Take the stage at ThreatModCon 2025 DC! Call for Papers submissions are open.
close
November 7-8, 2025

Threat modeling journeys: from 0-1, from good to great.
Join us for two action-packed days of practitioner-led talks, peer discussions and networking.

Call for Papers open now!

This year’s theme is Threat Modeling Journeys.
We’re inviting stories of how you started, scaled, or sharpened your threat modeling practices.

Submission deadline: August 8, 2025

Why speak at ThreatModCon?
  • Share your voice in a global community
  • Engage with a passionate, practitioner-led audience
  • Get professional development support and speaker mentoring
  • Join a growing movement advancing threat modeling and secure-by-design practices 
What we’re looking for

As a practice-oriented conference, we welcome proposals that explore real-world experience, hands-on techniques, and community-proof across all maturity levels. 

  • 30-minute presentation
  • 70-minute interactive workshops
  • 70-minute threat modeling game session
  • New: 5-minute threat modeling story/mini case-study (for the un-keynote)*
  • New: Poster sessions **
*Threat modeling story/mini case-study (for the un-keynote) 

The Un-Keynote is back—a community-led session featuring five-minute flashbacks from real threat modeling journeys. Share a defining moment: how you got started, a tough lesson, a breakthrough, or what you’d do differently if starting today. These bite-sized stories highlight the human side of threat modeling and inspire others through honest, relatable experiences.

**Poster session

New this year, poster sessions offer a visual, conversational way to share your work. Great for early-stage ideas, research, or prototypes, this format lets you engage one-on-one with attendees and spark informal, thoughtful discussions.

Only a few tickets remain... Grab yours now!

Got you feeling inspired? Stoked your curiosity? Lit the threat modeling fire in your belly?!

Limited tickets are left so get yours now before they're gone (and they will go!).

Speakers

Gain invaluable insights from top industry experts, seasoned practitioners, and thought leaders in threat modeling across technology, security consulting, academia, and beyond. Explore cutting-edge trends, delve into real-world case studies, and discover how these experts have empowered organizations to advance their threat modeling capabilities.

Un-keynote speakers 

ThreatModCon’s iconic un-keynote is back. Four leading practitioners, four journeys, one shared passion for threat modeling.

John Taylor
Application Security and Design Leader, Deloitte
John Taylor, Senior Manager at Deloitte Global where he leads a high-impact, globe-spanning application security and design team dedicated to delivering security-ready applications without slowing the pace of business delivery. John has spoken at many industry events and webinars like TMCon2023.
Navneet Keshav
Sr. Threat Modeling Architect, Lenovo
Navneet Keshav is a Senior Threat Modeling Architect at Lenovo, specializing in secure-by-design and AI-assisted threat modeling. He leads Lenovo’s global threat modeling efforts, founded the Raleigh–Durham Threat Modeling Connect chapter, and holds a U.S. patent in technology.
Spandana Gorantla
Product Security Engineer, Adobe
Spandana Gorantla is a security engineer specializing in application and product security, currently focused on AI threat modeling. With a background spanning cloud and product security in fast-paced environments, she brings a practical and approachable lens to emerging security challenges.
Brook Shoenfield
CTO & Chief Security Architect, Resilient Software Security
Brook is the Author of Secrets Of A Cyber Security Architect (Auerbach, 2019) and Securing Systems: Applied Security Architecture and Threat Models (CRC Press, 2015), co-author of Building In Security At Agile Speed (Auerbach, 2021) and contributing author to Core Software Security (CRC Press, 2014). Brook is a passionate security architect with decades of technical leadership experience.
Speakers

Meet the industry experts speaking at this year’s event.

Nathan Pembe
Senior Application Security Consultant, NVISO

Senior AppSec Consultant at NVISO, Nathan helps teams across Europe embed security from design to delivery. He leads threat modeling workshops, secure design reviews, and lectures. Nathan turns AppSec into real-world impact and help fast-paced teams make threat modeling stick for good with no bullsh*t.

Dan Rochon
Author, Speaker, Behavior Specialist, Teach To Sell

Dan has been quoted in CNBC, The Washington Post, WTOP News, The Today Show, and more. His accomplishments include being voted Best Real Estate Agent in DC by the Washington City Paper Readers Poll and being featured on The Nightly News with Brian Williams.

Dustin Lehr
AppSec Advocate, Security Journey & Co-founder, Katilyst

Dustin Lehr is the Application Security Advocate at Security Journey, Co-founder of Katilyst, and an accomplished software engineer and cybersecurity leader. He helps organizations build developer-centric programs that motivate and engage developers by leveraging behavioral science techniques.

Damian McGrath
Sr. Principal Cybersecurity Engineer, Workday

Damian is obsessed with scaling security across agile development teams. He was a founding member of Workday’s product security champions program and, weirdly, seems to be happiest when helping teams to threat model their systems. Damian is a Sr. Principal Cybersecurity Engineer at Workday.

Taraka Vishnumolakala
Sr. Cybersecurity Engineer, Workday

Taraka is a software engineer turned cybersecurity professional. His development background helps him identify software vulnerabilities and create practical security solutions. He specializes in secure SDLC design, automating code reviews, and leveraging AI to solve complex security challenges.

Areeb Khawaja
Technology Specialist, TELUS

Areeb Khawaja is an engineer passionate about design thinking and emerging technologies, transforming ideas into impactful prototypes. With a background in Electrical Engineering and an MEng in Engineering Design, he blends human-centered design with technology to craft innovative solutions.

Vikramaditya Narayan
AI Engineer, Ascendus AI

Vikramaditya holds a Master’s from Carnegie Mellon and is an Azure-certified AI Engineer. He built the prototype for an AI governance system that secured YC funding. Vikramaditya is now leading work on multi-agent threat modeling, using LLM-driven pre-mortems across layered agentic architectures to uncover emergent risks.

Marisa Fagan
Head of Product, Katilyst

Marisa Fagan is Head of Product at Katilyst, a "security champions as a service" startup that's revolutionizing how organizations scale their security culture initiatives. She's dedicated her career to building security into the SDLC and empowering developers to own secure code. She lives in SF, CA.

Anthony Lombardo
VP of Marketing, ThreatModeler

Tony Lombardo is the marketing leader at ThreatModeler, where he brings a deep technical foundation and a growth-focused mindset to advancing the threat modeling. Tony has a background in Computer Science and brings a unique voice to the threat modeling space—one that speaks both code and customer.

Amir Kavousian
Founder & CEO, DevArmor

Amir Kavousian is a two-time cybersecurity founder and the CEO of DevArmor, an AI-native platform reinventing threat modeling and security design reviews for the AI era. He also led engineering teams at Capital One and holds a PhD in Engineering from Stanford.

Ian Justiniani
Sr. Product Security Engineer, Navy Federal Credit Union

Ian Justiniani has been in the Cybersecurity field for 9 years starting in utilities and now in the financial space specializing in app sec and threat modeling. He lives in Southern California with his wife and. two young boys. In his spare time he is out golfing and playing basketball.

Dave Soldera
Security Architect, Electronic Arts

Dave is a veteran of the security industry, working across a range of industries and performing a range of security functions. An engineer and developer at heart, his focus has been more toward all aspects of application security, from finding vulnerabilities to designing and architecting solutions

Sebastien Deleersnyder
CTO, Toreon

Sebastien Deleersnyder, CTO Toreon, has a deep cybersecurity background. He has trained many developers in secure coding practices, started OWASP Belgium, contributed significantly to projects like SAMM. Now, he's focusing on integrating AppSec into DevOps and expanding the reach of threat modeling.

Topics you could cover...

Frameworks, Tools & Technical Practices
Frameworks, methods, and tools (including open source)
Integration with DevSecOps and Agile development
Metrics and risk prioritization – measuring value, impact, and maturity
Security design patterns and standards
Implementation & Organizational Scale
Case studies and implementation lessons
Scaling threat modeling in teams and organizations
Threat modeling culture and team dynamics
Educational strategies and training programs
Innovation & Emerging Domains
Threat modeling in emerging areas (AI, machine learning, hardware, etc.)
Privacy, data protection, and regulatory alignment
Academic or industry research in threat modeling
Wild Cards & New Ideas
Got your own idea? Go for it!

First-time conference speakers? We’ve got you!

All accepted speakers will be paired with a mentor through our well-received Speaker Mentorship Program. Mentors are experienced threat modeling professionals and seasoned speakers who will support you with feedback, preparation tips, and coaching to help you succeed.

Meet our 2025 sponsors

Diamond
Gold
Silver

Interested in being a sponsor?

Connect with potential clients and build your community at the world’s only conference dedicated to threat modeling and secure by design.

Ready to journey together?

Connect with fellow practitioners who share your passion for threat modeling. Hear their stories, share your own, and grow together on your threat modeling journey.