JOHN TROTTA
Chief Technology & Security Officer
I build security and compliance programs where none exist, and they pass audits on the first try. I've done it in regulated financial services, from an empty network to a defense-in-depth operation with zero major incidents and a clean audit record across SOC 2, PCI, HIPAA, and NIST. I deploy AI systems that generate revenue and catch compliance failures before they become problems. I present to clients, close deals, advise ownership, and fix things that aren't in my job description. Operations management background, CISSP, and I still write code when it's the fastest path to the answer.
Experience
Chief Technology & Security Officer
RTR Financial Services, Inc.
August 2019 - Present
Staten Island, NY
Executive owner of security, compliance, and technology for a regulated mid-size financial services firm operating across hybrid on-prem and cloud. Functioning as the organization's CISO with full accountability for security strategy, risk, and compliance.
- Built the defense-in-depth security program from scratch across IAM, EDR, DLP, PKI, network security, and 24×7 SOC. Zero major incidents in seven years.
- Stood up SOC 2 Type II, PCI-DSS, and HIPAA from nothing, all mapped to NIST CSF. Designed the control frameworks, authored the policy library, defined the audit scope. First-time certification on every program.
- Passed 10+ audits end-to-end with zero material findings.
- Drove uptime from ~95% to 99.99%. Lead quarterly DR/BC testing against aggressive RPO and RTO targets.
- Designed and shipped an AI compliance monitoring platform that replaced manual spot-checking with full-coverage legal disclosure verification and sentiment analysis on customer calls. Closed the compliance blind spots sampling could never catch and gave managers hours back every week.
- Trusted advisor to ownership on risk, organizational design, and operational efficiency across the business, not just the technology side.
- Technical authority on proposals, RFPs, security questionnaires, and contract terms. Present directly to prospective regulated clients. Primary liaison to legal, auditors, and regulators.
- Drove down technology spend through architecture rationalization and vendor consolidation, even as the company scaled through major growth.
- Build AI ops tooling: agentic workflows that monitor, remediate, and report on their own. Anything risky still comes back for approval.
IT Manager
RTR Financial Services, Inc.
2016 - August 2019
Staten Island, NY
- Led the WannaCry ransomware recovery with no DR plan, no golden images, and no documented procedures. Coordinated an ad-hoc response across internal team and outside vendors. Restored full operations in 48 hours.
- Used the incident as the catalyst to stand up formal disaster recovery, business continuity, and security monitoring programs from scratch.
- Owned availability, security, patching, and compliance across every enterprise system and network.
Infrastructure & Security Lead
RTR Financial Services, Inc.
2014 - 2016
Staten Island, NY
- Designed and deployed enterprise domain architecture, network segmentation, server infrastructure, and the foundational security controls every program since has been built on.
- Established PowerShell and Python as the automation default. The operating model the company would scale on.
Systems Administrator
RTR Financial Services, Inc.
2012 - 2014
Staten Island, NY
- Assumed sole ownership of enterprise IT. Inherited a barely-managed network with no security controls and no documented policies.
Business Analyst
RTR Financial Services, Inc.
August 2008 - 2012
Staten Island, NY
- Analyzed business processes and operational workflows across revenue-generating departments. The cross-functional fluency I built here later shaped how I approached technology and security.
Press
All from AccountsRecovery.net
AI 101: Back to the Basics
April 2026
Getting to Know John Trotta of RTR Financial Services
December 2025
Teaching Prompt Engineering to Your Staff
March 2025
Using AI as a Research Tool and for Creation of Policies and Procedures
January 2025
Artificial Intelligence: Empowering Human Agents for Better Efficiency
November 2024
View all speaking engagements
Archive
Skills
Security and Compliance
Infrastructure and Cloud
Engineering and Automation
Executive Leadership
Certifications
Certified Information Systems Security Professional
ISC2
VMware Certified Professional
Data Center Virtualization 6.7
Microsoft Certified Solutions Expert
Windows Server Security and Core Infrastructure
Cisco Certified Network Associate
Implementing and Administering Cisco Solutions
Education
CUNY Baruch College
Zicklin School of Business
Bachelor of Business Administration, Operations Management
New York, NY
Projects
Compliance Monitoring Platform
AI platform that replaced manual spot-checking with full-coverage legal disclosure verification and sentiment analysis on customer calls. Closed the compliance blind spots that sampling could never catch.
Tech: Python, Speech-to-Text, LLM APIs, Sentiment Analysis
Homelab
Production-grade k3s cluster on ProxMox, GitOps-managed with Flux. Runs 25+ services across monitoring, automation, media, document management, and AI workloads. Bare metal.
Tech: ProxMox, k3s, Flux, Kube-Prometheus, Velero, Loki
OpsMan
Semi-autonomous AI ops manager for the homelab. Watches ProxMox and Kubernetes, runs approved Day-2 operations, logs everything. Anything risky comes back for approval.
Tech: Python, ProxMox API, Kubernetes API, Pushover
What I Build With
The core of what makes me productive. The rest of my stack lives in GitHub.