Sales Engineering & Field Technical Leadership · Cybersecurity

Jannis Utz

Bridging deep technical security expertise and boardroom-ready strategy.

VP Global Sales Engineering, Pentera — Hamburg, Germany · Open to remote EMEA

About

Twenty years translating technical risk into decisions leaders can act on

I've spent the last twenty years on the technical front line of cybersecurity — first as a hands-on consultant and engineer, then leading the teams that help the world's security leaders separate real risk from noise.

Today I lead Global Sales Engineering at Pentera, the company that pioneered automated, continuous penetration testing. My work is helping CISOs and their teams move from point-in-time assessments to continuous validation of their actual security posture — and translating that shift into language that resonates at board level, not just in the SOC.

Before Pentera, I built the same technical-to-executive bridge at Recorded Future (threat intelligence), Tenable and Qualys (vulnerability management), and nearly a decade at indevis, a German IT security consultancy, where I ran the northern-Germany regional office. Trained originally in bioinformatics at LMU Munich, and a graduate of K1 Investment Management's Advanced Management Program, I've always been drawn to translating dense technical systems into something people can act on — security has just turned out to be where I've spent my career doing it.

Track record

Twenty years, one throughline

  1. 2024 — Present

    VP Global Sales Engineering · Pentera

    Leading the global SE organization for the world's first fully automated, agentless penetration testing platform.

  2. 2022 — 2024

    AVP, Head of Sales Engineering, EMEA & APAC · Pentera

    Extended the technical pre-sales leadership remit from EMEA into APAC as the company scaled.

  3. 2021 — 2022

    Head of Sales Engineering → Senior Director, EMEA · Pentera

    Took on regional SE leadership for EMEA, promoted to Senior Director within the same remit.

  4. 2019 — 2021

    Senior Sales Engineer · Pentera

    Joined as an individual-contributor Sales Engineer, promoted into regional leadership within a year.

  5. 2018 — 2019

    Sales Engineer · Recorded Future

    Threat intelligence — helping enterprises operationalize threat data into their security programs.

  6. 2016 — 2018

    Senior Security Engineer · Tenable

    Vulnerability management at enterprise scale.

  7. 2014 — 2016

    Technical Account Manager · Qualys

    Cloud-based security and compliance.

  8. 2005 — 2014

    Senior Consultant → Regional Office Manager · indevis IT-Consulting

    Nine years building technical consulting expertise, then leading the northern-Germany regional office.

Insights

Notes from the field

Continuous validation

The annual pentest is over — most security teams haven't caught up

+

For decades, "are we secure?" was answered once or twice a year, by a pentest report that was stale before the ink dried. That model made sense when infrastructure changed slowly. It doesn't anymore.

Cloud environments, identity sprawl, and constant code deployment mean your attack surface today isn't your attack surface next Tuesday. The organizations getting this right have stopped treating validation as a project and started treating it as a continuous process — automated, always-on, and integrated into how they prioritize remediation.

The hard part isn't the technology. It's the operating model change: security teams built around quarterly reporting cycles need to rethink how they consume continuous signal without drowning in it.

Board communication

What boards actually want to hear about cyber risk

+

Most security leaders present risk the way they were trained to think about it: CVEs, exploitability scores, patch cadence. Most boards don't have the context to act on any of that.

What boards want is simpler and harder: what's our exposure, in business terms, and what are we doing about the things that matter most. That means translating technical findings into a small number of prioritized, well-evidenced statements — not a dashboard of severity scores.

The security leaders who get promoted into board-facing roles are usually the ones who've already been doing this translation work informally for years, inside their own organizations, before anyone gave them the title.

AI & offensive security

AI is changing both sides of the fight

+

Offensive AI is getting real attention right now — funding rounds framed around "AI vs. AI" security, autonomous attack simulation, agentic red-teaming. That's not hype; the tooling is genuinely getting better at finding paths through defenses faster than manual testing ever could.

But the more interesting shift is on the defensive side: AI-assisted validation lets under-resourced security teams run continuous testing that used to require a large, specialized team. That's a democratizing force — mid-market companies can now validate their posture the way only the largest enterprises could a few years ago.

The organizations that will struggle aren't the ones without AI. They're the ones still running their security program on an annual cycle while both attackers and defenders around them move to continuous.

From colleagues

"Add the exact wording from your LinkedIn recommendation here — copy it verbatim rather than paraphrasing, so the attribution stays accurate."

— Steve Smith · LinkedIn recommendation, June 2025 ◆ placeholder — replace before publishing