About

At Aedify, our passion goes beyond cybersecurity; it empowers organizations to mature at scale while nurturing their individuals to achieve. We are sincere partners in navigating digital transformation securely. We prioritize deep listening, allowing us to comprehend the unique contexts and problems our customers face. This approach, combined with our commitment to fostering individual careers, means that we offer more than just delivered services; we guide and mentor with unwavering dedication, ensuring that each individual has the resources and knowledge they need to thrive.

When we say we “live in the trenches,” we mean it. At Aedify, collaboration isn’t just a buzzword. It is our practice to stand shoulder to shoulder with our team and clients, rolling up our sleeves to help them deliver outcomes security faster.

It's about nurturing talent to foster maturity in software security initiatives, ensuring that the growth of the individual and the organization are inextricably linked and mutually reinforcing.

Our Culture

Leadership

John Steven

Managing Principal

President, Founder

Through his firm Aedify, John advises innovative security product startups as well as CISOs maturing software security initiatives. For two decades, John led technical direction at Cigital, where he rose to the position of co-CTO. He founded spin-off Codiscope as CTO in 2015. When both Cigital and Codiscope were acquired by Synopsys in 2016, John transitioned to the role of Senior Director of Security Technology and Applied Research. His expertise runs the gamut of software security—from managing security initiatives, to cloud security, to threat modeling and security architecture, to static analysis, as well as risk-based security orchestration and testing.  

John is keenly interested in engineering-led and software-defined security governance at the cadence of modern development. As a trusted adviser to security executives, he uses his unparalleled experience to build, measure, and mature security programs. He has co-authored the BSIMM study and served as co-editor of the Building Security In department of IEEE Security & Privacy magazine. John is regularly invited to speak and keynote. 

Sammy Migues

Senior Principal

Frequent Contributor

Sammy Migues is a lifelong innovator who has made a career of helping organizations address hard cybersecurity problems. He contributed practical security models and approaches to computer and network security seminal works such as the Rainbow Books, Common Criteria, PCI, CMU CERT, and Government and NIST standards. More recently, he is a creator of the Building Security In Maturity Model (BSIMM), a set of controls and an assessment methodology for creating software security program scorecards. He is also a creator of The CISO Study, an analysis of and scoring approach for security management practices. 

In his career, Sammy has held technical leadership positions at Synopsys, Cigital, TruSecure/Cybertrust, and defense contractors, and for high-profile clients in every major market sector. To address evolving needs, his marketplace solutions span software security, governance and risk management models, compliance, metrics and dashboards, and other areas. 

 Sammy’s writings have appeared in journals such as IEEE Security & Privacy, IEEE Software, ACM Proceedings, and many industry publications. He is a frequent speaker and is often asked to simplify complex topics for the press and others needing guidance in making important decisions. 

We look forward to welcoming you into our community.