Jorge Orchilles

CEO

Fort Lauderdale, Florida, United States23 yrs 4 mos experience
Most Likely To SwitchHighly Stable

Key Highlights

  • Leader of Readiness and Proactive Security at Verizon
  • SANS Principal Instructor with multiple authored courses
  • Co-authored Common Vulnerability Scoring System (CVSS)
Stackforce AI infers this person is a Cybersecurity expert with extensive experience in vulnerability management and penetration testing.

Contact

Skills

Core Skills

Penetration TestingVulnerability ManagementTeaching

Other Skills

Exposure & Vulnerability ManagementEnterprise Penetration TestingEnterprise Red TeamDedicated Purple TeamThird Party Proactive Managed ServicesSEC565: Red Team Operations and Adversary EmulationSEC699: Purple Team TacticsSEC560: Enterprise Penetration TestingSEC504: Hacker Tools, Techniques, and Incident HandlingSEC660: Advanced Penetration TestingSEC524: Cloud Security FundamentalsSEC577: Virtualization Security FundamentalsSEC579: Virtualization and Private Cloud SecurityCISSPSecurity

About

Jorge Orchilles leads the Readiness and Proactive Security team at Verizon which includes Exposure & Vulnerability Management, Penetration Testing, Red Team, Purple Team, and the AI Red Team. Jorge is a SANS Principal Instructor, creator of the C2 Matrix project, author of the Purple Team Exercise Framework, and co-author of SANS SEC565: Red Team Operations and Adversary Emulation. He was a founding member of MITRE Engenuity Center of Threat-Informed Defense as well as an active contributor to MITRE ATT&CK and Atomic Red Team. He is a Fellow at the Information Systems Security Association (ISSA) and National Security Institute. Prior, Jorge was CTO at SCYTHE and led the offensive security team at Citi for over 10 years. ‍ Jorge Orchilles co-authored the Common Vulnerability Scoring System (CVSS) and A Framework for the Regulatory Use of Penetration Testing in the Financial Services Industry, and is the author of Microsoft Windows 7 Administrator’s Reference. Jorge holds post-graduate degrees from Stanford and Florida International University in Advanced Computer Security & Master of Science. Jorge speaks English, Spanish, and Portuguese, in decreasing levels of fluency. When he’s not hacking, teaching, or writing, you’ll find him watching and playing soccer. For more updates on Jorge, follow him on Twitter: @jorgeorchilles

Experience

Verizon

Senior Director

Feb 2023Present · 3 yrs 1 mo · Florida, United States · Remote

  • Lead Readiness and Proactive Security under CISO - Cyber Defense:
  • Exposure & Vulnerability Management
  • Enterprise Penetration Testing
  • Enterprise Red Team
  • Dedicated Purple Team
  • Third Party Proactive Managed Services
Exposure & Vulnerability ManagementEnterprise Penetration TestingEnterprise Red TeamDedicated Purple TeamThird Party Proactive Managed ServicesPenetration Testing+1

Scythe

Chief Technology Officer

Jun 2020Jan 2023 · 2 yrs 7 mos

  • Product evangelist

Citi

4 roles

Director

Jan 2019May 2020 · 1 yr 4 mos

Senior Vice President

Promoted

Jun 2014Dec 2018 · 4 yrs 6 mos

  • Provide leadership to the Advanced Penetration Testing and Vulnerability Assessment Quality Control teams.

Vice President - Infrastructure Vulnerability Assessment Manager

Promoted

Jan 2012Jun 2014 · 2 yrs 5 mos

  • Infrastructure Vulnerability Assessment
  • Provide leadership to highly talented and motivated group of security professionals who primarily work on penetration testing engagements, security architecture reviews, and vulnerability and threat management.

Technical Analyst

Jun 2010Jan 2012 · 1 yr 7 mos

  • Provide vulnerability assessment services to businesses globally through comprehensive testing process. Typical assignments involve testing of overall security of critical infrastructure components and applications to ensure they comply with internal policies, security architecture best practices, and industry standards.

Intralinks

Advisory Board Member

May 2015Jun 2017 · 2 yrs 1 mo

  • Acquired by Synchronoss for $821 million
  • Information Security Adviser

Sans institute

Principal Instructor, Author, and Ambassador

Aug 2010Present · 15 yrs 7 mos

  • Author of SEC565: Red Team Operations and Adversary Emulation
  • Instructor:
  • SEC699: Purple Team Tactics - Adversary Emulation for Breach Prevention & Detection
  • SEC565: Red Team Operations and Adversary Emulation
  • SEC560: Enterprise Penetration Testing
  • SEC504: Hacker Tools, Techniques, and Incident Handling
  • SEC660: Advanced Penetration Testing, Exploit Writing, and Ethical Hacking
  • SEC524: Cloud Security Fundamentals
  • SEC577: Virtualization Security Fundamentals
  • SEC579: Virtualization and Private Cloud Security
SEC565: Red Team Operations and Adversary EmulationSEC699: Purple Team TacticsSEC560: Enterprise Penetration TestingSEC504: Hacker Tools, Techniques, and Incident HandlingSEC660: Advanced Penetration TestingSEC524: Cloud Security Fundamentals+4

South florida issa

Member of Board of Directors

Jan 2010Dec 2021 · 11 yrs 11 mos

  • ISSA Fellow. Serve on Board of Directors since 2010 in various positions including President for 3 years. Serve on the ISSA International Web Conference Committee.

Terremark

2 roles

Security Analyst

Promoted

Jun 2009Jun 2010 · 1 yr

  • Provide security services to MSSP and Cloud customers:
  • 24/7 Monitoring
  • Intrusion Detection Systems
  • Intrusion Prevention Systems
  • Log Aggregation
  • Network Analysis/ Deep packet Inspection
  • Managed Firewall
  • Network Forensics
  • Database Monitoring
  • Vulnerability Scanning
  • File integrity monitoring
  • Managed End User Metrics and Analytics
  • Compliance Reporting

System Administrator

Oct 2007Jun 2009 · 1 yr 8 mos

  • Technical position managing and supporting Corporate IT systems. Emphasis on maximizing up time and availability of systems to ensure productivity.
  • Managed help desk and assisted junior administrators on escalated tickets; average ticket turnover: 4 hours or less.
  • More information about this position may be obtained by contacting me directly.

Florida international university

Active Directory Migration Engineer

May 2007Oct 2007 · 5 mos

  • Migrate all client workstations to Active Directory including user profiles. 3800+ workstations

The business strategy partners, inc.

IT Consultant

Dec 2002May 2007 · 4 yrs 5 mos

  • Windows 2003 Small Business Server, Windows 2003 Standard, Share Point Portal Server and Microsoft Dynamics-CRM in-house implementation and maintenance
  • Managing and administering customers in information technology (IT), gathering requirements, identifying customer needs, and formulating strategies and implementing Information Systems and Network Infrastructure including but not limited to: (a) Windows NT 4 and Windows 2000 migration to Microsoft Windows Server 2003 for small and medium sized business clients; (b) Active Directory user profile definition, user security policies, deployment procedures, maintenance routines, and data integrity verification; (c) Backup policy for business critical applications and overall system environment
  • Design and manage help desk for residential and small business clients. Provided service to over 100 clients.

Education

Stanford University

Advanced Computer Security — Computer Science

Jan 2014Jan 2016

Florida International University

Masters of Science — Management Information Systems

Jan 2008Jan 2009

Florida International University

BBA — Management Information Systems

Jan 2004Jan 2008

Stackforce found 100+ more professionals with Penetration Testing & Vulnerability Management

Explore similar profiles based on matching skills and experience