AeroLeads people directory · profile

Richard Stevens Email & Phone Number

Senior Application Security Engineer at Financial Company
Location: Charlotte, North Carolina, United States 15 work roles 5 schools
1 work email found @tiaa-cref.org LinkedIn matched
✓ Verified July 2026 4 data sources Profile completeness 100%

Contact Signals · 1 work email

Work email r****@tiaa-cref.org
LinkedIn Profile matched
3 free lookups remaining · No credit card
Current company
Financial Company
Role
Senior Application Security Engineer
Location
Charlotte, North Carolina, United States

Who is Richard Stevens? Overview

A concise factual answer block for searchers comparing this professional profile.

Quick answer

Richard Stevens is listed as Senior Application Security Engineer at Financial Company, based in Charlotte, North Carolina, United States. AeroLeads shows a work email signal at tiaa-cref.org and a matched LinkedIn profile for Richard Stevens.

Richard Stevens previously worked as DevSecOps Application Security Engineer at Healthcare Company and Information Security Engineer at Wells Fargo. Richard Stevens holds Computer Science Major from Colorado State University.

Company email context

Email format at Financial Company

This section adds company-level context without repeating Richard Stevens's masked contact details.

{first}.{last}@tiaa-cref.org
86% confidence

AeroLeads found 1 current-domain work email signal for Richard Stevens. Compare company email patterns before reaching out.

Profile bio

About Richard Stevens

18 years of progressive information technology security consulting services, in the areas of web application vulnerability testing, source code evaluation, security automation (SecDevOps), cloud operations, compliance auditing, and web application programming.

Listed skills include Information Security, Vulnerability Assessment, Computer Security, Cissp, and 17 others.

Current workplace

Richard Stevens's current company

Company context helps verify the profile and gives searchers a useful next step.

Financial Company
Financial Company
Senior Application Security Engineer
Charlotte, NC, US
15 roles

Richard Stevens work experience

A career timeline built from the work history available for this profile.

Senior Application Security Engineer

Financial Company

Charlotte, Nc, Us

Devsecops Application Security Engineer

Healthcare Company

Starting, implementing and automating a DevSecOps application security program in an Azure cloud environment utilizing Azure Functions, Logic Apps, and Terraform.

Information Security Engineer

San Francisco, California, Us

Automation Engineer utilizing Python and PowerShell scripts to create workflow for the Qualys suite of tools. Duties include problem solving security engineer issues, automating existing manual processes, script performance enhancement, and implementing DevOps and Agile development processes.

Dec 2018 - Jul 2021

Senior Application Security Engineer

Davidson, North Carolina, Us

Duties include selecting, implementing, and operating SAST (Checkmarx, Coverity) and DAST (Netsparker, Qualys WAS, Burp) scanning technologies, CI/CD integration activities, and operation of infrastructure vulnerability scans using Qualys VM.

Apr 2017 - Nov 2018

Lead Info Security Engineer

New York, Ny, Us

Lead Information Security Engineer responsible for conducting in depth application security vulnerability assessments for new and existing applications via SAST and DAST scanning technologies. Responsible for training developers on the use of static code analysis tools (AppScan Source for Analysis) utilizing monthly developer workshops. Responsible for AppScan Enterprise database table mapping for selective exportation of vulnerability data to third party visualization tools for the production of application security metrics. Other duties include automation of common tasks via PowerShell.

Apr 2014 - Apr 2017

Senior Security Architect

Kobbegem, Be

Information Security Architect position responsible for conducting in depth security risk assessments for new and existing applications to identify weaknesses or security exposures. Duties aligned with the OWASP SAMM (Software Assurance Maturity Model) verification step to include design review, code review, and security testing. Specialized in web service / application security utilizing OWASP ASVS (Application Security Verification Standard) in concert with automated IBM AppScan assessments.

Sep 2011 - Mar 2014

Information Security Specialist

Knoxville, Tn, Us

Evaluation and creation of policies, procedures, and technical work instructions for compliance with FISMA and NERC-CIP requirements. Application security evaluation of intranet applications to include governance, risk and compliance (GRC) middleware.

Jul 2011 - Sep 2011

Contract Security Analyst - St&E

Oak Ridge, Tn, Us

Contracted to perform ST&E for C&A of all ORNL unclassified systems utilizing NIST SP 800-53 rev. 3 control framework. Evaluated scientific and nuclear research technology for cyber security compliance and risk to include the nuclear High Flux Isotope Reactor (HFIR) and High Performance Computing.

Dec 2010 - Aug 2011

Senior Security Analyst

Sti

Various Tasks, including:

Jan 2003 - Nov 2010

Senior Security Analyst (Consultant)

Tennessee Valley Authority (Tva)

Served as a Technical Lead for a team of auditors who conducted independent risk assessments, penetration testing, and cyber security assessments utilizing NIST SP 800-53 control framework. Created SSPs and analyzed policies and procedures for compliance with FISMA/C&A requirements. Identified threat/vulnerability pairs and evaluated compliance of management, technical, and operational controls for electric power generation control systems to ensure confidentiality, integrity, and availability of critical applications and infrastructure.

Mar 2009 - Oct 2010

Senior Security Analyst (Consultant)

Advance America Corporation

Review policies, procedures, and guidelines to ensure multi-regulatory compliance. Security control evaluation (gap analysis) using COBIT and ISO 27001 control frameworks. Evaluate compliance with physical security requirements, backup and recovery operation requirements, logical access control requirements, configuration management requirements, audit trail logging and review requirements, security awareness training procedures, SDLC process review and recommendations. Java code review on proprietary financial applications, security testing with Canvas, and change management requirements as each pertains to ITGC of the Sarbanes-Oxley Act and NIST 800 Series FISMA requirements. Mentor other auditors and teach control framework and testing methodologies.

May 2007 - Jan 2010

Senior Security Analyst (Consultant)

Custom Direct

Translate bank regulatory requirements into business and technical requirements. Develop policies, procedures, standards, and guidelines to meet diverse regulatory requirements. Provide guidance and support to configure hardware and software systems to meet requirements of ISO, GLBA, and PCI compliance under a common GRC framework. Perform security control evaluation (gap analysis) using COBIT, NIST, and ISO 27001 control frameworks. Evaluate compliance with physical security requirements, backup and recovery operation requirements, logical access control requirements, configuration management requirements, audit trail logging and review requirements, security awareness training procedures, SDLC process review and recommendations.

Aug 2008 - Mar 2009

Security Analyst (Consultant)

Nasa Multiple Centers

Conduct security control evaluation using NIST 800-53 control framework. Mentor other auditors and perform FISMA compliance evaluations. Evaluate compliance of physical security requirements, application security implementation, effectiveness of backup and recovery procedures, effectiveness of logical access control, effectiveness of configuration management, compliance with audit trail logging and review requirements, existence of security awareness training procedures, effectiveness of SDLC management, existence of risk assessment procedures, and other controls related to protecting the confidentiality, integrity and availability of critical applications and infrastructure

Jun 2006 - Mar 2009

Senior Security Analyst (Consultant)

National Energy Technology Lab

ST&E based upon NIST 800-53A, NIST 800-37, NIST 800-30 and DOE guidelines. Systems evaluated included firewalls, Unix systems, Windows systems, IDS, Mainframe, and proprietary scientific applications. Assisted with creation and testing of COOP. Developed and executed custom UNIX scripts to determine extent of vulnerabilities. Conducted network penetration testing and vulnerability analysis in compliance with NIST 800-53A. Rated findings using risk scale and documented results and recommendations in final Security Assessment Report to allow Authorizing Official to make final approval to operate decision.

Oct 2007 - May 2008

Security Analyst (Consultant)

Noaa

Performed ST&E testing on various NOAA information systems. Performed analysis of all NIST 800-53 controls by reviewing security policies and procedures, reviewing information security plans, reviewing server configurations, performing vulnerability assessments utilizing tools such as Nessus, Paros Proxy, and Canvas, interviewing information system representatives, and physically reviewing site where information systems reside.

Oct 2005 - Oct 2006
5 education records

Richard Stevens education

Computer Science Major

Colorado State University

Bachelor Of Science, Chemistry

Colorado State University

Education record

Sans Technology Institute

Information Security Secure Coding

Security Innovation Team Professor Cbts

Information Security Secure Coding

Cigital Cbt
FAQ

Frequently asked questions about Richard Stevens

Quick answers generated from the profile data available on this page.

What company does Richard Stevens work for?

Richard Stevens works for Financial Company.

What is Richard Stevens's role at Financial Company?

Richard Stevens is listed as Senior Application Security Engineer at Financial Company.

What is Richard Stevens's email address?

AeroLeads has found 1 work email signal at @tiaa-cref.org for Richard Stevens at Financial Company.

Where is Richard Stevens based?

Richard Stevens is based in Charlotte, North Carolina, United States while working with Financial Company.

What companies has Richard Stevens worked for?

Richard Stevens has worked for Financial Company, Healthcare Company, Wells Fargo, Ingersoll Rand, and Tiaa-Cref.

How can I contact Richard Stevens?

You can use AeroLeads to view verified contact signals for Richard Stevens at Financial Company, including work email, phone, and LinkedIn data when available.

What schools did Richard Stevens attend?

Richard Stevens holds Computer Science Major from Colorado State University.

What skills is Richard Stevens known for?

Richard Stevens is listed with skills including Information Security, Vulnerability Assessment, Computer Security, Cissp, Security, Information Security Management, Vulnerability Management, and Penetration Testing.

Find 750M verified contacts

Search by job title, company, industry, location, and seniority. Export verified B2B contact data when you need it.