Cybersecurity Leader

Petra Vukmirovic

OWASP Project Co-Leader Threat Model Library
Head of InfoSec & IT @ Numan
Fractional Head of Product @ DevArmor
Creating order out of chaos and building a safer, more secure and open source digital world.

Threat Modeling Public Speaker Ex-Doctor DevSecOps AI & Security Patent Holder Open Source Security Leader Team Builder Security at Scale Volleyball Player
Petra Vukmirovic speaking at OWASP
01

About me

My journey into cybersecurity is unconventional. I started my career as an Emergency Medicine Doctor in Croatia, later moving to the UK to continue my specialty training with the NHS. The high-pressure environment of the ER taught me to think systematically about complex, ambiguous problems — and to build protocols that work when everything is on fire. Those same skills now drive how I approach incident response playbooks and security architecture.

Today, I serve as Head of Information Security and Technology at Numan and Fractional Head of Product at DevArmor. I apply diagnostic thinking from medicine to threat modeling — the parallels are striking: differential diagnosis is just threat modeling for the human body. Both fields require pattern recognition, risk assessment under uncertainty, and protecting what matters most.

I'm an OWASP Project Co-Leader for the Threat Model Library — the first open-source, structured, peer-reviewed threat modeling dataset. I also co-lead the Threat Modelling Use Cases working group at the Linux Foundation AI & Data. My mission is to democratise security knowledge and make threat modeling accessible to everyone.

Outside of work, alongside with my mother, I co-founded a non-profit in Croatia called DIP, focused on community inclusion — running workshops, activities and mentoring programs for young people with learning disabilities and various types of neurodiversity. I also compete in volleyball in the NVL and London League, and beach volleyball in the UKBT.

Petra — Who am I slide at OWASP London Who am I
Petra playing volleyball On the court
02

Podcasts & Video

03

Conference Talks

Petra speaking at a conference
OWASP Global AppSec DC 2025
Petra presenting AI-Driven Threat Modelling
London DevSecOps 2025
Petra at OWASP event, Who am I slide
OWASP London 2024
Petra at OWASP Global AppSec USA 2025
OWASP Global AppSec USA 2025
Petra at London Tech Show 2026
London Tech Show 2026
Petra at teiss London 2026
teiss London 2026
Petra at Fortress London 2026
Fortress London 2026

← scroll for more →

2026

Breaking Out of Optimised Failure

London Tech Show 2026

Presentation Recording unavailable
Conference
2025

Breaking the Black Box: Using the OWASP Threat Model Library to End Security via Obscurity

OWASP Global AppSec USA 2025 — Washington D.C., Nov 3–7

Conference
2025

OWASP Threat Model Library — v1.0 Release

OWASP Global AppSec Barcelona — May 29th, 2025

Presentation Recording unavailable
Conference
2024–25

AI and AppSec: Are We Finally on the Verge of the Big Breakthrough

Presented at OWASP London Chapter on October 31, 2024 and London DevSecOps Meetup on April 16, 2025

Meetup

Panels & Roundtables

Selected panel appearances focused on leadership, threat intelligence, AI in security, resilience, and inclusive security practice.

2026

AI cyber-threat defence tools, neurodiversity, and inclusive security

teissLondon2026 | The European Information Security Summit — February 26, 2026. Panels on what works and what does not in AI cyber-defence tools, how to measure effectiveness, and whether security approaches leave neurodiverse colleagues behind.

Panel
2026

From Defence to Design: The CISO’s Role in Building the Business of Tomorrow

Fortress London — February 25, 2026. Discussion centered on resilience, leadership, mental health, recovery, and risk ownership when critical issues are not surfaced early.

Panel
2025

AI and LLMs in Fintech Security

CTO Craft Con: Finance Edition — November 18, 2025. Panel covering AI and LLM use in fintech security, sophisticated threat handling, proactive security posture, and DevSecOps in complex financial environments.

Panel
2025

Changing Threat Landscape

CyberSec Leaders Convention 2025, Cotswolds Retreat — March 31 to April 1, 2025. Closed-door discussion on current threat intelligence, vulnerabilities in financial institutions, and practical peer exchange under Chatham House Rule.

Panel
04

Upcoming Appearances

No upcoming talks scheduled right now.

Want me at your event? Get in touch →

05

Writing & Thoughts

My writing and speaking style is clear, direct, witty, and grounded in real-world practice. I focus on making complex security topics understandable, challenging assumptions that no longer hold, and turning abstract ideas into practical, thought-provoking insight. Whether through talks or blog posts, my aim is to give people something useful to question, rethink, and apply.

Open to collaboration

Let's build something together

I'm passionate about making security knowledge open and accessible. Whether you want to contribute to an OWASP project, invite me to speak, or just explore ideas — here's how we can work together.

🌐

Contribute to OWASP

Help build the Threat Model Library — the first open-source, peer-reviewed threat modeling dataset. All skill levels welcome.

🎤

Invite Me to Speak

I speak on threat modeling, AI in security, DevSecOps, leadership, resilience, security strategy, executive risk conversations, and building security into business decisions. Reach out on LinkedIn.

✍️

Write or Research Together

Interested in co-authoring articles, research papers, or contributing to open-source security tooling.