Fraser Scott

Chief Scientist
@
IriusRisk

Professional Expertise & Experience

Fraser Scott serves as the Chief Scientist (AI) at IriusRisk, where he is responsible for the strategic vision and practical implementation of artificial intelligence within the threat modeling platform. His work ensures that IriusRisk delivers cutting-edge, AI-augmented security solutions that meet the needs of modern, agile development teams.

Fraser is a highly experienced product manager and advocate for Threat Modeling as a pragmatic toolkit to navigate the complex relationship between software value and security risk. This perspective is built on his significant history in implementing security at scale, including his experience as the Senior Manager of Enterprise Threat Modeling at Capital One. His deep-seated knowledge spans:

  • DevOps and Cloud Security
  • Software Design and Development Lifecycle (SDLC) Security
  • AI and Machine Learning in Security

Skills and Contributions

Fraser is a prominent evangelist for the "shift-left" security movement and actively contributes to the wider cybersecurity community, cementing his reputation as an industry authority.

  • Open Source Creation: He is the creator of several experimental open-source projects, including ThreatSpec.
  • Community Leadership: He is a key contributor to the globally respected Threat Modeling Manifesto Group.
  • Thought Leadership: He has published on specialized topics, such as the critical need for Fintech companies to focus on software security in the face of rapid growth and increased cyber threats.
  • Leadership Role: Prior to his current position, Fraser held the role of VP, Product Development at IriusRisk, overseeing the platform's strategic development.

Blogs by

Fraser Scott

AI & ML
Threat Modeling
Why AI Won't Kill Developer Jobs (It'll Create More)
June 23, 2025
AI & ML
Zen and the Art of Vibe Coding
April 24, 2025
AI & ML
Adaptability and the New Era of Software Development
April 1, 2025
Product Release
AI & ML
Product Update: Release 4.21: Featuring Countermeasure Filtering & More Automation
October 16, 2023
Software security
Insecure Design Added As a New Category in the OWASP Top 10
November 3, 2022
Infrastructure as Code
Intro to Threat Modeling
Introduction to the Open Threat Model standard
February 22, 2022
Infrastructure as Code
How to create an OTM parser
February 22, 2022
News
IriusRisk announces appointment of new VP, Product Development – Fraser Scott
April 28, 2021