Travis Ruff Email and Phone Number
Travis Ruff work email
- Valid
- Valid
- Valid
- Valid
Travis Ruff personal email
- Valid
Travis Ruff phone numbers
Senior security leader with a proven track record of establishing and leading business-focused global risk management organizations. Effective communicator and influencer throughout all levels of the enterprise with a strong reputation for developing deep business knowledge and establishing relationships with business resources. Demonstrated focus on employee development and engagement, business enablement, service delivery, and project and portfolio management. Specific areas of expertise include:- Enterprise Risk Assessment & Management- Legal & Regulatory Compliance- Secure Systems Development Lifecycle- Security Architecture- Business Collaboration & Enablement- Business Continuity & Disaster Recovery- 3rd Party & Vendor Risk Management- M&A Due Diligence/Integration- Training Development & Delivery- Incident Response & Forensics
-
Engineering Manager, Security Business EnablementStripe Nov 2022 - PresentSouth San Francisco, California, Us -
Sr. Manager, Information Security Engineering, Governance, And PrivacyAmazon Web Services (Aws) Oct 2020 - Dec 2022
-
Sr. Manager, Information Security Engineering And Risk ManagementAmazon Mar 2019 - Oct 2020Seattle, Wa, Us -
CisoAmperity Nov 2017 - Mar 2019Seattle, Washington, UsDesigned and built the information security and compliance program for a startup processing trillions of PII records. Identified and consolidated compliance, legal, and regulatory requirements for more than a dozen distinct business regions. Acted as the face of risk and security to prospective and current customers.* Created the information security go-to-market strategy and trained executives and sellers on current and prospective customers’ security and risk concerns. Engaged with CIO/CTO/CISO/CMO counterparts to establish trust and address security, compliance, and third-party risk concerns, enabling a fourfold revenue increase in one year.* Built a comprehensive information security policy, risk assessment methodology, and maturity model addressing the architecture, infrastructure, application, and operations components of critical systems. Enabled risk posture measurement, management, and prioritization of investments in the context of impacts on business objectives and initiatives for the company and our customers.* Managed the SSAE 18/SOC 2 compliance program, including objective scoping, control mapping, sprint/release planning for compliance-related initiatives, and audit execution. Initial audit completed without exceptions with less than three months of preparation. -
Sr. Director, Information SecurityAvalara Feb 2015 - Nov 2017Durham, Nc, UsFormed and managed the enterprise security and risk management function in a rapidly growing SaaS and professional services organization, overseeing infrastructure, application, operational, and physical security. Set and achieved clear and compelling risk management objectives aligned with corporate goals for growth and acquisition, enabling Avalara to reach new markets and secure enterprise-level customers.* Engaged with current and prospective customers, partners, and vendors to establish credibility and address information security, risk management, data privacy, compliance, and availability concerns. Worked directly with Avalara, partner, and customer legal counsel to review contracts, negotiate terms, and ensure Avalara’s interests were appropriately protected. * Managed security features and requirements for all products and implemented DDoS mitigation, vulnerability and compliance scanning, automated patch and configuration management, static and dynamic code analysis, SIEM, PKI, anti-malware, and data encryption capabilities. Managed the customer-requested security feature and capability backlog.* Established SSAE 16 SOC 1/SOC 2, PCI, HIPAA, and EU data privacy compliance programs for multiple products and services. Managed objective scoping, execution, and ongoing relationships with external auditors and regulators.* Implemented an enterprise-wide GRC toolset for the management of all risk, policy, compliance, and privacy-related requirements and controls. Provided executive visibility across systems and business units to identify and address both individual deficient processes and broader systemic failures. Regularly presented Avalara’s overall risk posture, progress, and recommendations to the Risk Committee and Board of Directors. -
Principal Security EngineerAvalara Aug 2013 - Feb 2015Durham, Nc, UsImplemented foundational security and risk management processes and toolsets as the first information security professional at Avalara. Performed risk assessments on multiple business processes, products, services, and solutions to guide investment and set the company’s strategic direction.* Implemented a vulnerability management program providing real-time visibility into patch, configuration, and exploit state and automated patch deployment capabilities across corporate and production networks, including 1,800 local and remote clients, 800 servers in offices and co-located/AWS datacenters, and 400 networking and infrastructure components.* Instituted a Data Privacy program as part of two EU-based acquisitions, coordinating with internal and external legal counsel, product managers, engineering, operations, and executives to provide clear guidance and ensure compliance with EU regulatory requirements. Developed sales and marketing collateral to consistently represent Avalara’s commitment to data privacy. -
Principal Security ArchitectMicrosoft Apr 2012 - Aug 2013Redmond, Washington, UsBusiness relationship manager between Information Security/Risk Management and the Global Sales & Marketing organization, providing risk assessment and prioritization, portfolio management, security strategy, and architecture consulting. Partnered with business and technical teams to align strategies, determine acceptable risk levels, and establish strategic and tactical plans to enable effective business risk management for internal and external customers. * Engaged with engineering and service delivery teams during incidents and drove root cause analysis activities. Identified and re-architected broken business processes and supporting systems, closing critical gaps with significant potential financial and reputational impacts in a system generating more than $1 billion in annual revenue.* Developed the security architecture for a high-visibility incentive compensation outsourcing initiative and provided risk management consulting during the negotiation and implementation of a $60 million multi-year contract.* Developed and maintained Azure migration templates and reference architectures for common application patterns. Consulted with internal and external application teams to ensure compliance and security objectives were appropriately identified, implemented, and verified as part of the migration process. -
Global Application Security ManagerCargill Jun 2008 - Apr 2012Wayzata, Minnesota, UsProvided leadership and strategic direction for application security and systems development in a $120 billion global enterprise operating in 63 countries with 74 distinct lines of business. Owned application risk management, service provider assessments, internally developed and COTS software security, and the system development lifecycles. Developed and provided leadership to the application security team, consisting of a mix of seasoned security professionals and recent college graduates.* Architected and drove the implementation of a secure systems development lifecycle, integrating risk management, security, and quality assurance activities into the development, selection, implementation, and operation of IT systems to more than 2,000 engineers and IT operations personnel.* Implemented a comprehensive risk dashboard providing visibility on known vulnerabilities, risk exposure, remediation activities, and accepted risks to business unit and platform executives.* Directed application risk assessments, remediation activities, and integration for M&A during valuation, due diligence, and post-close phases with an annual global M&A spend averaging $8 billion. * Managed global PCI-DSS and secure payment zone operations activities with enterprise-wide compliance achieved in four months, protecting a $1 billion annual revenue stream and delivering $3 million in direct cost savings annually. -
Senior Data And Application ArchitectCargill Jul 2007 - Jun 2008Wayzata, Minnesota, UsDirected the Enterprise Data and Application Architecture organization, establishing reference architectures and managing the lifecycle of application development and database technologies of a $15B global business. Developed the enterprise architecture strategy ensuring support for emerging technologies, sourcing initiatives, and significant M&A activities, and aligned with business and software engineering functions. -
Business Analyst/Application ManagerCargill Feb 2006 - Jul 2007Wayzata, Minnesota, UsFunctioned as the product manager and liaison between lines of business and IT shared services, managing a portfolio of six manufacturing control and quality assurance applications supporting 27 business units and 100+ global locations. Built and led a global team of business and technical resources, providing full-stack development, operations, and 24/7 support. -
Software EngineerDonatelle Sep 2004 - Feb 2006New Brighton, Mn, UsDesigned, developed, and maintained inventory management, material traceability, manufacturing control, and business intelligence software. Managed compliance with FDA regulatory requirements for both internally developed and commercial software through the integration of audits, code reviews, testing, and validations into the software development lifecycle. -
Database Administrator/Software EngineerHomeshield Apr 2002 - Sep 2004UsManaged all aspects of multiple databases supporting ERP/MRP systems, including performance tuning, backups, disaster recovery, and security/compliance. Customized and extended commercial software packages to support specific business needs. Created and maintained architecture, data, and security standards. Core member of the ERP implementation team.
Travis Ruff Skills
Travis Ruff Education Details
-
Harvard Business SchoolProgram For Leadership Development -
Minnesota State University, MankatoMis
Frequently Asked Questions about Travis Ruff
What company does Travis Ruff work for?
Travis Ruff works for Stripe
What is Travis Ruff's role at the current company?
Travis Ruff's current role is Information Security Engineering, Governance, and Data Privacy.
What is Travis Ruff's email address?
Travis Ruff's email address is ts****@****zon.com
What is Travis Ruff's direct phone number?
Travis Ruff's direct phone number is (952)-742*****
What schools did Travis Ruff attend?
Travis Ruff attended Harvard Business School, Minnesota State University, Mankato.
What skills is Travis Ruff known for?
Travis Ruff has skills like Enterprise Risk Management, Strategic Planning, Tactical Planning, Risk Assessment, Security Architecture Design, Training And Development, Secure Application Development, Third Party Risk Management, Business Collaboration, Business Analysis, Data Architecture, Application Architecture.
Who are Travis Ruff's colleagues?
Travis Ruff's colleagues are Wendy Guo, Genesis Medina, Ian Wright, Bogdan Taranta, Robert Aurora, Brittany I., Bhumika Keswani.
Free Chrome Extension
Find emails, phones & company data instantly
Aero Online
Your AI prospecting assistant
Select data to include:
0 records × $0.02 per record
Download 750 million emails and 100 million phone numbers
Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.
Start your free trial