Skip to main content
Jorge Zelaya

Jorge Zelaya

Chief Information Security Officer

Atmosera

About

Jorge Zelaya is the Chief Information Security Officer (CISO) at Atmosera, where he leads the company’s cybersecurity strategy, managed security services, compliance initiatives, and cyber resilience programs. With more than 20 years of experience in cybersecurity and information technology, he has built and scaled security organizations across startups, managed service providers, and Fortune 1000 companies spanning healthcare, financial services, manufacturing, SaaS, and technology sectors. At Atmosera, Zelaya is responsible for advancing the company’s security operations and compliance offerings, including Microsoft-aligned security services and Atmosera’s Microsoft Verified MXDR capabilities. He oversees 24x7 security operations, cyber risk management, governance and compliance programs, and the integration of AI-driven security automation. His work focuses on helping organizations strengthen cyber resilience while aligning security investments with business objectives and regulatory requirements. Prior to joining Atmosera, Zelaya served as the Global CISO ZeroFox and IDX, where he was responsible for cybersecurity strategy, IT vision, and platform operations. Throughout his career, he has led security modernization, incident response, risk management, and technology transformation initiatives across a wide range of industries. A recognized cybersecurity thought leader and industry speaker, Zelaya frequently shares insights on AI governance, cyber risk, cloud security, managed detection and response, Microsoft security technologies, and executive security leadership.

Sessions

When Exploitation Moves at AI Speed: Can Security Teams Keep Up?

What you will learn:

The window between vulnerability disclosure and exploitation is getting harder to defend. As AI potentially accelerates how quickly attackers can analyze, adapt, and exploit vulnerabilities, security teams may be forced to respond before they’ve fully assessed exposure or completed patching. This conversation will explore what happens in that critical gap, what teams should be watching for, and how visibility, access, detection, and response need to evolve as the pace of exploitation continues to accelerate.