Experience

Aubrey Ian Perin

CISSP  ·  MBA  ·  JD Candidate

Cybersecurity Executive  ·  Enterprise Risk & Governance
Originator of the Qualys TruRisk methodology

Based Hudson, NH
Experience 19 Years
Current MassMutual
LinkedIn aiperin
Scroll
01 — Profile

The through-line

Nineteen years across security operations, threat intelligence, vulnerability and exposure management, and enterprise risk governance — built in national intelligence, defense-adjacent manufacturing, global technology, and regulated financial services.

Eight years of people and program leadership: standing up a malware reverse-engineering capability in the Air Force from charter through budget and staffing, directing a six-analyst research unit at Qualys, and owning enterprise security programs end to end at FLIR and MassMutual.

MBA-trained and pursuing a JD, which is less a credential stack than a working method — the financial and legal fluency to translate technical exposure into risk narratives that executives, regulators, and boards can actually act on.

The pattern across all of it: find the structural principle a system can't see about itself, make it measurable, and make it legible to the people who need to act on it.

02 — Signature Outcomes

What actually moved

Authored the risk methodology now used industry-wide

Originated Qualys TruRisk — the exploitability- and threat-actor-weighted scoring model that replaced CVSS-only prioritization across a platform serving 10,000+ enterprise customers, and became a reference point for risk-based vulnerability management.

Compressed enterprise remediation from months to 48 hours

Drafted and drove adoption of a firm-wide 48-hour SLA covering all patchable vulnerabilities and known misconfigurations at a regulated financial institution. Written in response to AI-accelerated vulnerability discovery collapsing the exploitation window; moved from proposal to full program adoption in two months.

Converted chronic SLA failure into managed supplier risk

Built the root-cause program that identified third-party and vendor dependencies as the dominant driver of missed remediation — moving recurring failures out of accountability dispute and into owned vendor-risk treatment with named owners.

Quantified the industry exploitation window

Published research establishing a 19.5-day mean time to weaponize against a 30.6-day mean time to remediate, with only 57.7% of weaponized vulnerabilities ever patched — findings that reset remediation SLA expectations across a global customer base.

Built a security function from nothing

Stood up the malware reverse-engineering capability for a U.S. Air Force intelligence unit — charter, SOPs, policy designations, budget, lab acquisition, and analyst training — then transitioned it to permanent leadership.

03 — Core Capabilities

What I bring to the table

Strategy & Roadmap

Multi-year security strategy, target-state capability definition, control framework architecture, and ownership of transformation programs from current-state assessment through operational handoff.

Enterprise Risk Integration

Cyber risk taxonomy, scenario development, risk appetite calibration, aggregation into enterprise risk reporting, and documented risk acceptance at the right level of authority.

Risk-Based Exposure Management

Exploitability modeling, threat-informed prioritization, and remediation sequencing at both enterprise and platform scale — the discipline behind TruRisk and the QCRF.

Governance, Risk & Compliance

NIST 800-53 and CSF, CIS Controls, CMMC, ISO 27001 concepts. Policy and standards architecture, control assurance, audit coordination, and third-party cyber risk.

Threat Intelligence & Detection

Adversary tracking, APT investigation, MITRE ATT&CK coverage analysis, behavioral analytics, and threat hunting — from MSTIC casework to directing research at platform scale.

Executive Communication

Board and senior-leadership reporting, KRI and KPI definition, investment prioritization, and written analysis across Legal, Audit, Finance, and business functions.

04 — Experience

The record

MassMutual
Sep 2024 – Present
Vulnerability Manager
Remote  ·  Regulated financial services
Qualys, Inc.
Jan 2021 – Jun 2024
Lead Threat Intelligence Analyst
Remote  ·  Threat Research Unit (TRU)
FLIR Systems
Dec 2018 – Jan 2021
Vulnerability Manager
North Billerica, MA
Microsoft Corporation
Apr 2015 – Mar 2018
Security Program Manager  ·  Threat Analyst
Redmond, WA  ·  Microsoft Threat Intelligence Center (MSTIC)
City of Seattle
Jul 2018 – Sep 2018
Security Consultant
Seattle, WA  ·  1099 Contract
Nike Inc.
Dec 2014 – Apr 2015
Cyber Security Analyst
Beaverton, OR
Parsons
Nov 2012 – Nov 2014
Senior Network Analyst  ·  Developer
Columbia, MD
Tailored Access LLC
Mar 2012 – Nov 2012
Cyber Analyst  ·  Network Security Engineer
Fort Meade, MD
United States Air Force
Jan 2007 – Mar 2012
Cyber Intelligence Analyst  ·  1N4 Fusion Analyst
Active Duty
05 — Education

Formation

Juris Doctor
Massachusetts School of Law
In Progress
Master of Business Administration
University of New Hampshire
Graduated May 2025
From the MBA

Ethical Business: Restoring Philosophical Integrity (2025)

This book began as a theoretical model developed during the MBA — an attempt to turn a gut-level reaction to the national debt into something testable and falsifiable. What started as a single framework for examining fiscal distortion accelerated into four: the Corporate Welfare Equation, the ALE Standard, the Marketing Integrity Test, and the Market Integrity Equation. Each is rooted in the philosophical and financial methods the MBA demanded, and each is built to expose a specific type of economic distortion that traditional metrics allow to remain hidden.

Read more about the book →
Bachelor of Arts  ·  General Studies
Southern New Hampshire University
Graduated September 2021
A.A.S.  ·  Intelligence Studies & Technology
Community College of the Air Force
Graduated June 2009
06 — Research & Original Work

Original work

Quantitative risk research developed independently of any employer, plus four economic-accountability frameworks from Ethical Business (2025). Different domains, same method: take a distortion a system can't see about itself and make it measurable.

Quantitative Risk Research
White Paper & Interactive Calculator

QCRF — A Quantitative Framework for Holistic Cybersecurity Risk Evaluation Using Actuarial Principles

Developed after my time at Qualys. The framework builds on actuarial principles to evaluate risk in two complementary areas: CVE-based risk (known vulnerabilities with dynamic real-world adjustments for time-to-exploit, MTTR, and active exploitation trends) and non-CVE infrastructure risk (aging systems, failing controls, and operational dependencies benchmarked against industry standards). Both formulas produce numeric scores mapped to actionable tiers — designed to translate technical exposure into executive-ready risk posture.

Published as original research, implemented as an interactive calculator, and routed to CISA via FS-ISAC government coordination.

Open the Calculator → Download White Paper →
From Ethical Business (2025)

CWE — Corporate Welfare Equation

Quantifies the net public cost of private success — exposing the gap between declared profitability and hidden dependence on public subsidy, regulatory shelter, and externalized harm.

ALE — Expanded Balance Sheet

A philosophical filter sitting above GAAP/IFRS. Tests whether financial statements are Accountable, Logical, and Equitable — not just legally compliant.

MIT — Marketing Integrity Test

Formula-based evaluation of whether marketing matches delivery — or manufactures belief through the Figma Fallacy, behavioral manipulation, and asymmetric information.

MIE + FMET — Market Integrity

Tests whether a firm's market valuation reflects actual contribution or speculative narrative. FMET provides a companion lens for ethically sound firms the market systematically undervalues.

07 — Credentials & Service

Credentials

CISSP Certified Information Systems Security Professional License #503648
MBA University of New Hampshire  ·  2025
JD Candidate Massachusetts School of Law
FS-ISAC Threat Intelligence Committee