About

From penetration tester to program lead

15+ years in security, most of it building the teams and programs that turn vulnerability data into business decisions.

I started hands-on, running penetration tests and PCI assessments for Fortune 500 companies at VeriSign and handling incident response at the Federal Reserve Bank of St. Louis. At Secureworks I moved into management, and at Accenture I built and scaled the vulnerability management and application security program in the career history below.

The thread through all of it is risk-based prioritization. Rank the work by whether a vulnerability is being exploited, whether it’s reachable and whether the system matters. Write down every exception with an owner and an expiry date. Report a few numbers executives can act on. I architected the orchestration platform behind US Patent 11,106,801 with my co-inventors, and I still build tooling that works this way. I care just as much about developing the people who do the work.

What I want next: a full-time role where someone needs to own vulnerability management or application security end to end, develop the team, and report risk to executives in numbers they can act on.

Get in touch LinkedIn

Career

  1. Founder, FlintScope

    December 2024 to present · St. Louis

    I write and publish complete vulnerability management programs: policy, a two-stage prioritization model, triage and remediation runbooks, an executive metrics dashboard, and a crosswalk to NIST CSF 2.0, PCI DSS v4.0.1, ISO 27001:2022 and SOC 2. I also build the prioritization tooling that ranks findings by CISA KEV, EPSS, exposure and asset criticality. flintscope.com

  2. Senior Security Consulting Manager, Accenture

    November 2016 to December 2024

    Directed global teams of up to 60 people delivering SAST and DAST assessments of 1,200+ applications a quarter and penetration tests for 750 applications a year, on more than $10 million in annual engagements. Architected the application security orchestration and automation platform behind US Patent 11,106,801. Led vulnerability management workshops and proposals that won $3M+ a year, built reusable engagement materials that cut proposal response time by 30%, and mentored six analysts to promotion in a single review cycle.

  3. Senior Manager, Secureworks

    October 2010 to November 2016

    Managed a technical threat exposure management team generating $800K a month while meeting utilization targets, with the lowest employee turnover in the consulting organization. Built tools that cut reporting time by 70%, launched new service lines and a remote assessment offering, and standardized the assessment, penetration testing and reporting methodology across the team.

  4. Earlier

    Information Security Analyst, Federal Reserve Bank of St. Louis. Incident response, vulnerability scan analysis and remediation planning, and risk analysis of software before enterprise rollout.

    Senior Security Consultant, VeriSign. PCI assessments and penetration tests for Fortune 500 companies, and technical instruction on installing and troubleshooting enterprise applications.

Skills and certifications

Leadership

  • Security program management
  • Technical program management
  • Stakeholder management
  • Security metrics and executive reporting
  • Mentoring and team development

Vulnerability management

  • Risk-based prioritization
  • CISA KEV and EPSS
  • Remediation SLAs and exceptions
  • Incident response

Application security

  • SAST and DAST
  • Penetration testing
  • DevSecOps
  • PCI DSS, NIST CSF, ISO 27001, SOC 2

Certifications and training

  • CISSP (ISC2)
  • SABSA Foundation, ITIL Foundation v3
  • GIAC GCWN, GMOB, GAWN
  • SANS SEC505, 542, 575, 617, 660
  • Offensive Security, DoD Cyber Crime Center

Outside of work

I help with my family’s winery in rural Missouri, I’m developing an off-grid glamping property, and I build software with AI tools. A few of those apps are on the Projects page. I think the best security leaders stay curious, and building things is how I stay that way.

Nick Strupp smiling beside an excavator at a dig site in the woods.