Senior Security Manager · CISSP
Nick Strupp
I build and run vulnerability management and application security programs for large enterprises.
More than 15 years in security, from penetration testing to leading programs of 60 people. I’m looking for a full-time role as a Senior Security Manager, Security Technical Program Manager or Director of Security. Based in St. Louis, open to remote, hybrid or relocation.
The record
At Accenture I grew a vulnerability management program from 12 people to 60, covering more than 5,000 applications.
- 1,200 applications scanned with SAST and DAST every quarter, and about 750 penetration tests a year.
- $10M+ a year in engagements, plus $3M+ a year in won work as lead subject matter expert for vulnerability management.
- US Patent 11,106,801 for vulnerability triage orchestration. I architected the platform with my co-inventors.
- Six analysts I mentored were promoted in one review cycle, and an earlier team I managed at Secureworks had the lowest turnover in its consulting organization.
What I lead
- Vulnerability management
- Asset discovery and scanning through risk-based prioritization, remediation SLAs, exceptions and tracking, ranked by real exploitability (CISA KEV, EPSS, exposure and asset criticality) instead of raw CVSS.
- Application security
- SAST and DAST at scale, web application penetration testing, and security built into development (DevSecOps). Earlier, penetration tests and PCI assessments for Fortune 500 companies.
- Program leadership
- Security and technical program management across cross-functional teams: roadmaps, processes, security metrics and executive reporting, plus developing the people who do the work.
- Frameworks
- NIST CSF 2.0, PCI DSS v4.0.1, ISO 27001:2022 and SOC 2. Through FlintScope I publish a complete vulnerability management program mapped to all four.
How I think about risk
The scanner sorts everything by CVSS, and that’s almost never the order you should work in. CVSS says how bad a vulnerability could be. It doesn’t say whether anyone is exploiting it, whether it’s reachable, or whether the system matters.
So I build the score from those inputs, set SLAs on it, write down every exception with an owner and an expiry date, and report a few numbers executives can act on: how many open findings are exploited and reachable right now, and whether they’re getting fixed inside the SLA.
Exploited and exposed comes first. CVSS is one input, not the whole score.