Alex Fry
Founder & Principal Security Engineer
Alex Fry is a security engineer and the founder of Privilege Security, a private cybersecurity practice for high-net-worth individuals and their families.
Before cybersecurity, Alex trained as a marine engineer at the United States Merchant Marine Academy — Kings Point, New York — earning his Chief Engineer's license for ocean-going vessels. That foundation in complex, high-stakes systems engineering shaped the discipline he brought into security. His path into the field ran through classified defense contracting: at Northrop Grumman Mission Systems, he led application security for the Defense Travel System, a program operating in an environment where the stakes are national and findings carry consequences. He has led Strong Crypto Innovations as president and principal security consultant since 2006, with security engagements spanning the Department of Defense, the Department of Homeland Security, the Department of the Army, the Internal Revenue Service, the Department of Commerce and the Department of Housing and Urban Development.
He is the co-author, with Ronald L. Krutz, of The CSSLP Prep Guide (Wiley) — the first published preparation guide for the (ISC)² Certified Secure Software Lifecycle Professional credential. He has contributed to the OWASP CISO Survey Project and OWASP Top 10 Privacy Risks Project, developed the OWASP NodeGoat SSRF Tutorial and WebGoat8 SSRF Lesson, and authored SANS research on runtime application self-protection and Android application security. He also served as Vice President of Technology Security at Elsevier, where he led global software security and security engineering across the publisher's R&D operations.
Privilege Security exists because of an asymmetry Alex saw repeatedly: institutions with far less at stake than a wealthy family are protected by entire departments, while the family itself — its accounts, devices, homes and people — is protected by habit and luck. The practice applies institutional security discipline to private life: every engagement is personally led by Alex, on a retained basis, quietly and without requiring the client to become a technologist.
Public Record
A career in environments where results cannot be published leaves few public traces by design. The verifiable record that exists: co-authorship of a Wiley certification text, published SANS research, active contributions to OWASP's practitioner standards, and a 2016 Washington Examiner feature on national cybersecurity strategy.
Credentials & Certifications
Alex is the co-author, with Ronald L. Krutz, of The CSSLP Prep Guide: Mastering the Certified Secure Software Lifecycle Professional (Wiley) — the first published preparation guide for (ISC)²’s secure-software-lifecycle certification.
He is a graduate of the United States Merchant Marine Academy, a contributor to OWASP and a longtime participant in the software-assurance community.
Certifications documented across his published work and press coverage include:
- (ISC)² — CISSP, CSSLP, ISSAP, ISSEP
- SANS GIAC — GSE (GIAC Security Expert), GPEN, GWAPT, GMOB, GCIA, GCIH, GSEC, GSSP-Java, GCPM
- EC-Council — LPT (Licensed Penetration Tester), ECSA, CEH
- IAPP — CIPP/E, CIPP/US, CIPT
- Infrastructure — Red Hat RHCE, Cisco CCNA, Microsoft MCP
Press
The Washington Examiner interviewed Alex at length on national cybersecurity strategy, government security talent and the threat landscape: “4 ways the government can improve its tech talent” (2016).
Media inquiries welcome. Contact the practice.
When you’re ready, the conversation is confidential.
Request a Confidential Consultation