About
Invictus Cybersecurity is a military-spouse-owned security consultancy in San Antonio, Texas. We help small and mid-sized organizations move from scanner noise to verified risk reduction — and we tell you the truth about what you need, including when it isn’t us.
The founder
Emmanuel spent six years doing this work inside other people’s companies before starting Invictus. He built a security program from nothing across four SaaS products, ran three PCI DSS audit cycles, and most recently led vulnerability management operations at enterprise scale — the kind of environment where a bad prioritization call costs real money and a good one is invisible.
That last role is where VM3 came from. Watching teams drown in findings while nobody could answer the only question that mattered — is risk actually going down? — turned into a maturity model, which turned into a published paper, which turned into how we run engagements.
He also builds agentic security tooling with containment boundaries and audit logging, which is why we can tell you where your data actually flows, what your guardrails miss, and what to fix first. We secure this stuff because we build it.
The practical consequence for you: the person who scopes your engagement is the person who delivers it. There is no bench, no handoff to a junior, and no sales layer between you and the work. That’s a deliberate constraint on how many clients we take at once.
CertificationsISC2 CSSLP · ISC2 SSCP · Security+
FederalCyberAB Registered Practitioner — verify →
EducationMS Cybersecurity
FrameworksNIST CSF · 800-171 · TSC · CIS · PCI DSS v4.0 · OWASP
LanguagesEnglish · Español
How we work
Invictus is independent and product-agnostic — a proud supporter of any and all security tooling and vendors. The right tool is the one that’s best for you. We run programs on what you already own, and when something new genuinely helps, we tell you what to look for and leave the choice to you.
We test applications. We don’t do internal network penetration testing or red-teaming, we’re not a SOC, and we don’t do emergency incident response. When you need those, we say so and point you to someone who does.
A report nobody acts on is an expensive document. We hand your engineers a queue they can work, then come back and verify the risk actually went down.
If your board can’t read it, it isn’t finished. Most of our clients have no internal security team, and we write for that reader — in English or Spanish.