JOHN TROTTA

Chief Technology & Security Officer

I build security and compliance programs where none exist, and they pass audits on the first try. I've done it in regulated financial services, from an empty network to a defense-in-depth operation with zero major incidents and a clean audit record across SOC 2, PCI, HIPAA, and NIST. I deploy AI systems that generate revenue and catch compliance failures before they become problems. I present to clients, close deals, advise ownership, and fix things that aren't in my job description. Operations management background, CISSP, and I still write code when it's the fastest path to the answer.

Experience

Chief Technology & Security Officer

RTR Financial Services, Inc.

August 2019 - Present

Staten Island, NY

Executive owner of security, compliance, and technology for a regulated mid-size financial services firm operating across hybrid on-prem and cloud. Functioning as the organization's CISO with full accountability for security strategy, risk, and compliance.

  • Built the defense-in-depth security program from scratch across IAM, EDR, DLP, PKI, network security, and 24×7 SOC. Zero major incidents in seven years.
  • Stood up SOC 2 Type II, PCI-DSS, and HIPAA from nothing, all mapped to NIST CSF. Designed the control frameworks, authored the policy library, defined the audit scope. First-time certification on every program.
  • Passed 10+ audits end-to-end with zero material findings.
  • Drove uptime from ~95% to 99.99%. Lead quarterly DR/BC testing against aggressive RPO and RTO targets.
  • Designed and shipped an AI compliance monitoring platform that replaced manual spot-checking with full-coverage legal disclosure verification and sentiment analysis on customer calls. Closed the compliance blind spots sampling could never catch and gave managers hours back every week.
  • Trusted advisor to ownership on risk, organizational design, and operational efficiency across the business, not just the technology side.
  • Technical authority on proposals, RFPs, security questionnaires, and contract terms. Present directly to prospective regulated clients. Primary liaison to legal, auditors, and regulators.
  • Drove down technology spend through architecture rationalization and vendor consolidation, even as the company scaled through major growth.
  • Build AI ops tooling: agentic workflows that monitor, remediate, and report on their own. Anything risky still comes back for approval.

IT Manager

RTR Financial Services, Inc.

2016 - August 2019

Staten Island, NY

  • Led the WannaCry ransomware recovery with no DR plan, no golden images, and no documented procedures. Coordinated an ad-hoc response across internal team and outside vendors. Restored full operations in 48 hours.
  • Used the incident as the catalyst to stand up formal disaster recovery, business continuity, and security monitoring programs from scratch.
  • Owned availability, security, patching, and compliance across every enterprise system and network.

Infrastructure & Security Lead

RTR Financial Services, Inc.

2014 - 2016

Staten Island, NY

  • Designed and deployed enterprise domain architecture, network segmentation, server infrastructure, and the foundational security controls every program since has been built on.
  • Established PowerShell and Python as the automation default. The operating model the company would scale on.

Systems Administrator

RTR Financial Services, Inc.

2012 - 2014

Staten Island, NY

  • Assumed sole ownership of enterprise IT. Inherited a barely-managed network with no security controls and no documented policies.

Business Analyst

RTR Financial Services, Inc.

August 2008 - 2012

Staten Island, NY

  • Analyzed business processes and operational workflows across revenue-generating departments. The cross-functional fluency I built here later shaped how I approached technology and security.

Skills

Security and Compliance

SOC 2 Type IIPCI-DSSHIPAANIST CSFSecurity Program LeadershipPolicy AuthoringAudit ManagementThird-Party Risk ManagementIncident Response

Infrastructure and Cloud

Hybrid Cloud StrategyCloud MigrationVDI & Remote WorkforceDisaster RecoveryBusiness ContinuityEnterprise ArchitectureTechnology ModernizationIT Service Management

Engineering and Automation

AI StrategyAI-Driven OperationsAgentic WorkflowsProcess AutomationInfrastructure as CodeCI/CDEngineering VelocityBuild vs. Buy

Executive Leadership

Strategic Advisory to OwnershipTechnology Budget ManagementVendor NegotiationOrganizational ScalingRevenue EnablementTeam LeadershipRegulator LiaisonLean Operations Management

Certifications

CISSP

Certified Information Systems Security Professional

ISC2

VCP

VMware Certified Professional

Data Center Virtualization 6.7

MCSE

Microsoft Certified Solutions Expert

Windows Server Security and Core Infrastructure

CCNA

Cisco Certified Network Associate

Implementing and Administering Cisco Solutions

Education

CUNY Baruch College

Zicklin School of Business

Bachelor of Business Administration, Operations Management

New York, NY

What I Build With

The core of what makes me productive. The rest of my stack lives in GitHub.