Ian Roth

Security products · Threat-informed defense

Ian Roth

Before I wrote my first detection, I called in artillery for a living.

I spent four years hunting threats and writing detections across a DoD network of more than 100,000 endpoints. The recurring problem wasn’t a shortage of tools. It was knowing whether the tools we had covered the threats we faced. I co-founded Interpres Security in 2020 to answer that question. CyberProof acquired the company in 2024; today I lead product innovation there.

Selected work

From operating defenses to building them

My work has moved from doing the job, to turning an operator’s problem into a company, to bringing that product into a larger security service.

01 · Interpres Security 2020 — 2024

Turn the coverage gap into a product

Do the defenses already in place cover the threats that matter to this organization?

We combined threat exposure, attack surface, and defense posture in one MITRE ATT&CK–based model, then ranked gaps by threat relevance. I owned the product from discovery and roadmap through technical architecture, the core data model, and positioning.

The work earned Gartner recognition, resulted in multiple patents, and led to CyberProof acquiring the company in 2024.

Built from zero Recognized by Gartner Acquired in 2024
02 · CyberProof 2024 — now

Make exposure operational

Move from periodic reporting to a shared view of what needs attention now.

I lead product innovation at CyberProof, integrating the Interpres approach into co-managed detection and response. I led development of CDC Reveal360, bringing security, IT, and GRC data into role-specific views and composite exposure scores.

I also scaled the CTEM engine into CyberProof’s environment, connected coverage analysis to service reporting, and established a product operating cadence for a services-led organization.

Exposure management Product systems AI-assisted operations

How I got here

Two operating jobs shaped the way I build

03 · US Army 2012 — 2016

Coordinate under pressure

In field artillery and Division Fires, I learned to coordinate people, data, and systems when the information was incomplete and the consequences were real. I trained NATO forces on the alliance’s eastern flank and became my unit’s subject-matter expert for battle-command systems and digital integration.

Division Fires NATO training Digital integration

04 · Adapt Forward 2016 — 2020

Find the gap the tools couldn’t show

I brought that systems mindset to threat hunting, detection engineering, and incident response for a DoD CSSP protecting more than 100,000 endpoints. We could inventory products and controls, but not answer the more important question: did they cover the adversary behavior that mattered? That gap became Interpres.

100k+ endpoints 100+ detections 15+ products evaluated

Now

Compare notes

I’m interested in what becomes scarce in security when software itself is no longer scarce. Agents compress the time from intent to capability: attackers can vary behavior cheaply, while defenders can tailor detections and investigations to their own environment. The bottleneck shifts from building features to deciding what matters, proving what works, and learning from deployment. Durable advantage may move to unique telemetry, better models of the environment, and products embedded deeply enough in the operating loop to compound what they learn.

If you’re building around those shifts—or think the thesis is wrong—I’d like to compare notes.