Steve Green, CISSP

Information Security & Cybersecurity Leader | IT & Physical Security Strategist | Risk & Compliance Expert

San Jose, California, United States

About

I’m a passionate information security leader with extensive experience building and leading security programs that protect both global enterprises and high-growth startups in regulated industries. My expertise spans incident response, threat intelligence, IT governance, risk management, and physical security, with a proven record of automating and integrating security practices into diverse business environments. I began my professional journey with a B.S. in Meteorology, where I honed analytical and problem-solving skills that continue to serve me in security today. I thrive on technology, continuous learning, and enjoy the adrenaline surge of incident management — having served as incident commander on major events, working with law enforcement, and guiding executive staff through critical decisions. As Director of IT Security at Abbott, I led IT, information security, and physical security, ensuring robust post-acquisition security and business continuity. Previously, as Senior Director, IT & CISO at Bigfoot Biomedical, I built and matured security and IT operations, achieving SOC 2 Type 2 certification, strengthening supply chain security, and enabling scalability for a fast-growing medical device startup. I also played a key role in Abbott’s acquisition of Bigfoot, leading IT and security due diligence and supporting seamless integration of people, processes, and technology. Earlier in my career, I led global security teams at Juniper Networks, where I built and operationalized cyber incident response programs, managed international teams in the U.S. and India, and enhanced enterprise-wide security strategies. At Sun Microsystems, I focused on security architecture, compliance, and IT transformation, contributing to long-term process and cultural improvements. Passionate about innovation, I continue to explore emerging technologies and their impact on security, business, and daily life. Outside of work, I’m an aviation enthusiast with a Private Pilot Certificate and Instrument Rating, and I maintain my lifelong fascination with meteorology — the field that sparked my love for data, analysis, and technology. If you want to connect to learn more about my professional story, please send me an InMail message or at [email protected]. Key Strengths: Security Operations | Incident Response | Threat Management | Risk Management & Compliance | Cybersecurity Strategy | Crisis Management | Security Architecture & Design | Strategic Leadership | Identity & Access Management | Data Privacy & Protection | IT Security Program Development | Risk Management

Experience

  • Director IT Security at Abbott
    Sep 2023 - Present · 2 yrs 10 mos

    In this role, I directed IT, information security, and physical security integration during Abbott’s acquisition of Bigfoot Biomedical (Sept 2023), ensuring a secure, compliant, and seamless transition of people, processes, and technology. Also, I oversaw enterprise security operations, system monitoring, and incident response to safeguard business continuity throughout the M&A process. Key contributions included leading the integration of security access badge systems across Bay Area facilities, coordinating employee transfers, and managing IT logistics such as laptop deployment, legacy device returns, and data migration for 100% of staff with minimal downtime. I directed the transition of employees to Abbott’s email, identity, and file storage systems, ensuring compliance with corporate security standards and enabling secure collaboration across merged teams. Additionally, I successfully executed the cutover of network and infrastructure services, maintaining uninterrupted operations and strong security posture during organizational change.

  • Bigfoot Biomedical (Milpitas, California, United States)
    • Senior IT Director and Chief Information Security Officer
      Mar 2020 - Sep 2023 · 3 yrs 7 mos

      I directed IT, information security, and physical security operations at a high-growth medical device startup with 100+ employees, leading a lean team to maximize efficiency, resilience, and compliance. I provided executives with IT and security dashboards that improved visibility into performance, risk, and regulatory posture, helping shape strategic decision-making. Highlights of my work include achieving the company’s first SOC 2 Type II certification with no significant auditor findings, advancing supply chain security through standardized third-party risk assessments, and strengthening DevSecOps practices in AWS and Salesforce by enforcing MFA, eliminating shared admin accounts, and securing CI/CD pipelines. I also designed end-to-end onboarding and offboarding processes with HR, implemented SSO for 100+ SaaS applications (reducing account management overhead by 75%), and led recurring vulnerability assessments that remediated 100% of critical risks within 30 days. In collaboration with Legal, Finance, and HR, I played a key role in facilitating Abbott’s acquisition of Bigfoot Biomedical, ensuring the secure integration of people, processes, and technology during the transition.

    • Director of Information Security
      Feb 2019 - Mar 2020 · 1 yr 2 mos

      I led the information security and physical security functions at a growing medical device startup, managing a lean team to deliver enterprise-grade protections in a fast-paced environment. I established mature security practices from the ground up, including policy development, security awareness training, role-based access controls, MFA, and password management, significantly strengthening the company’s security posture. I directed IT and security operations during a full site relocation, ensuring uninterrupted business operations and safeguarding sensitive systems and data. To support commercial operations and medical device manufacturing, I designed and implemented a highly available network by consolidating ISPs, firewalls, and power systems, achieving near 100% uptime post-deployment. I also enhanced network security through VLAN-based segmentation, reducing the attack surface and isolating critical systems from corporate and guest traffic. Beyond IT and cybersecurity, I deployed a modern physical security program, including access badges, integrated cameras, and alarms, to protect facilities and equipment for more than 200 employees and contractors.

  • Incident Response and Threat Intelligence Senior Manager at Juniper Networks
    Jan 2011 - Oct 2018 · 7 yrs 10 mos

    I established and led a global Cyber Incident Response Team (CIRT), building a 24/7 operation with 10 analysts in India and two in the US to deliver incident response, threat intelligence, and security operations at scale. I regularly traveled to align global teams, strengthen collaboration, and ensure consistent security standards across geographies. In this role, I built and matured enterprise capabilities to detect, analyze, contain, and recover from cyberattacks, transforming ad hoc practices into structured, measurable processes that significantly reduced detection and response times. I directed proactive threat monitoring and risk mitigation, neutralizing hundreds of potential incidents per quarter before they could impact the business. Prior to that, as an Information Security Solutions Architect, I advanced global security operations by deploying the ServiceNow Security Operations suite and managing a global MSSP, improving efficiency and accelerating response. I also helped shape enterprise-wide security strategy and culture by leading governance efforts, defining policies and standards, and delivering awareness training that reached over 10,000 employees worldwide.

  • Information Security Program Manager at Sun Microsystems
    Jan 2007 - Feb 2010 · 3 yrs 2 mos

    I led global security initiatives that strengthened compliance, threat detection, and organizational resilience across 13 international sites. This included deploying an Intrusion Detection System (IDS), rolling out Qualys vulnerability scanners, and migrating legacy auditing tools to Tripwire Enterprise to modernize security operations. To complement technical defenses, I drove enterprise-wide security awareness by publishing a daily Security News bulletin, helping employees stay informed, engaged, and proactive in safeguarding the organization.