Team
Six practitioners. You will meet the ones who do the work.
Defenseum is deliberately small. Everybody here has spent years on the inside of a security team as well as consulting into one, which is why our findings arrive with an idea of how they get fixed.
- Team size
- Six senior practitioners, and we grow only when we can do so without lowering the bar.
- Staffing
- The people who scope your engagement are the people who run it.
- Backgrounds
- Platform engineering, managed detection, red team, payments and audit.
Who you work with
The people on the other end of the engagement
Each of them leads on their own discipline and reviews the work of the others. Nothing leaves here without a second pair of eyes on it.
Marisol Okonjo
Founder and Principal Security Consultant
Application security and payment systems
Marisol started Defenseum after a decade split between offensive consulting and running security inside a payments company, where she learned how differently a finding lands when you are the person who has to fix it. She leads scoping on every engagement and still tests personally, mostly against authorisation logic and payment flows, which she considers the two places where clever architecture most often goes quietly wrong. She is also the one clients bring to the call when a report has to be defended in front of an enterprise procurement team.
Skills
- Application security
- Payment systems
- Threat modelling
- Security leadership
Ilias Vantomme
Principal Penetration Tester
Networks, identity and exploit chaining
Ilias has spent eleven years attacking networks for a living, first inside the red team of a national telecoms operator and since then as a consultant. He specialises in the unglamorous half of the job: chaining three findings that were individually rated low into one that ends the argument about whether the risk is real. He maintains the internal tooling Defenseum uses for reconnaissance and reporting, and he writes reproduction steps precise enough that clients have fixed findings before the walkthrough call happens.
Skills
- Network penetration testing
- Active Directory
- Exploit chaining
- Red team operations
Priya Raghunathan
Cloud Security Architect
Cloud architecture, identity and segmentation
Priya designs the version of your infrastructure you wish you had built the first time. She came to security from platform engineering, which is why her recommendations tend to arrive as pull requests and reusable modules rather than a slide asking somebody else to do the work. She has rebuilt identity and segmentation for companies halfway through a cloud migration, and she is unusually good at finding the single over-permissioned role that quietly undoes an otherwise sound design.
Skills
- AWS and Google Cloud
- Identity and access management
- Infrastructure as code
- Network segmentation
Daniel Freije
Incident Response Lead
Detection, forensics and readiness
Daniel spent six years on a managed detection team, which means he has been on the phone at three in the morning often enough to know exactly which parts of an incident plan get abandoned under pressure. He builds runbooks a tired engineer can follow, facilitates the tabletop exercises, and reviews logging with one question in mind: if this happened tonight, could you reconstruct it tomorrow. He also handles live response work for retained clients, which keeps the plans he writes honest.
Skills
- Digital forensics
- Detection engineering
- Tabletop facilitation
- Log pipeline design
Noor Haddadi
Security Consultant, Governance and Risk
Frameworks, audits and enterprise review
Noor translates between engineering teams and the auditors, regulators and enterprise buyers asking them questions. She has taken companies through SOC 2 Type II and ISO 27001 from a standing start, and she is candid about which controls genuinely reduce risk and which exist to satisfy a form. Her risk registers get read rather than filed, largely because she refuses to write a line that nobody is going to act on.
Skills
- SOC 2 and ISO 27001
- Risk assessment
- Third-party review
- Policy people follow
Tomas Erlend
Senior Application Security Engineer
Code review, APIs and pipeline controls
Tomas reviews code and architecture for teams shipping faster than the security process they inherited was designed for. He works inside the pipeline, adding the checks that catch a whole class of bug once instead of the same bug repeatedly, and he pairs with developers rather than filing tickets at them. He spent seven years as a backend engineer before moving into consulting, which is why his findings usually arrive with a working patch attached.
Skills
- Secure code review
- API security
- CI and CD controls
- Developer enablement
Portrait treatment
Every portrait is made the same way: a matte navy backdrop, one soft key light from the left, and a duotone print in navy and ice with the house hex mesh laid over the shoulder line. The team reads as one set rather than six different photographers, which is the point.
How engagements are staffed
No handover after signature
Engagements are staffed by the people you meet during scoping. Nothing is subcontracted, nothing is passed to a junior once the contract is signed, and if the named lead changes for any reason we tell you before the work moves.
Next step
Talk to the person who would run your engagement
Scoping calls are taken by the practitioner who would lead the work, not by a salesperson. Tell us the situation and we will tell you what it needs.