Richard Stevens

Richard Stevens Email and Phone Number

Secure Development Operations/Application Security Engineer at HealthCare Company @
Richard Stevens's Location
Charlotte, North Carolina, United States, United States
Richard Stevens's Contact Details

Richard Stevens work email

Richard Stevens personal email

About Richard Stevens

18 years of progressive information technology security consulting services, in the areas of web application vulnerability testing, source code evaluation, security automation (SecDevOps), cloud operations, compliance auditing, and web application programming.

Richard Stevens's Current Company Details
HealthCare Company

Healthcare Company

Secure Development Operations/Application Security Engineer at HealthCare Company
Richard Stevens Work Experience Details
  • Healthcare Company
    Devsecops Application Security Engineer
    Healthcare Company Jul 2021 - Present
    Starting, implementing and automating a DevSecOps application security program in an Azure cloud environment utilizing Azure Functions, Logic Apps, and Terraform.
  • Wells Fargo
    Information Security Engineer
    Wells Fargo Dec 2018 - Jul 2021
    San Francisco, California, Us
    Automation Engineer utilizing Python and PowerShell scripts to create workflow for the Qualys suite of tools. Duties include problem solving security engineer issues, automating existing manual processes, script performance enhancement, and implementing DevOps and Agile development processes.
  • Ingersoll Rand
    Senior Application Security Engineer
    Ingersoll Rand Apr 2017 - Nov 2018
    Davidson, North Carolina, Us
    Duties include selecting, implementing, and operating SAST (Checkmarx, Coverity) and DAST (Netsparker, Qualys WAS, Burp) scanning technologies, CI/CD integration activities, and operation of infrastructure vulnerability scans using Qualys VM.
  • Tiaa-Cref
    Lead Info Security Engineer
    Tiaa-Cref Apr 2014 - Apr 2017
    New York, Ny, Us
    Lead Information Security Engineer responsible for conducting in depth application security vulnerability assessments for new and existing applications via SAST and DAST scanning technologies. Responsible for training developers on the use of static code analysis tools (AppScan Source for Analysis) utilizing monthly developer workshops. Responsible for AppScan Enterprise database table mapping for selective exportation of vulnerability data to third party visualization tools for the production of application security metrics. Other duties include automation of common tasks via PowerShell.
  • Delhaize Group
    Senior Security Architect
    Delhaize Group Sep 2011 - Mar 2014
    Kobbegem, Be
    Information Security Architect position responsible for conducting in depth security risk assessments for new and existing applications to identify weaknesses or security exposures. Duties aligned with the OWASP SAMM (Software Assurance Maturity Model) verification step to include design review, code review, and security testing. Specialized in web service / application security utilizing OWASP ASVS (Application Security Verification Standard) in concert with automated IBM AppScan assessments.
  • Tennessee Valley Authority
    Information Security Specialist
    Tennessee Valley Authority Jul 2011 - Sep 2011
    Knoxville, Tn, Us
    Evaluation and creation of policies, procedures, and technical work instructions for compliance with FISMA and NERC-CIP requirements. Application security evaluation of intranet applications to include governance, risk and compliance (GRC) middleware.
  • Oak Ridge National Laboratory
    Contract Security Analyst - St&E
    Oak Ridge National Laboratory Dec 2010 - Aug 2011
    Oak Ridge, Tn, Us
    Contracted to perform ST&E for C&A of all ORNL unclassified systems utilizing NIST SP 800-53 rev. 3 control framework. Evaluated scientific and nuclear research technology for cyber security compliance and risk to include the nuclear High Flux Isotope Reactor (HFIR) and High Performance Computing.
  • Sti
    Senior Security Analyst
    Sti Jan 2003 - Nov 2010
    Various Tasks, including:
  • Tennessee Valley Authority (Tva)
    Senior Security Analyst (Consultant)
    Tennessee Valley Authority (Tva) Mar 2009 - Oct 2010
    Served as a Technical Lead for a team of auditors who conducted independent risk assessments, penetration testing, and cyber security assessments utilizing NIST SP 800-53 control framework. Created SSPs and analyzed policies and procedures for compliance with FISMA/C&A requirements. Identified threat/vulnerability pairs and evaluated compliance of management, technical, and operational controls for electric power generation control systems to ensure confidentiality, integrity, and availability of critical applications and infrastructure.
  • Advance America Corporation
    Senior Security Analyst (Consultant)
    Advance America Corporation May 2007 - Jan 2010
    Review policies, procedures, and guidelines to ensure multi-regulatory compliance. Security control evaluation (gap analysis) using COBIT and ISO 27001 control frameworks. Evaluate compliance with physical security requirements, backup and recovery operation requirements, logical access control requirements, configuration management requirements, audit trail logging and review requirements, security awareness training procedures, SDLC process review and recommendations. Java code review on proprietary financial applications, security testing with Canvas, and change management requirements as each pertains to ITGC of the Sarbanes-Oxley Act and NIST 800 Series FISMA requirements. Mentor other auditors and teach control framework and testing methodologies.
  • Custom Direct
    Senior Security Analyst (Consultant)
    Custom Direct Aug 2008 - Mar 2009
    Translate bank regulatory requirements into business and technical requirements. Develop policies, procedures, standards, and guidelines to meet diverse regulatory requirements. Provide guidance and support to configure hardware and software systems to meet requirements of ISO, GLBA, and PCI compliance under a common GRC framework. Perform security control evaluation (gap analysis) using COBIT, NIST, and ISO 27001 control frameworks. Evaluate compliance with physical security requirements, backup and recovery operation requirements, logical access control requirements, configuration management requirements, audit trail logging and review requirements, security awareness training procedures, SDLC process review and recommendations.
  • Nasa Multiple Centers
    Security Analyst (Consultant)
    Nasa Multiple Centers Jun 2006 - Mar 2009
    Conduct security control evaluation using NIST 800-53 control framework. Mentor other auditors and perform FISMA compliance evaluations. Evaluate compliance of physical security requirements, application security implementation, effectiveness of backup and recovery procedures, effectiveness of logical access control, effectiveness of configuration management, compliance with audit trail logging and review requirements, existence of security awareness training procedures, effectiveness of SDLC management, existence of risk assessment procedures, and other controls related to protecting the confidentiality, integrity and availability of critical applications and infrastructure
  • National Energy Technology Lab
    Senior Security Analyst (Consultant)
    National Energy Technology Lab Oct 2007 - May 2008
    ST&E based upon NIST 800-53A, NIST 800-37, NIST 800-30 and DOE guidelines. Systems evaluated included firewalls, Unix systems, Windows systems, IDS, Mainframe, and proprietary scientific applications. Assisted with creation and testing of COOP. Developed and executed custom UNIX scripts to determine extent of vulnerabilities. Conducted network penetration testing and vulnerability analysis in compliance with NIST 800-53A. Rated findings using risk scale and documented results and recommendations in final Security Assessment Report to allow Authorizing Official to make final approval to operate decision.
  • Noaa
    Security Analyst (Consultant)
    Noaa Oct 2005 - Oct 2006
    Performed ST&E testing on various NOAA information systems. Performed analysis of all NIST 800-53 controls by reviewing security policies and procedures, reviewing information security plans, reviewing server configurations, performing vulnerability assessments utilizing tools such as Nessus, Paros Proxy, and Canvas, interviewing information system representatives, and physically reviewing site where information systems reside.

Richard Stevens Skills

Information Security Vulnerability Assessment Computer Security Cissp Security Information Security Management Vulnerability Management Penetration Testing Application Security Risk Assessment Web Applications Secure Coding Secure Sdlc Active Directory Animal Husbandry Powershell Automation Autoit Security Awareness Iso 27001 Teaching It Professionals To Read

Richard Stevens Education Details

  • Colorado State University
    Colorado State University
    Computer Science Major
  • Colorado State University
    Colorado State University
    Chemistry
  • Sans Technology Institute
    Sans Technology Institute
  • Security Innovation Team Professor Cbts
    Security Innovation Team Professor Cbts
    Information Security Secure Coding
  • Cigital Cbt
    Cigital Cbt
    Information Security Secure Coding

Frequently Asked Questions about Richard Stevens

What company does Richard Stevens work for?

Richard Stevens works for Healthcare Company

What is Richard Stevens's role at the current company?

Richard Stevens's current role is Secure Development Operations/Application Security Engineer at HealthCare Company.

What is Richard Stevens's email address?

Richard Stevens's email address is ri****@****ref.org

What schools did Richard Stevens attend?

Richard Stevens attended Colorado State University, Colorado State University, Sans Technology Institute, Security Innovation Team Professor Cbts, Cigital Cbt.

What are some of Richard Stevens's interests?

Richard Stevens has interest in Code Review, Secure Software Development Life Cycle, Application Security.

What skills is Richard Stevens known for?

Richard Stevens has skills like Information Security, Vulnerability Assessment, Computer Security, Cissp, Security, Information Security Management, Vulnerability Management, Penetration Testing, Application Security, Risk Assessment, Web Applications, Secure Coding.

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Aero Online

Your AI prospecting assistant

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.