JOHN TROTTA
Technology and security leader for regulated financial services.
Technology and security leader with 18 years in regulated financial services, still hands-on today. I build and run the whole infrastructure and security program for a 300-employee firm, from network and identity through compliance, detection, and AI in production. I've stood up security and compliance from nothing with a clean audit record, run point on the incidents that mattered, and turned vague business problems into systems that ship. CISSP and PMP, and I still write code when that's the fastest way to the answer.
Experience
Chief Technology & Security Officer
RTR Financial Services, Inc.
August 2019 - Present
Staten Island, NY
Functioning as the company's CISO under a Chief Technology & Security Officer title. Own security, technology, and compliance for a 300-employee regulated financial services firm across hybrid on-prem and cloud, on a $2M budget: decide what gets built, build it with the team, and own how it runs. Report to ownership.
- Built and run the security program as defense in depth: behavior-based EDR (SentinelOne) and ThreatLocker application allow-listing on the endpoint, DLP across the network and application layers, an email-security detection program, and SIEM-based monitoring with insider-threat alerting on new-hire risk signals. I set the coverage and priorities; the security engineers operate the stack. It has caught real phishing and flagged and removed real insider risk.
- Detected, investigated, and contained a third-party compromise that reached the environment through a vendor: scoped the blast radius and confirmed it went no further, remediated it, and closed the gap with tighter controls and vendor oversight.
- Stood up PCI-DSS and SOC 2 Type II with HIPAA controls from nothing, first-time certification on each, mapped to NIST CSF, 10+ audits with zero material findings, and wrote the incident-response plan and every security runbook from a blank page.
- Delivered AI into production inside a strict compliance boundary, with the model architecturally separated from regulated data. Segmented the network into isolated zones with MFA and least-privilege access across identity, devices, and data.
- Built the company's first real disaster recovery and continuity and drove uptime to 99.99%, scaled the environment from 75 to 300 employees, and moved to multi-state remote operations in a week when COVID hit, opening 8+ states.
- The technical voice to ownership, clients, legal, and regulators: turned vague business problems into systems that ship, and carried the proposals, RFPs, and security reviews behind eight-figure regulated-client revenue.
IT Manager
RTR Financial Services, Inc.
2016 - August 2019
Staten Island, NY
- Led the endpoint response to the 2017 WannaCry outbreak: contained the estate, coordinated recovery, and restored full operations in 48 hours. The root cause was signature AV with no patching, so I closed it with managed patching (WSUS), a domain GPO security baseline, behavior-based EDR, and LAPS.
- Took over a consultant-run environment and built the security function in-house, the in-sourcing my CTSO role was created from in 2019. Replaced a 30-minute manual account-provisioning process with a PowerShell workflow we later turned into the zero-touch tool HR uses today.
- Owned availability, security, patching, and compliance across every enterprise system.
Infrastructure & Security Lead
RTR Financial Services, Inc.
2014 - 2016
Staten Island, NY
- Transformed how the existing environment was used: reworked current tools, standardized automation with PowerShell and Python, added new systems as extensions to what was already in place, and built the procedures to meet new client requirements.
Systems Administrator
RTR Financial Services, Inc.
2012 - 2014
Staten Island, NY
Business Analyst
RTR Financial Services, Inc.
August 2008 - 2012
Staten Island, NY
Press
All from AccountsRecovery.net
AI 101: Back to the Basics
April 2026
Getting to Know John Trotta of RTR Financial Services
December 2025
Teaching Prompt Engineering to Your Staff
March 2025
Using AI as a Research Tool and for Creation of Policies and Procedures
January 2025
Artificial Intelligence: Empowering Human Agents for Better Efficiency
November 2024
View all speaking engagements
Archive
Skills
Detection & Response
Security & Compliance
Infrastructure & Cloud
Engineering & AI
Executive Leadership
Certifications
Certified Information Systems Security Professional
ISC2 · #928259
Project Management Professional
PMI · #9852796
VMware Certified Professional
Data Center Virtualization 6.7
Microsoft Certified Solutions Expert
Windows Server Security and Core Infrastructure
Cisco Certified Network Associate
Implementing and Administering Cisco Solutions
Education
CUNY Baruch College
Zicklin School of Business
Bachelor of Business Administration, Operations Management
New York, NY
Projects
Homelab
Production-grade k3s cluster on ProxMox, GitOps-managed with Flux. Runs 25+ services across monitoring, automation, media, document management, and AI workloads. Bare metal.
Tech: ProxMox, k3s, Flux, Kube-Prometheus, Velero, Loki
OpsMan
Semi-autonomous AI ops manager for the homelab. Watches ProxMox and Kubernetes, runs approved Day-2 operations, logs everything. Anything risky comes back for approval.
Tech: Python, ProxMox API, Kubernetes API, Pushover
What I Build With
The core of what makes me productive. The rest of my stack lives in GitHub.