Jorge Esperón

Senior Security Architect
@
IriusRisk

Professional Expertise & Experience

Jorge Esperón is a Senior Security Architect at IriusRisk, bringing over 15 years of experience in the cybersecurity field. His current role is centered on researching and threat modeling evolving software architectures to define and validate effective security controls for the IriusRisk platform.

Jorge is highly specialized in integrating security into the development lifecycle, moving teams from a reactive to a proactive security posture. His expertise covers:

  • Threat Modeling Architectures: He writes on the automation of threat modeling for modern architectures, including workflows for AWS CloudFormation and the Microsoft Threat Modeling Tool (MTMT).
  • AI Security Frameworks: He contributes content on cutting-edge security concepts like the MAESTRO threat modeling framework, which addresses complex, layered threats unique to Agentic AI systems.
  • Application Security Design: In his previous role as Head of the Application Security Office at Inditex, he developed security processes within the SDLC, giving him deep, practical knowledge of how enterprises build and secure software at scale.

Notable Contributions & Credentials

Jorge is a respected voice in the application security community, known for his technical depth and ability to simplify complex flaws:

  • Certifications: He holds key certifications including Certified Ethical Hacker (CEH) and PCI ISA (Internal Security Assessor), validating his technical and compliance expertise.
  • Industry Speaker: He is a key presenter on IriusRisk webinars, joining the CEO and other leaders to discuss why threat modeling is essential for securing the future of AI systems.
  • Thought Leadership: He has published detailed technical articles that use real-world examples, such as the Log4j vulnerability, to illustrate how threat modeling can expose design flaws before they are exploited.
  • Education: His academic background includes a Master's degree (MSc) in Information Security and a Bachelor's degree (BSc) in Physics.

Blogs by

Jorge Esperón

Threat Modeling
AI & ML
MAESTRO: Streamlining Agentic AI Security in IriusRisk
September 24, 2025
Software security
Threat Modeling
IriusRisk Functional Components
October 25, 2023
Infrastructure as Code
Threat Modeling
Lucidchart threat modeling workflow
March 28, 2023
Software security
Threat Modeling
Threat modeling as a way of thinking about design flaws - Log4j case
February 8, 2023
Threat Modeling
Threat modeling workflow for Microsoft Threat Modeling Tool
November 11, 2022
Infrastructure as Code
Software security
Threat Modeling
Microsoft Visio threat modeling workflow
November 11, 2022
Product Release
Threat Modeling
New Dataflow Library in IriusRisk v4.6
August 4, 2022
Cloud Security
Software security
Threat Modeling
Infrastructure as Code
Threat modeling workflow for AWS Cloudformation architectures using IriusRisk
June 16, 2022
Methodologies & Frameworks
Infrastructure as Code
Cloud Security
Threat modeling workflow for Terraform defined architectures using IriusRisk
June 16, 2022
Methodologies & Frameworks
Cloud Security
Threat Modeling Software Features vs Architecture
February 22, 2022
Software security
Threat Modeling
Security is a Journey
April 28, 2021
Standards, Compliance and Regulations
Threat Modeling
Build GDPR Compliance into Your Applications with IriusRisk
April 27, 2021