Headshot of Nick Strupp, smiling, in a striped collared shirt.

Senior Security Manager · CISSP

Nick Strupp

I build and run vulnerability management and application security programs for large enterprises.

More than 15 years in security, from penetration testing to leading programs of 60 people. I’m looking for a full-time role as a Senior Security Manager, Security Technical Program Manager or Director of Security. Based in St. Louis, open to remote, hybrid or relocation.

Get in touch LinkedIn

The record

At Accenture I grew a vulnerability management program from 12 people to 60, covering more than 5,000 applications.

  • 1,200 applications scanned with SAST and DAST every quarter, and about 750 penetration tests a year.
  • $10M+ a year in engagements, plus $3M+ a year in won work as lead subject matter expert for vulnerability management.
  • US Patent 11,106,801 for vulnerability triage orchestration. I architected the platform with my co-inventors.
  • Six analysts I mentored were promoted in one review cycle, and an earlier team I managed at Secureworks had the lowest turnover in its consulting organization.
Vulnerability management
Asset discovery and scanning through risk-based prioritization, remediation SLAs, exceptions and tracking, ranked by real exploitability (CISA KEV, EPSS, exposure and asset criticality) instead of raw CVSS.
Application security
SAST and DAST at scale, web application penetration testing, and security built into development (DevSecOps). Earlier, penetration tests and PCI assessments for Fortune 500 companies.
Program leadership
Security and technical program management across cross-functional teams: roadmaps, processes, security metrics and executive reporting, plus developing the people who do the work.
Frameworks
NIST CSF 2.0, PCI DSS v4.0.1, ISO 27001:2022 and SOC 2. Through FlintScope I publish a complete vulnerability management program mapped to all four.

How I think about risk

The scanner sorts everything by CVSS, and that’s almost never the order you should work in. CVSS says how bad a vulnerability could be. It doesn’t say whether anyone is exploiting it, whether it’s reachable, or whether the system matters.

So I build the score from those inputs, set SLAs on it, write down every exception with an owner and an expiry date, and report a few numbers executives can act on: how many open findings are exploited and reachable right now, and whether they’re getting fixed inside the SLA.

More of this on LinkedIn

Exploited and exposed comes first. CVSS is one input, not the whole score.

Hiring for vulnerability management or AppSec leadership?

I typically reply within one business day. The longer story is on the About page, and the patent, FlintScope and what I’ve built are on Projects.

Get in touch