Skip to content

Team

Six practitioners. You will meet the ones who do the work.

Defenseum is deliberately small. Everybody here has spent years on the inside of a security team as well as consulting into one, which is why our findings arrive with an idea of how they get fixed.

Team size
Six senior practitioners, and we grow only when we can do so without lowering the bar.
Staffing
The people who scope your engagement are the people who run it.
Backgrounds
Platform engineering, managed detection, red team, payments and audit.

Who you work with

The people on the other end of the engagement

Each of them leads on their own discipline and reviews the work of the others. Nothing leaves here without a second pair of eyes on it.

  • Marisol Okonjo

    Founder and Principal Security Consultant

    Application security and payment systems

    Marisol started Defenseum after a decade split between offensive consulting and running security inside a payments company, where she learned how differently a finding lands when you are the person who has to fix it. She leads scoping on every engagement and still tests personally, mostly against authorisation logic and payment flows, which she considers the two places where clever architecture most often goes quietly wrong. She is also the one clients bring to the call when a report has to be defended in front of an enterprise procurement team.

    Skills

    • Application security
    • Payment systems
    • Threat modelling
    • Security leadership
  • Ilias Vantomme

    Principal Penetration Tester

    Networks, identity and exploit chaining

    Ilias has spent eleven years attacking networks for a living, first inside the red team of a national telecoms operator and since then as a consultant. He specialises in the unglamorous half of the job: chaining three findings that were individually rated low into one that ends the argument about whether the risk is real. He maintains the internal tooling Defenseum uses for reconnaissance and reporting, and he writes reproduction steps precise enough that clients have fixed findings before the walkthrough call happens.

    Skills

    • Network penetration testing
    • Active Directory
    • Exploit chaining
    • Red team operations
  • Priya Raghunathan

    Cloud Security Architect

    Cloud architecture, identity and segmentation

    Priya designs the version of your infrastructure you wish you had built the first time. She came to security from platform engineering, which is why her recommendations tend to arrive as pull requests and reusable modules rather than a slide asking somebody else to do the work. She has rebuilt identity and segmentation for companies halfway through a cloud migration, and she is unusually good at finding the single over-permissioned role that quietly undoes an otherwise sound design.

    Skills

    • AWS and Google Cloud
    • Identity and access management
    • Infrastructure as code
    • Network segmentation
  • Daniel Freije

    Incident Response Lead

    Detection, forensics and readiness

    Daniel spent six years on a managed detection team, which means he has been on the phone at three in the morning often enough to know exactly which parts of an incident plan get abandoned under pressure. He builds runbooks a tired engineer can follow, facilitates the tabletop exercises, and reviews logging with one question in mind: if this happened tonight, could you reconstruct it tomorrow. He also handles live response work for retained clients, which keeps the plans he writes honest.

    Skills

    • Digital forensics
    • Detection engineering
    • Tabletop facilitation
    • Log pipeline design
  • Noor Haddadi

    Security Consultant, Governance and Risk

    Frameworks, audits and enterprise review

    Noor translates between engineering teams and the auditors, regulators and enterprise buyers asking them questions. She has taken companies through SOC 2 Type II and ISO 27001 from a standing start, and she is candid about which controls genuinely reduce risk and which exist to satisfy a form. Her risk registers get read rather than filed, largely because she refuses to write a line that nobody is going to act on.

    Skills

    • SOC 2 and ISO 27001
    • Risk assessment
    • Third-party review
    • Policy people follow
  • Tomas Erlend

    Senior Application Security Engineer

    Code review, APIs and pipeline controls

    Tomas reviews code and architecture for teams shipping faster than the security process they inherited was designed for. He works inside the pipeline, adding the checks that catch a whole class of bug once instead of the same bug repeatedly, and he pairs with developers rather than filing tickets at them. He spent seven years as a backend engineer before moving into consulting, which is why his findings usually arrive with a working patch attached.

    Skills

    • Secure code review
    • API security
    • CI and CD controls
    • Developer enablement

Portrait treatment

Every portrait is made the same way: a matte navy backdrop, one soft key light from the left, and a duotone print in navy and ice with the house hex mesh laid over the shoulder line. The team reads as one set rather than six different photographers, which is the point.

How engagements are staffed

No handover after signature

Engagements are staffed by the people you meet during scoping. Nothing is subcontracted, nothing is passed to a junior once the contract is signed, and if the named lead changes for any reason we tell you before the work moves.

Next step

Talk to the person who would run your engagement

Scoping calls are taken by the practitioner who would lead the work, not by a salesperson. Tell us the situation and we will tell you what it needs.