Founded in 2010, we’re not your typical security firm.. We specialize in protecting the people, processes, data, and technology that drive your organization—without the gimmicks or one-size-fits-all solutions.
How We Work
- We Listen First: Every organization has unique challenges. We start by understanding yours.
- We Solve Real Problems: Our team has deep, operational experience. We don’t rely on guesswork or cookie-cutter fixes.
- We Stay Independent: We never upsell or resell products you don’t need, so you can trust our recommendations.
Why It Matters
- Fewer Surprises: By tailoring solutions to your exact environment, we reduce the risk of nasty surprises and keep costs under control.
- Better Outcomes: You get security solutions that actually address your threats and fit your culture, not just something that looks good on paper.
- Trusted by Global Clients: Organizations worldwide partner with us year after year because we deliver what we promise.
Our Commitment
- Expertise That Works: We bring real-world know-how, not just theory.
- Continual Learning: Threats evolve, so do we—constantly improving to keep you protected.
- Your Success First: When we do our job well, you can keep doing yours.
Leadership Team
Our leaders combine deep operational experience with a passion for tackling complex security challenges. They’ve steered global initiatives, earned industry recognition, and consistently delivered measurable impact for our clients.
Together, they shape the vision, drive innovation, and uphold the high standards that define who we are—and how we protect what matters most to you.
Leadership Team
Mark Stamford
Founder & CEO
Mark started playing around with computers at age 8, eventually growing up and gaining over 25 years of experience in cybersecurity, operations, and more. Prior to founding OSec, he worked at UBS and KPMG.
Erin Murtha
Chief Operations Officer
Erin brings over 20 years of experience in ensuring optimal organizational performance, growth, and client success. Her prior experience includes work at Homeland Security managing projects of critical national importance.
Robbie Tyrie
Chief Technical Officer
Robbie leads our technology strategy, ensuring innovative solutions that align with our business goals. He drives our team to deliver cutting-edge, scalable technologies for success.
Christian Kimball
Technology Director
Christian has over 20 years of experience in IT, security, risk management, and implementing security risk programs. He has conducted offensive security engagements, and specializes in physical security and threat intelligence.
Cayce Mahon
CTI Director
Cayce leads the CTI Team. With over 10 years experience in offensive security operations, Cayce leads the threat intel and vulnerability research teams at OSec.
Spencer Lindgren
Operations Lead
Spencer has a background in healthcare technology, encryption, security, and compliance. He has held roles at telemedicine provider Vigilint, Patronus Medical, and assistant adjunct professor at UNC Chapel Hill.
Matt Landers
Assessment Director
Matt's career spans over 20 years focused on discovering and researching security vulnerabilities. He is passionate about finding unintended uses for common technology stacks.
Jimmy Fisher
CTEM Director
Jimmy Fisher is a cybersecurity practitioner and U.S. Army Veteran with multiple professional certifications, including OSCP, specializing in offensive security and penetration testing.
Mark Stamford
Mark started in security at age 11, eventually turning it into a career where he now has over 20 years of professional experience in cybersecurity, operations, control assessment, and related fields. He started OccamSec in 2010 to help organizations find, address, and minimize exposure to cybersecurity threats, and with aspirations of saving the world. Prior to founding OSec, he worked as director of threat and vulnerability management at UBS, and at KPMG, conducting penetration tests and identifying global threats for Fortune 100 clients.
Erin Murtha
Erin has 20 years of experience in operations and risk mitigation. She previously worked at the U.S. Department of Homeland Security, where she evaluated preparedness for nationwide emergencies and responded to inquiries from the National Security Council, Department of Justice, and Congress to improve the country’s security posture. Erin holds a B.A. in international policy studies from Elmira College and an M.A. in international commerce and policy from George Mason University.
Robbie Tyrie
Robbie has over 20 years experience across a range of technology roles. Working in both software development and information security, his prior roles include being part of the senior information security leadership team at FNZ, IT SEcurity manager at Aegon, Security consultant at Clydesdale Bank, and a number of other roles across the finance and pulic sectors.
Christian Kimball
Christian has over 20 years of experience in IT, security, risk management/assessment, and implementing security programs within regulatory and compliance governance. He has conducted offensive security engagments to evaluate cyber, physical, and social engineering security protections, and specializes in physical security and threat intelligence.
Cayce Mahon
Cayce’s first computer was an old IBM 486 running MS-DOS. From there, she learned how to code, pick locks, manipulate many OS flavors, and finally learned how to circumvent security controls within cyber, social, and physical environments. One of her favorite projects resulting in her breaching a busy office building and exfiltrating physical and stored company data from simply talking an employee out of their keycard and workstation. She hopes there are many more projects like these in the future.
Spencer Lindgren
Spencer has a background in healthcare technology, encryption, security, and compliance, with expertise in implementing security programs while maintaining HIPAA compliance. Prior to OSec, he was an assistant adjunct professor at UNC Chapel Hill, VP of clinical operations at Patronus Medical, and program manager at telemedicine provider Vigilint. Spencer holds a B.S. in geography and a Master of Public Health, both from UNC Chapel Hill.
Matt Landers
Throughout his career at OSec he has led red team engagements, penetration tests and special research projects to identify risk. Prior to working at OSec Matt worked as a private security consultant and taught at the Upper Peninsula Cybersecurity Institute at Northern Michigan University.
Matt Landers has been an accomplished consultant and security researcher for over 20 years. At OSec he has led red team engagements, penetration tests and special research projects to identify risk. His passion lies in discovering unintended uses for common technologies, this includes utilizing various APIs and IOT protocols to communicate with compromised hosts. In addition to his hands-on work, Matt is an active member of the infosec community, sharing his expertise as a guest speaker and lecturer at Northern Michigan University and the Upper Peninsula Cybersecurity Institute.
Jimmy Fisher
Jimmy Fisher is a cybersecurity practitioner and U.S. Army Veteran with multiple professional certifications, including OSCP, specializing in offensive security and penetration testing. Drawing from his military background and disciplined approach, Jimmy excels at identifying and mitigating vulnerabilities to strengthen organizational security. Passionate about mentorship, he actively contributes to the cybersecurity community, fostering collaboration, continuous learning, and the development of future security professionals.
Jimmy is deeply committed to client success, ensuring that organizations not only address vulnerabilities but also build stronger, more resilient security postures. By tailoring his approach to meet each client's unique needs, he delivers actionable insights and solutions that drive measurable improvements. His dedication to helping clients achieve their security goals reflects his passion for making a meaningful impact in the field of cybersecurity.
Advisory Board
Neil Bryden
Advisor
Neil has over 35 years of experience in IT risk and security, including CISO roles at KPMG and other global enterprises. He has also advised CISOs across various industries, and has experience across governance, architecture, and strategy.
Robert Hayes
Advisor
Robert holds board, director, and advisory roles at public and private organizations, helping mitigate security risks during complex business transformations. He is an acknowledged expert in cybersecurity, and former Microsoft senior fellow.
Philip Niedermair
Advisor
Philip has over 35 years of experience in helping companies expand their potential through corporate development, strategic alignment, and relationship building. Philip is a Senior Advisor to the Cyberspace Solarium Commission.
John Quigg
Advisor
John is a senior staff member at the Johns Hopkins University Applied Physics Laboratory, supporting the DoD’s security initiatives in cloud, 5G, and cyber situational awareness. His background is the Airborne Rangers and DoD.
Chris Reid
Advisor
Chris is the Chief of Staff for Elastic's US Public Sector. He retired last year after 36 years in the US Army where he served as a Brigadier General in Cyber and Special Operations assignments in the US and overseas.
Neil Bryden
Neil has over 35 years of experience in IT risk and security, having designed, implemented, and managed security transformation programs. Most recently, he was CISO at Teleperformance, co-chair of Pacific Northwest Cybersecurity Business Leadership Council at University of Washington Bothell, and served as chief cyber security strategist at Hewlett Packard Enterprise. Prior to those roles, he began his career at KPMG, spending nearly 30 years at the firm and rising to principal and CISO. Over his career, Neil has advised CISOs across various industries, and has experience on the security aspects of governance, architecture, outsourcing, business continuity, and strategy. Neil holds a B.Acc. in accountancy from University of Glasgow.
Robert Hayes
Robert holds board, director, and advisory roles at many public and private organizations, helping mitigate security risks during complex organizational transformations. He is an acknowledged expert in cybersecurity, crisis management, and strategic risk assessment, and an international authority on policy and regulatory issues between governments and the technology and communications industries. Robert served as a senior fellow of the Microsoft Institute for Advanced Technology in Governments, and as senior director, strategy and partnerships, in Microsoft’s Enterprise Cybersecurity Group. His prior experience includes hostage negotiation, being appointed inaugural head of the U.K. National Specialist Law Enforcement Centre, developing the U.K. National Hi-Tech Crime Training Centre, and serving as head of the U.K. National Technical Assistance Centre. Currently, Robert is a member of the Scottish Cyber Resilience Advisory Board, a fellow of the British Computer Society, a member of the Expert Advisory Panel at the Global Cyber Security Capacity Centre at the University of Oxford, and advises the U.K. Ministry of Defence on cybersecurity matters while holding the rank of Major (V) in the Engineer and Logistics Staff Corps of the British Army.
Philip Niedermair
Global corporate strategy leader, innovator, disruptor, connector. Philip has over 35 years of experience in helping companies expand their potential through corporate development, strategic alignment, and relationship building.
Philip is a Senior Advisor to the Cyberspace Solarium Commission and serves as a company Director to LPFIRSTCAPITAL PE firm focused on building technology and cyber platforms in services and cyber education and a Director of NCG (National Cyber Group), as well as Occamsec, Nsion and Platform Aerospace. Philip also acts as an advisor to and sits on multiple boards and advises organizations like the: Gula Tech Foundation, Squadra Ventures, Army Cyber Institute, Industry Round Table of the Federal Reserve Bank of Richmond, Univ. of Balt. Merrick School of Business, DEA Educ. Foundation, Royal Conservatoire of Scotland and Historic Ships of Balt. Previously he advised the Eisenhower Memorial Presidential Comm. and National Law Enforcement Officers Museum.
Philip was a Man. Dir. for over a decade at Whiteford, Taylor & Preston and was the Founder & Managing Partner of The Bridge Alliance, a shared collaborative management platform driving opportunities and cooperation between members. He has worked in almost every State, and in over 40 countries, and managed several significant global programs as a Consultant for his clients like Cresset Capital, CohnReznick, The Cordish Company, ARINC, ServiceMaster, Coca-Cola, MasterCard, UPS and Citibank.
John Quigg
John is a senior staff member at the Johns Hopkins University Applied Physics Laboratory, supporting security initiatives in cloud, 5G, and cyber situational awareness. He previously served as futures lead for the Director of White House Information Technology, was awarded patents for applying high-performance computing techniques to cybersecurity, and investigated the 5G/edge computing security risks of smart cities and buildings. John has been technical director for the Department of Defense Joint Task Force for Global Network Operations, and helped establish the U.S. Cyber Command, eventually serving as its technical director. He also established the security practice at Spurrier Capital Partners, was a security consultant for private enterprises and the U.S. Defense Department, worked for Intel McAfee as a cyber strategist, and served in the U.S. Army for nearly 30 years. John holds a B.S. in Physics from the United States Military Academy at West Point, an M.S. in computer science from the Naval Postgraduate School, an M.A. in computer systems management from Webster University, and is a Ph.D. candidate in information security at George Mason University.
Chris Reid
A transformational and empathetic leader with senior executive experience in mid to long-term strategy development, organizational development and design, and unstructured problem solving. Chris has successfully led several multi-disciplinary enterprises in ambiguous and complex strategic environments.
Currently the Chief of Staff for Elastics US Public Sector. He previously served as a Strategic Advisor and Chief of Staff to senior leaders in the Department of Defense. Prior to that Chris led the J8 Directorate at US Cyber Command, and had various senior roles across the US Army and Special Operations Command.
Industries we work with
We’ve partnered with organizations across a wide range of sectors—each with its own unique challenges and regulatory demands.
Read on to see where we’ve made an impact—and how we can do the same for you.
Media
Media organizations depend on complex broadcast systems and high-value content, making them prime targets for ransomware, data breaches, and operational disruptions that can halt live broadcasts, expose unreleased material, and erode brand trust. Proactive security measures—far cheaper than crisis management—safeguard revenue streams, protect reputations, and keep broadcasts on the air.
Education
Education institutions hold vast amounts of sensitive student and financial records, making them prime targets for cyber threats that can erode trust, strain already tight budgets, and disrupt essential services. Schools and universities worldwide strengthen their defenses to protect critical data while remaining within budget constraints.
Industrial
Industrial organizations span critical infrastructure sectors, where cyberattacks can halt production, jeopardize safety, and disrupt entire supply chains. In this environment, threats aren’t just digital—kinetic impacts can cause physical harm and facility damage. Organizations across the sector fortify operational technology, secure supply chains, and ensure business continuity to mitigate these risks.
Technology
Tech innovators power our digital world with products ranging from web services to mobile apps and complex infrastructure. We secure every stage—from development to deployment—so solutions meet industry standards and remain resilient against evolving threats. Through rigorous testing, proactive threat intelligence, and continuous monitoring, organizations protect customer data, safeguard intellectual property, and maintain trust.
Energy
Public sector organizations provide essential services—from public safety and healthcare to infrastructure and citizen services. They often face complex challenges like outdated systems, constrained budgets, and strict regulations that complicate security efforts. By adopting robust defensive measures, these agencies protect citizen data, ensure operational continuity, and maintain trust in government services.
Healthcare / Pharma
Healthcare organizations manage critical patient data and deliver life-saving services, making them prime targets for sophisticated cyber threats. Breaches can undermine patient trust, disrupt care, and result in steep regulatory penalties. By rigorously protecting sensitive data and medical systems, healthcare providers maintain compliance, ensure patient safety, and safeguard operational continuity.