About
At Aedify, our passion goes beyond cybersecurity; it empowers organizations to mature at scale while nurturing their individuals to achieve. We are sincere partners in navigating digital transformation securely. We prioritize deep listening, allowing us to comprehend the unique contexts and problems our customers face. This approach, combined with our commitment to fostering individual careers, means that we offer more than just delivered services; we guide and mentor with unwavering dedication, ensuring that each individual has the resources and knowledge they need to thrive.
When we say we “live in the trenches,” we mean it. At Aedify, collaboration isn’t just a buzzword. It is our practice to stand shoulder to shoulder with our team and clients, rolling up our sleeves to help them deliver outcomes security faster.
It's about nurturing talent to foster maturity in software security initiatives, ensuring that the growth of the individual and the organization are inextricably linked and mutually reinforcing.
Our Culture

Bringing Art into Scalable Practice
Aedify's Founder brings over 25 years of pioneering expertise in software security, establishing a legacy of transforming theoretical 'art' into measurable, industry standard practices. We were at the helm developing now-ubiquitous techniques like threat modeling, static analysis, and penetration testing at scale. Our role in creating the BSIMM study revolutionized how organizations' are gauged.
Our commitment to innovation has been unwavering, including founding security tool startups and steering benchmark-setting early security initiatives.

Enabling Orgs by Growing Individuals
At Aedify, we're committed to the individual's journey as much as the organization's advancement. We act as mentors and sherpas, guiding security professionals along a career path marked by continuous learning and leadership in software security.
Our personalized mentorship equips individuals with the skills and insights needed to elevate their organization's security practices. It's about nurturing talent to foster maturity in software security initiatives, ensuring that the growth of the individual and the organization are inextricably linked and mutually reinforcing.

Coaching and Playing in Action
At Aedify, we believe that the true measure of knowledge is in its execution. Our expertise extends beyond academic to the practical implementation of security strategies in varied organizational contexts. As architects of change, our thought leadership is complemented by a pragmatic approach—engaging directly with challenges and delivering hands-on solutions.
This approach ensures that our contributions are not just solutions but integral transformations, empowering leaders to take control of their security narrative and confidently navigate the future.
Leadership

John Steven
Managing Principal
President, Founder
Through his firm Aedify, John advises innovative security product startups as well as CISOs maturing software security initiatives. For two decades, John led technical direction at Cigital, where he rose to the position of co-CTO. He founded spin-off Codiscope as CTO in 2015. When both Cigital and Codiscope were acquired by Synopsys in 2016, John transitioned to the role of Senior Director of Security Technology and Applied Research. His expertise runs the gamut of software security—from managing security initiatives, to cloud security, to threat modeling and security architecture, to static analysis, as well as risk-based security orchestration and testing.
John is keenly interested in engineering-led and software-defined security governance at the cadence of modern development. As a trusted adviser to security executives, he uses his unparalleled experience to build, measure, and mature security programs. He has co-authored the BSIMM study and served as co-editor of the Building Security In department of IEEE Security & Privacy magazine. John is regularly invited to speak and keynote.

Sammy Migues
Senior Principal
Frequent Contributor
Sammy Migues is a lifelong innovator who has made a career of helping organizations address hard cybersecurity problems. He contributed practical security models and approaches to computer and network security seminal works such as the Rainbow Books, Common Criteria, PCI, CMU CERT, and Government and NIST standards. More recently, he is a creator of the Building Security In Maturity Model (BSIMM), a set of controls and an assessment methodology for creating software security program scorecards. He is also a creator of The CISO Study, an analysis of and scoring approach for security management practices.
In his career, Sammy has held technical leadership positions at Synopsys, Cigital, TruSecure/Cybertrust, and defense contractors, and for high-profile clients in every major market sector. To address evolving needs, his marketplace solutions span software security, governance and risk management models, compliance, metrics and dashboards, and other areas.
Sammy’s writings have appeared in journals such as IEEE Security & Privacy, IEEE Software, ACM Proceedings, and many industry publications. He is a frequent speaker and is often asked to simplify complex topics for the press and others needing guidance in making important decisions.
