Workshop AllThreats Security Leadership
⇄ Switch to ZedTrust | ← Hub
Home
My Network
Jobs
Messaging
MK
Marcus Kwame
CEO
PN
Dr. Priya Nair
COO
TM
Tariq Mahmood
VP, Pro Services
AO
Adriana Orellana
Senior TA Partner
DC
Devon Choi
Sr. Threat Intel Analyst
RO
Renata Osei
SOC Manager
MK
Marcus Kwame
CEO & Co-Founder, AllThreats Security | Former CISO | Incident Responder | Building a firm where practitioners lead everything
📍 Washington, DC Metro AllThreats Security Georgetown University (Advisory Board) 500+ connections
Connect
Message
523 connections · 4,800 followers

About

I started AllThreats in 2009 because I was tired of watching organizations spend millions on security products they couldn't operate, sold to them by vendors who had never responded to a real breach.

After 22 years in this industry — starting as a network admin, then IR analyst, then CISO at a major healthcare network after leading the response to a 4.2 million patient breach — I knew the only way to build something different was to start it from scratch.

What I'm most proud of isn't the company's growth or the clients we've landed. It's the careers we've built. 72% of our senior roles are filled internally. Analysts who joined us fresh out of school are now leading practices. People who felt burned out and undervalued at other firms have found something different here.

I try to be the leader I wish I'd had earlier in my career — honest about what's hard, clear about direction, and genuinely invested in the people doing the work.

If you're a practitioner who wants to do real work in a place that takes care of you — let's talk.

Experience

CEO & Co-Founder Current

AllThreats Security
Jan 2009 – Present · 15 years 11 months

Founded AllThreats with a team of 6 practitioners. Scaled to 1,200+ employees across 4 offices. Built the ThreatMap platform, launched the AT Rising early career program, and established the practitioner-first operating model. Directly accountable to employees, clients, and our PE partners at Ironbridge Capital.

Chief Information Security Officer

Meridian Health System
Mar 2004 – Dec 2008 · 4 years 10 months

Rebuilt the security program following a major breach affecting 4.2M patient records. Implemented zero-trust architecture, established a 24/7 SOC, and led the regulatory response with HHS OCR. Experience with breach response at scale directly shaped AllThreats' IR methodology.

Senior Incident Responder

SecureCore Consulting
Jun 1999 – Feb 2004 · 4 years 9 months

Handled incident response for Fortune 500 clients. Specialized in financial sector breaches and nation-state attributed intrusions. Led a team of 8 analysts.

Skills

Incident Response· 94
Threat Intelligence· 87
Executive Leadership· 112
CISO Advisory· 76
Servant Leadership· 68
Organizational Culture· 54
Digital Forensics· 43

Recommendations

TM
Tariq Mahmood
VP, Professional Services at AllThreats · Reports to Marcus
"Marcus is the rarest thing in this industry — a leader who has been in the work, stays close to the work, and makes every decision through the lens of 'what does this mean for the people doing the work?' I've worked for a lot of leaders in 20 years. None of them have matched what he's built here."
DC
Devon Choi
Senior Threat Intel Analyst at AllThreats · Former direct report
"When I was a junior analyst, Marcus reached out to me personally after reading a threat report I'd written. Not to correct it — to tell me it was excellent and ask what I needed to grow. That email shaped how I think about leadership. I've been here 6 years and I'm still learning from him."

Recent Activity

Marcus posted: "Just wrapped our annual all-hands. Shared our financial performance (strong), our headcount targets for 2025 (we're hiring), and — most importantly — the results of our first pay equity audit. We found 14 disparities. We corrected all 14 before the meeting. I'll post the full audit summary later this week."
Marcus shared: An article on the CISO burnout crisis, adding: "The CISO burnout problem is a leadership failure, not an individual resilience failure. If your security leaders are burning out, look at what you're asking them to carry — and whether you've given them the resources, the authority, and the air cover to do the job."
Marcus commented on a post about layoffs in the cybersecurity sector: "This industry's staffing model is broken. We don't practice 'workforce optimization' at AllThreats. We make long-term bets on people. Every time the market softens and others reduce headcount, we're picking up outstanding talent and investing in it."
PN
Dr. Priya Nair, PhD
COO, AllThreats Security | Building sustainable PS practices | Promoted from within | Transparency advocate | Carnegie Mellon CS PhD
📍 Pittsburgh, PAAllThreats Security500+ connections
Connect
Message
491 connections · 3,200 followers

About

I joined AllThreats 11 years ago as their first hire with a formal operations background. At the time, we had 40 people and were figuring out how to scale without losing what made us different.

I built our Professional Services practice from a 3-person team to what is now 400+ consultants across 4 offices — and my proudest moment wasn't any single client engagement. It was when our first cohort of junior consultants grew into senior leaders.

I care deeply about pay equity and compensation transparency. I championed our open salary bands initiative and the annual third-party pay equity audit. Uncomfortable conversations about fairness are not optional — they're leadership work.

Women in cybersecurity: my DMs are always open. I've mentored 30+ people through career transitions in this field and I have strong opinions about which firms are worth your time and which ones aren't.

Experience

Chief Operating Officer Current

AllThreats Security
Mar 2021 – Present · 3 years 8 months · Promoted from VP, Professional Services

Responsible for all operational functions including PS delivery, people operations, finance, and legal. Executive sponsor of pay equity audit initiative and internal mobility program.

VP, Professional Services

AllThreats Security
Jun 2016 – Mar 2021 · 4 years 9 months · Promoted from Director, PS Operations

Scaled the consulting practice 10x. Implemented delivery quality frameworks, analyst development curriculum, and the utilization model that prioritizes analyst wellbeing over billable hour maximization.

Director, PS Operations → Senior Consultant

AllThreats Security
Jan 2014 – Jun 2016 · 2 years 6 months

Skills

Operations Leadership· 88
Consulting Practice Management· 72
Compensation & Equity· 61
Organizational Design· 55
D&I Strategy· 48
TM
Tariq Mahmood
VP, Professional Services @ AllThreats Security | Incident Response | DFIR | Building practitioners who go on to lead | 8 years AT | Promoted from Director IR
📍 Chicago, ILAllThreats Security500+ connections
Connect
Message
412 connections · 2,800 followers

About

I spent my first decade in this industry at Big 4 consulting firms and hated every day of it after year 3. Brilliant colleagues, constantly being overworked, underinvested in, and shuffled between accounts like billing resources.

I joined AllThreats 8 years ago as a Director of Incident Response because a colleague told me it was different. She was right.

I now run a 300-person consulting practice and I spend most of my time thinking about one question: what does this analyst need to become the best version of themselves? I try to have that conversation with every person on my team at least quarterly.

A few things I'm proud of: the AllThreats IR methodology (I wrote the first version in 2017 and we've updated it 9 times since). The mentorship program that came out of conversations I started with Sofia (CPO). The fact that 6 of the 8 people who reported to me directly when I was a Director are now Directors or above themselves.

Open to conversations from practitioners thinking about their next move. Be honest with me and I'll be honest with you about whether AllThreats is a fit.

Experience

VP, Professional Services Current

AllThreats Security
Sep 2020 – Present · 4 years 2 months · Promoted from Director, Incident Response

Lead AllThreats' full consulting and IR practice. Responsible for delivery quality, analyst development, utilization strategy, and client relationships across 600+ active engagements per year.

Director, Incident Response

AllThreats Security
Feb 2017 – Sep 2020 · 3 years 7 months

Senior Manager, Cybersecurity Incident Response

PricewaterhouseCoopers
Aug 2010 – Jan 2017 · 6 years 6 months

Led incident response and forensic investigation practice. Worked on some of the largest retail and financial sector breaches of the 2010s. Excellent technical work, increasingly difficult organizational environment — the comparison to AllThreats has been stark.

Recent Activity

Tariq posted: "We just promoted 4 people from Senior Analyst to Lead within our IR practice. Every single one of them started at AllThreats as an entry-level hire. This is what 'growth culture' actually looks like. Not a slide in a recruiting deck — a list of names."
Tariq commented on a burnout thread: "The utilization models most consulting firms use are designed to extract maximum billable hours. We explicitly built ours to prevent that. When we see an analyst consistently over 80% utilization, that's a problem I need to fix — not a metric to celebrate."
AO
Adriana Orellana
Senior Talent Acquisition Partner @ AllThreats Security | Cybersecurity Recruiting | 5 yrs AllThreats | Hiring for roles I'd take myself | LGBTQ+ advocate
📍 Austin, TXAllThreats Security500+ connections
Connect
Message
387 connections · 1,900 followers

About

I've been a cybersecurity recruiter for 9 years and I've worked at places that treated recruiting as a numbers game and places — like AllThreats — that treat it as an integrity function.

The difference is night and day. At my previous employer, I was incentivized to fill seats. At AllThreats, I'm incentivized to make matches that last and that don't result in a candidate accepting a role that isn't what I described.

I will always tell you the truth about what a role is and what it isn't. If I think you'd be a better fit at a different company, I will tell you. If AllThreats isn't ready for what you need, I'd rather lose a hire than mislead someone into a situation they'll regret.

Currently hiring for threat intelligence, incident response, and MDR roles. If you're a security professional curious about AllThreats — even just exploratory — reach out. I'm happy to have an honest conversation about whether it could be a fit.

Experience

Senior Talent Acquisition Partner Current

AllThreats Security
Mar 2020 – Present · 4 years 8 months · Promoted from TA Partner after 18 months

Own full-cycle recruiting for threat intelligence, MDR, and incident response practices. Focus on diverse candidate sourcing, structured interview design, and candidate experience. Average time-to-fill: 22 days. Offer acceptance rate: 91%.

Technical Recruiter

Resolve Recruiting (Agency)
Jun 2016 – Feb 2020 · 3 years 9 months

Cybersecurity-focused agency recruiting. High-volume, metric-driven environment. Learned a tremendous amount about the industry and what candidates are actually looking for. Left to find somewhere I could recruit with more integrity and less pressure to hit placement numbers at any cost.

Recent Activity

Adriana posted: "Green flag I noticed internally this week: a hiring manager came to me and said they didn't think we should move forward with a candidate because the role had changed since posting — and they wanted to update the JD before proceeding rather than 'see if the candidate will adapt.' That's the right call. That's also why our offer acceptance rate is 91%."
Adriana posted: "Reminder that our technical assessments at AllThreats are compensated at $75/hour regardless of hiring outcome. We don't take free work from candidates. If this is standard in other companies, it should be standard everywhere."
DC
Devon Choi
Senior Threat Intelligence Analyst @ AllThreats Security | APT research | Malware RE | 6 years at AT (promoted 2x) | SANS FOR610 · GREM | Neurodivergent advocate
📍 Remote (Pacific)AllThreats Security500+ connections
Connect
Message
298 connections · 1,400 followers

About

I'm a threat intelligence analyst specializing in APT attribution and malware reverse engineering. I've been at AllThreats for 6 years — started as a junior analyst straight out of my BSCS program and have been promoted twice.

This is the first place in my career where being neurodivergent hasn't been a liability. AllThreats' AT Minds ERG was one of the first things that made me feel like I belonged here — and the accommodations I've received (flexible schedule, quiet space policies, async-first communication norms) have made me a significantly better analyst.

I've published 8 external threat intelligence reports and presented twice at SANS CTI Summit. None of that would have happened without the time and support AllThreats invested in my development — including fully funding my GREM, my GCTI, and two conference trips.

If you're a junior analyst who is neurodivergent and wondering whether this industry has space for you: yes, and AllThreats specifically is a good place to ask that question.

Experience

Senior Threat Intelligence Analyst Current

AllThreats Security
Jan 2022 – Present · 2 years 10 months · Promoted from TI Analyst II

Lead analyst for APAC-attributed nation-state threat actors. Primary author of AllThreats' quarterly Dragon Sector (PRC-nexus) threat landscape report. Specialties: malware reverse engineering, C2 infrastructure tracking, attribution methodology.

Threat Intelligence Analyst → Analyst II

AllThreats Security
Sep 2018 – Jan 2022 · 3 years 4 months

Certifications

GREM (GIAC Reverse Engineering Malware)
GCTI (GIAC Cyber Threat Intelligence)
GCFE (GIAC Computer Forensics Examiner)
CompTIA Security+
RO
Renata Osei
SOC Manager — Managed Detection @ AllThreats Security | 7 years AT | Promoted from analyst | BLKST ERG Co-Lead | Detection Engineering | CISSP · GCIA
📍 Chicago, ILAllThreats Security500+ connections
Connect
Message
341 connections · 1,600 followers

About

7 years at AllThreats. Started as a SOC Analyst I. Now I manage a team of 18 analysts across two shifts and am co-lead of BLKST, our Black employee ERG.

My career path here has not been linear, and that's been a feature, not a bug. I moved from SOC to detection engineering and back to SOC management because AllThreats actually encourages that. The internal mobility program isn't a checkbox — it's the reason my career looks the way it does.

I'm most passionate about analyst development and preventing burnout. I've watched the staffing model at too many SOCs crush talented people. We don't run that model here. When one of my analysts is struggling, that's a management problem, not a performance problem, until I've exhausted every resource I have to understand why.

Proud HBCU grad (Howard University, B.S. Computer Science). Proud Chicagoan. Proud of what I've built here.

Experience

SOC Manager, Managed Detection Current

AllThreats Security
Jun 2021 – Present · 3 years 5 months · Promoted from Sr. Detection Engineer

Manage 18-analyst SOC team supporting AllThreats' MDR client base. Responsible for shift scheduling, analyst development plans, detection rule quality, and client escalation handling. Run weekly team retrospectives and monthly mental health check-ins.

Senior Detection Engineer → SOC Manager

AllThreats Security
Nov 2018 – Jun 2021 · 2 years 7 months

SOC Analyst I → SOC Analyst II

AllThreats Security
Aug 2017 – Nov 2018 · 1 year 3 months

Recent Activity

Renata posted: "My team asked me last week what I would do differently if I were in their position. I told them: I would have asked for help sooner. The biggest thing AllThreats gave me was a manager who made asking for help feel safe. I try to be that manager every day."
Renata shared an article on SOC analyst mental health: "The turnover rate in SOC environments is a structural problem. Alert fatigue, 24/7 shift patterns, minimal development investment — we built our MDR model explicitly against all of these. Our analyst churn rate is 8% annually. Industry average is above 30%."