ThreatLayer
Company

Built by practitioners. Delivered as a program.

ThreatLayer was built by operators who have spent decades inside real enterprise environments. We created the program we wished existed when we were accountable for security outcomes.

Our operating principles
  • Human accountability over unchecked automation
  • Clear risk narrative for leadership and operators
  • Evidence, context, and measurable improvement over time
  • Tenant isolation and strict access controls by design

Our story

Across hundreds of security assessments, we kept seeing the same pattern: findings trapped in PDFs, remediation losing momentum, and each new engagement starting from scratch.

We lived these problems as operators. We worked around them manually. Eventually, we decided to solve them properly.

ThreatLayer brings expert-led assessment, continuous visibility, and institutional memory together in a single program — so security teams can measure progress, not just generate reports.

Our mission

To transform security assessment from a point-in-time checkbox into a continuous program that measurably reduces risk.

What we believe

Human judgment matters

Automation is powerful, but expert judgment is irreplaceable. We design systems that amplify human capability.

Context is everything

A vulnerability without context is just noise. We preserve history so findings lead to action.

Security is a journey

There is no “done” state. We track trends, measure progress, and support continuous improvement.

Clarity over complexity

Security is complicated enough. We communicate clearly and report honestly.

Leadership

ThreatLayer is led by experienced cybersecurity operators and executives focused on accountable execution and measurable risk reduction.

Rick Carbonaro headshot

Rick Carbonaro

Co-Founder

Cybersecurity and IT leader with nearly 30 years of experience building compliant, scalable security programs from SMB to Fortune 500.

Chris Alexander headshot

Chris Alexander

Co-Founder

Cybersecurity executive with 30+ years in IT and 20+ years in information security, leading penetration testing, incident response, and security engineering.

Kelly Fischer headshot

Kelly Fischer

Senior Executive

Kelly Fisher is a distinguished cybersecurity leader with over 33 years of experience spanning military service, government, and the private sector.

Advisors

ThreatLayer is guided by senior practitioners and executives across identity, cloud, incident response, governance, and enterprise security operations.

Michael Harrington headshot

Michael Harrington

Former Enterprise CISO

Enterprise security leader advising on executive risk translation and board reporting across regulated industries.

Laura Chen headshot

Laura Chen

Cloud & Identity Security Advisor

Advises on identity-first security architectures and cloud governance across modern AWS/Azure environments.

Daniel Wright headshot

Daniel Wright

Incident Response Advisor

Advises on readiness, ransomware response, and executive-level crisis coordination for high-pressure incidents.

Stephanie Morales headshot

Stephanie Morales

Governance & Compliance Advisor

Specializes in NIST/ISO/SOC 2 alignment and audit readiness for executive and regulatory expectations.

Robert Klein headshot

Robert Klein

Private Equity & M&A Security Advisor

Advises on security due diligence and post-acquisition risk reduction for portfolio companies.

Aisha Patel headshot

Aisha Patel

Application Security Advisor

Advises on secure SDLC, API security, and engineering enablement for modern product teams.

Thomas Becker headshot

Thomas Becker

OT & Manufacturing Security Advisor

Advises on OT/IT convergence and securing industrial and production environments.

Jonathan Reed headshot

Jonathan Reed

Threat Intelligence Advisor

Advises on adversary behavior modeling, attack path analysis, and defensive validation.

Emily Navarro headshot

Emily Navarro

Legal & Cyber Risk Advisor

Advises on governance, risk communication, and incident decision support for leadership teams.

Mark Sullivan headshot

Mark Sullivan

Security Program Architecture Advisor

Designs scalable security programs balancing technology, process, and human accountability.

*Advisors provide strategic guidance to ThreatLayer and do not participate in day-to-day operations or client engagements.*

Join the team building the future of security programs.

ThreatLayer is built by operators who care about clarity, accountability, and real-world impact. If you’ve lived the problems we’re solving, we want to hear from you.