2026 4 data sources Profile completeness 100%

Contact Signals · 1 work email

Work email m****@msn.com
LinkedIn Profile matched
3 free lookups remaining · No credit card
Role
Security Leader | Founder | Board Advisor | CISO at Trofi Security and United States Holocaust Memorial Museum
Location
Lafayette, Colorado, United States

Who is Michael Trofi Jr. Cissp, Cism, Cgeit? Overview

A concise factual answer block for searchers comparing this professional profile.

Quick answer

Michael Trofi Jr. Cissp, Cism, Cgeit is listed as Security Leader | Founder | Board Advisor | CISO at Trofi Security and United States Holocaust Memorial Museum at United States Holocaust Memorial Museum, based in Lafayette, Colorado, United States. AeroLeads shows a work email signal at msn.com and a matched LinkedIn profile for Michael Trofi Jr. Cissp, Cism, Cgeit.

Michael Trofi Jr. Cissp, Cism, Cgeit previously worked as Chief Information Security Officer at United States Holocaust Memorial Museum and Founder / vCISO at Trofi Security. Michael Trofi Jr. Cissp, Cism, Cgeit holds Bs Computer Engineering, Computers, Digital Design, Software from University Of Rhode Island.

Company email context

Email format at United States Holocaust Memorial Museum

This section adds company-level context without repeating Michael Trofi Jr. Cissp, Cism, Cgeit's masked contact details.

*@msn.com
68% confidence

AeroLeads found 1 current-domain work email signal for Michael Trofi Jr. Cissp, Cism, Cgeit. Compare company email patterns before reaching out.

Profile bio

About Michael Trofi Jr. Cissp, Cism, Cgeit

• Over 35 years of experience in start-ups, telecommunication, high-tech, financial services and governmental and not-for-profit industries. Background emphasizes visionary technology projects. Effective combination of engineering/research management talent and interpersonal sales, collaboration and deal making skills. • Strengths include IT security and risk management, compliance, technology development, relationship management with customers and business venture partners, engineering and team building, negotiations and project management from concept proposal and sign-off, budget monitoring through successful project completion or product release. • Reputation as dynamic agent of change, with entrepreneurial nature and high energy level. Proficient in product R&D, marketing analysis and strategic modeling of business variables.Specialties: • GLBA, FFEIC, FISMA/FISRA, GISRA, HITECH/HIPAA, PCI DSS (2 & 3) SOX, CISS, CJIS, ISO27001-2013, ISO27002, SSAE-16/18 SOC2, UCF, NIST• SDLC, RUP, UDP, RAD, CMM, SEI, ISO, COBIT, COSO • UML, WebLogic, MS-Office (all) , MS-Project, MS-Visio• Linux, Windows (2008, 7, 8, 10, 11, 2012, 2016, 2019, 2022), RTOS, VMware, Citrix, Hyper-V• C, C#, J2EE, XML, HTML, embedded firmware• TCP/IP, UDP, ADS, DNS, SMTP, SNMP, HDLC • Nmap, Nessus, Nexpose Pro, Qualsys, Metasploit Pro, MBSA, NETIQ, ECORA, WireShark, Solarwinds, WSUS, Checkpoint (FW-NGXT, VSEC, Horizon, XDR, PlayBlocks, events, CloudGuard appsec, posture management, Harmony Mobile, endpoint and email/collaboration), Cisco, Juniper, Palo-Alto, WatchGuard, McAfee EPO, Symantec, Trend Micro, Wd email coloborationd), Webroot, GFI Languard, GFI Event Manager, DLP, BeyondTrust, Qualys, Burp Suite Pro, ZAP, Secunia, Kali-Linux, HP Fortify Workbench, CheckMarx, OKTA, Delinea, Armis, Veriti, Fortinet NDR, Torq, Gigamon, Varonis• SQL (2012-2022), Exchange (2010, 2013, 2016), Sharepoint (2010, 2013, 2016), Active Directory (2008/2012/2016), GPO, Forefront, Tripwire, WebSense, Manage Engine, Netscaler, Forescout, Palo-Alto Cortex-XDR, SentinelOne, Morphisec, LogRhythm, Armis, Gigamon Insight

Listed skills include Information Security, Network Security, Information Security Management, Penetration Testing, and 46 others.

Current workplace

Michael Trofi Jr. Cissp, Cism, Cgeit's current company

Company context helps verify the profile and gives searchers a useful next step.

United States Holocaust Memorial Museum
United States Holocaust Memorial Museum
Security Leader | Founder | Board Advisor | CISO at Trofi Security and United States Holocaust Memorial Museum
AeroLeads page
19 roles · 43 years

Michael Trofi Jr. Cissp, Cism, Cgeit work experience

A career timeline built from the work history available for this profile.

Founder / Vciso

Current

Lafayette, Co, Us

vCISO (since 2/2015), MSSP services and acting CIO (since 5/2019) - United States Holocaust Memorial Museum - DCTrofi Security provides the following services to small to mid-size companies.• virtual CSO, CISO, CTO, Security Adviser• Corporate IT Security Strategy | Security Governance• Risk Assessments,| Management | Mitigation• Vulnerability Assessment | Management | Remediation• Disaster Recovery | Business Continuity Planning• Enterprise Security Architecture design | deployment• Regulatory Compliance (GLBA, FISMA, GISRA, HITECH/HIPAA, SOX, PCI, CISS, FedRAMP, NIST, CJIS, ISO 27001/2:2013, ISO/IEC 12207, ISO/IEC 29147:2014, SSAE-16/18, CSA-CM, NERC)• PCI DSS 3.2 Readiness Assessments | HIPAA Meaning Use Assessments | ISO27001-2013/27002 Readiness Assessments• Bank Security Audit assistance (AMEX, JPMC, GS, UBS, Wells Fargo, Mirador, Fifth-Third, BnA)• Security Assessment | Penetration Testing (Internal/External/Application/Mobile/Social/POS)• Software Security Assessments (Static & Dynamic)• Network | Server | Application Security• Cloud (AWS, Azure, Google)• Software Architecture | Design | Development (Embedded, Mobile and Web)- DevSecOps• Security Awareness Training• Forensics

Jan 2014 - Present

Founder, Vcto, Security Architect

Current

Lafayette, Colorado, Us

Provides the following services to small to mid-size companies.• Corporate IT Security Strategy | Security Governance• Risk Assessments,| Management | Mitigation• Vulnerability Assessment | Management | Remediation• Disaster Recovery | Business Continuity Planning• Enterprise Security Architecture design | deployment• Regulatory Compliance | pre-audit Assessments (GLBA, FISMA, GISRA, HITECH/HIPAA, SOX, PCI, CISS, FedRAMP, NIST, CJIS, ISO 27001:2013, ISO 12207-2008, SSAE-16, CSA-CM)• Bank Security Audit assistance (AMEX, JPMC, GS, UBS, Wells Fargo, Mirador, Fifth-Third)• IT Forensics• Security Assessment | Penetration Testing (Internal/External/Application/mobile)• Software Security Assessments (Static & Dynamic)• Network | Server | Application Security• Software Architecture | Design | Development (Embedded, Mobile and Web)• Security Awareness Training Trofi System Solutions’ Projects have supported the following industry sectors:o Financial services / Banking / Credit Card Processorso Telecommunications / Cloud Providers / Cableo Transportation / Automotiveo Local, State and Federal Governmento Energy o Education (local, state, federal)o HealthCare / Hospitals / Medical Practiceso Manufacturingo Aerospaceo Hospitality / Retail

Aug 1999 - Present

Strategic Partner / Cso

Cst Strategic Advisors,

Consulted with C-level management teams of numerous, midsized organizations in both the private- and public-sectors to provide concrete guidance in information security governance and enterprise security management. Worked with organizations to develop strategies and implementation plans to address Enterprise Security challenges posed by regulatory compliance mandates including BS 7799, ISO 17799, ISO 27799, ISO 27001, ISO 27002, HIPAA, PCI DSS, PA-DSS, SB 1386, SOX, GLBA, and FISMA. Liaised with the public, industry organizations, and information technology security leaders on a national level, and provided representation in major events, serving as a speaker and member of several security communities.• Virtual CSO | CISO | CTO services• Corporate / IT Security Strategy• Corporate / IT Security Governance• Risk Management & Mitigation• Vulnerability Management & Remediation• Direct Crisis Management (Incident Response)• Disaster Recovery and Business Continuity Planning• Financial Analysis & Budgeting• Client / Vendor Management • Enterprise Security Architecture• Regulatory Compliance (GLBA, FISMA, GISRA, HITECH/HIPAA, SOX, PCI, CISS, FedRAMP, NIST, CJIS)• IT Forensics• Security Assessment & Penetration testing (Internal/External/Application/mobile)• Software Security Assessments (Static & Dynamic)• Network / Server / Application Security

Jun 2012 - Jul 2014

Director Of Information Security And Compliance

Denver, Co, Us

Developed the information technology/security management architecture and company-wide program to safeguard information systems for credit card and ACH processing systems. Spearheaded security governance programs and maintained PCI Level 1 compliance certification. Conducted ongoing analysis of policies and procedures to maximize efficiency, achieve reliable adherence to cost and quality goals, and deliver services consistent with a strong company commitment to customers. Created and deployed a risk management program that implemented key mitigation strategies, benchmarking and best security practices while maintaining compliance with all appropriate corporate polices and regulatory agencies. Collaborated closely with IT Operations to develop a seamless Business Continuity Plan capable of ensuring near-realtime recovery of production operations, even in a full disaster recovery scenario, while maintaining full PCI compliance and client data privacy protection.Budget Accountability: $1.2 Million

Nov 2011 - Jun 2013

Chief Information Security Officer

Wealthtouch

Executive leader of the organization's strategies for information security systems and governance, policies and procedures, and employee training and awareness. Developed and implemented comprehensive risk management and regulatory compliance practices for the protection of client financial records. Managed information security budgets and expenditures while enforcing compliance with financial information privacy goals and financial data information technology standards. Spearheaded strategic planning and production tracking focused on maintaining superior organizational information security management performance. Promoted and established strong client relationships by working closely with customers to provide ongoing assessment of needs and resources. Analyzed policies and procedures to maximize efficiencies, streamline business processes and implement best practices.Budget Accountability: $1.4 Million

Jun 2010 - May 2013

Senior Network Architect

New York, Ny, Us

Performed network vulnerability, security risk assessments for SOX compliancy, network management and new system deployments for systems dealing with contract management, billing, commercial video insertion and back office functionality for corporate clients at several branch offices. Provide engineering support for network performance enhancements for data communications in the southeast region. Provide server remediation services for security vulnerabilities that were discovered during the assessment, defined disaster recovery/continuity plan and performed application performance tuning. Provide support for transfer of technology as part of the sale of the Adelphia Southeast region to Comcast and Time-Warner. Provide day-to-day support of all IT (server and desktop) operations for the WPB and Miami region and for key applications including TIM, Strata, Novar, Navic, Visible World and Matrix. Deployed Sharepoint collaboration server using WSS 3.0 for IT and Technical operations.

Dec 2005 - Apr 2009

Senior Security Architect

Denver, Co, Us

– Senior Security Engineer on the state-wide Colorado Cyber Security Program (CCSP). Participated in the creation and review of security polices and procedures, agency risk assessment activities, critical system inventory, agency budget and security planning review and the development of an Incident Response Plan for the State of Colorado. Duties included gathering requirements from project stake holders, developing a strategy and writing the appropriate guidelines, policies, processes and procedures. In addition, served as Senior Network Architect for a variety of operational oriented projects executed out of the CISO’s office to support activities within the state of Colorado.

Jun 2006 - Nov 2008

Director Of It And Security

Denver, Colorado, Us

Envisioned and championed information technology architectural and security vision. Planned and managed technology capacity, streamlined business processes, and reduced costs by eliminating redundancies and standardizing policies and procedures. Ensured compliance with system, IT, security, industry and quasi-governmental rules and regulations. Implemented best practices, and spearheaded projects which led to the agency to become recognized as a best-in-class security organization within housing authorities nationwide. Presented at board meetings as well as state and national housing conferences.Budget Accountability: $4.0 Million

Jun 2003 - Dec 2004

Senior Network Security Architect

Msha / Dol

Directed and oversaw computer information systems and operations that supported over 3,200 users at 102 sites. Collaborated with the Deputy Director and Department of Labor to create a Security Governance Program and secure computing infrastructure that met the vision and direction of the Department of Labor's technology roadmap. Performed capacity planning duties and generated all associated OMB A-130 documentation. Prepared capacity planning estimates, developed and presented annual and bi-annual budgets to the Secretary of Labor, and formulated an infrastructure strategy aimed at supporting the agency's planned growth and new product development. Served on a cross-agency DOL Security panel in generating responses to FISMA and GISRA regulatory audits and commitments, and set agency wide standards for various security architectures, consolidation and standardization efforts. Designed and delivered the information security plan, Incident Response and Reporting procedures, disaster recovery and business continuity plan, configuration management process and procedures.

1999 - 2003 ~4 yrs

Director Of Software Technologies/Information Security

Crosslink

Provided vision, strategic planning and management oversight on all new technologies. Responsible for the design and implementation oversight of an experimental data system for the Space Shuttle and Space Station working with Boeing and SPACEHAB. Directed the software architecture and product development for a start-up High-tech Company specializing in radio frequency identification (RF/RFID) technologies. Established software development department with annual IT budget of $2 million - $3 million. Launched new office and support company (DAI Systems) in Toronto, Canada.

Jun 1998 - Dec 1999

Manager Software Engineering

Us

Established and managed software and product development for publicly traded company that provided consolidated cost-effective access technologies. The start-up high tech company successfully grew revenues from $15 million to $60 million in two years.• Created company’s main products line (Access Bank II and Wide Bank 28), multiplexers that provides termination for xDSL/T1/T3 communication lines. Responsibilities included defining product requirements, the related logical architecture and design and management oversight for all software development. • Received patent for a telecommunications multiplexer (#6275510 B1) for Wide Bank 28 product.• Formalized research and development processes and participated in five successful product launches. Managed annual IT software development budget and trained staff of 13.• Worked with Sales/Marketing team to create and present application notes, white papers, RFPs, and presentations.

Jun 1996 - Jun 1998

Senior Software Architect

Us

Arctected and developed ETSI V5.2 software subsystem for Samsung Korea.Performed architectural and software development oversight for an ETSI V5.2 protocol based Integrated Digital Loop Carrier (IDLC) system to be integrated into the Samsung SDX-100 telephony switch. • Designed and implemented the internal system-wide software architectural infrastructure and the call processing protocol state machine entities and management resources. The product was developed in a Sun Solaris development environment for an embedded Motorola 68030 processor using C and a proprietary VRTX like kernel architecture.

1995 - 1996 ~1 yr

Senior Software Consultant

Monroe, La, Us

Business analyst for a knowledge-based product to automate the Engineering Work Order Process (EWO) utilized within US WEST. • Performed all Business analyst activities and Use case generation.• Generated requirements specification for software development team. The requirements included design of the GUI interface for the service assurance organization and the internal database architecture. • Selected deployment model for the project. The project was developed in C, C++, for a SUN/HP distributed network using the Oracle database, Neuron Data OIT and Persistence.

1994 - 1995 ~1 yr

Senior Software Engineer

Ajilon

Assignment entailed the design, implementation and test for prototype controller for Heart/Blood pump for COBE Laboratories. Design work included developing the prototype using SA/SD in the Cadre Teamwork environment. The software was developed in C and Motorola MC680xx assembly language for an embedded system on a HP-UX platform.

1994 - 1995 ~1 yr

Manager Software Development

Netrix Corporation

-- Manager Voice Technology DevelopmentResponsibilities included managing all Voice technology product enhancements and maintenance activities, as well performing R&D for next generation products. This included budgets; design documentation, project management and all other management related tasks.-- Manager of Corporate Process and Development EnvironmentDuties included analyzing and development of product development processes for the corporation. The main focus was on product life cycle definitions within the engineering organization with the emphasis on corporate ISO-9001 certification. Involvement also included defining a new development environment for the engineering department. This included researching various hardware platforms, operating systems, network architectures (LAN & WAN), engineering CASE tools (CM, Compilers, SA/SDX, Documentation tools, hardware design and layout, simulators, etc.), Multi-Media Applications, and structured methodologies. Duties included documenting business cases creating budgets, developing evaluation plans, and managing the evaluation for new platforms and tools, introduction of design methodologies and engineering procedures that were used throughout the company. Also lead a group to define software standards, methodology customization and efficient programming techniques to be used throughout the engineering department.-- Lead Engineer, ISO 9000-1 CertificationDuties included managing the Software engineering department, performing project management tasks, overseeing ISO 9000-1 implementation and capital budgets. Responsibilities also included the developing, implementing and training the engineering staff on ISO certified software development life cycle (SEI level-3) and introducing staff to I-Case tools (Cadre Teamwork, HP/Softbench, and CaseWare/CM).

1992 - 1994 ~2 yrs

Software Engineer

San Jose, Ca, Us

-- Technical Lead, Asynchronous ProtocolsResponsible for the design and maintenance of the asynchronous communications protocol subsystem for McDATA's 3270 cluster controllers. All software was written in 'C' and Intel Assembly language utilizing a proprietary multi-tasking kernel on Intel 80186, 80286 and 80376 based systems. Also responsible for developing a curriculum on the subsystem too cross-train other engineers on the internals of the subsystem architecture. Engineering Test and Software QualityResponsible for developing software test methodologies and procedures to test McData software products. This included the design and implementation of automated test and simulator platforms. Also responsible for developing the procedures needed to produce quality software through its entire life cycle. -- Software Engineer, System Group ProductsDesigned and implemented software to perform defined Telnet options in the McDATA Control Unit environment. Responsibilities also included for enhancing current SNMP/TCP/IP/UDP implementation (buffering and routing algorithms) in the control unit. -- Engineering Development and Software Standards CommitteeInvolved with defining a new development environment for the software-engineering department. This included researching various hardware platforms, operating systems, network architectures, engineering CASE tools (CM, Compilers, SA/SDx, Documentation tools, simulators, etc.), development process and structured methodologies. Duties include documenting business case, creating budgets, and evaluation for new platforms and tools, introduction of design methodologies and software engineering procedures that will be used. Also led a group to define software standards, methodology customization and efficient programming techniques to be used throughout the engineering department.

1988 - 1992 ~4 yrs

Software Engineer

London, Gb

-- Technical Supervisor, Network CommunicationsResponsible for the design and implementation of the network related layers for a T1 networking system. The system was designed to follow the ISO model for layered network architecture. Primary areas of investigation included: application, session, transport, network and data link layers of the OSI network model covering a wide range of topics from SDLC to interfacing with ISDN. Main area of concentration dealt with the implementation of code to establish and monitor "virtual" circuits in the T1 network. This required knowledge of the various T1 formats (M24, M44, SDM etc.) and (re-) routing and bumping algorithms. All software was written in "C" using the VRTX_OS real-time operating system and assembler on an Intel 80186 based platform.-- Network ManagementResponsibilities included investigating functionality and equipment for the design of a network management system to work in conjunction with the T1 network system.

1985 - 1988 ~3 yrs

Software Engineer

Mystech Associates

Responsibilities included performing the following benchmark/modeling activities for the US Navy Trident submarine program. -- WAA TMA SoftwareResponsible for the design and implementation of a data analysis and plot generation program for the Wide Aperture Array Target Motion Analysis (WAA TMA) advanced development model. -- Computer BenchmarkingProject involved testing commercial computer systems for military use. Various benchmarking techniques were used to test the various components that make up a typical military computer system. -- DDBMS ModelingThe project involved the research and development for modeling and simulation of a parallel DDBMS system for a multiple workstation network.

1984 - 1986 ~2 yrs
2 education records

Michael Trofi Jr. Cissp, Cism, Cgeit education

Bs Computer Engineering, Computers, Digital Design, Software

University Of Rhode Island

Telecommunications

Northeastern University
FAQ

Frequently asked questions about Michael Trofi Jr. Cissp, Cism, Cgeit

Quick answers generated from the profile data available on this page.

What company does Michael Trofi Jr. Cissp, Cism, Cgeit work for?

Michael Trofi Jr. Cissp, Cism, Cgeit works for United States Holocaust Memorial Museum.

What is Michael Trofi Jr. Cissp, Cism, Cgeit's role at United States Holocaust Memorial Museum?

Michael Trofi Jr. Cissp, Cism, Cgeit is listed as Security Leader | Founder | Board Advisor | CISO at Trofi Security and United States Holocaust Memorial Museum at United States Holocaust Memorial Museum.

What is Michael Trofi Jr. Cissp, Cism, Cgeit's email address?

AeroLeads has found 1 work email signal at @msn.com for Michael Trofi Jr. Cissp, Cism, Cgeit at United States Holocaust Memorial Museum.

Where is Michael Trofi Jr. Cissp, Cism, Cgeit based?

Michael Trofi Jr. Cissp, Cism, Cgeit is based in Lafayette, Colorado, United States while working with United States Holocaust Memorial Museum.

What companies has Michael Trofi Jr. Cissp, Cism, Cgeit worked for?

Michael Trofi Jr. Cissp, Cism, Cgeit has worked for United States Holocaust Memorial Museum, Trofi Security, Trofi System Solutions, Cst Strategic Advisors,, and Paysimple.

How can I contact Michael Trofi Jr. Cissp, Cism, Cgeit?

You can use AeroLeads to view verified contact signals for Michael Trofi Jr. Cissp, Cism, Cgeit at United States Holocaust Memorial Museum, including work email, phone, and LinkedIn data when available.

What schools did Michael Trofi Jr. Cissp, Cism, Cgeit attend?

Michael Trofi Jr. Cissp, Cism, Cgeit holds Bs Computer Engineering, Computers, Digital Design, Software from University Of Rhode Island.

What skills is Michael Trofi Jr. Cissp, Cism, Cgeit known for?

Michael Trofi Jr. Cissp, Cism, Cgeit is listed with skills including Information Security, Network Security, Information Security Management, Penetration Testing, Vulnerability Assessment, Disaster Recovery, Pci Dss, and Tcp/Ip.

Find 750M verified contacts

Search by job title, company, industry, location, and seniority. Export verified B2B contact data when you need it.