Cobalt, a leader in penetration testing as a service (PTaaS) and human-led, AI-powered offensive security, has announced the appointment of Tony Spinelli to its Board of Directors. Spinelli, a distinguished cybersecurity veteran with over 25 years of experience, has previously served as a Chief Information Security Officer (CISO) for four organizations and a Chief Information Officer (CIO) for two. His extensive background in digital transformation and securing complex enterprise environments is expected to bolster Cobalt’s strategic support for organizations navigating modern, AI-driven threats.
Tony Spinelli joins Cobalt’s Board of Directors with over 25 years of security leadership.
Spinelli has served as CISO for four companies and CIO for two, including Capital One.
The appointment aims to help enterprise customers transition to continuous offensive security.
Cobalt focuses on Pentesting as a Service (PTaaS) to replace traditional point-in-time testing.
Spinelli is an early investor in Cobalt and a long-time user of the platform.
The strategy aligns with the industry shift toward Continuous Threat Exposure Management (CTEM).
The appointment comes as organizations face rapidly expanding attack surfaces and increasingly sophisticated adversaries. Cobalt’s platform is designed to move security testing away from isolated events toward a programmatic, continuous approach that aligns with modern cloud and development cycles. Spinelli’s experience in pioneering secure cloud adoption at scale is positioned as a critical asset for Cobalt as it scales its Offensive Security Platform.
“Security leaders are operating in an environment where threats evolve faster than traditional testing models can keep up,” said Sonali Shah, CEO, Cobalt. “Tony has been at the forefront of cloud transformation and cybersecurity innovation for decades, helping some of the world’s most complex organizations navigate this shift. His perspective will be invaluable as we continue to scale the Cobalt Offensive Security Platform and help customers operationalize continuous offensive security.”
Throughout his career, Spinelli has led cybersecurity and machine learning initiatives at major institutions, including Capital One, Equifax, First Data, and Tyco International. He currently serves as the Chief Security Officer at Halcyon and holds faculty positions at George Washington University and the National Association of Corporate Directors. His dual perspective as a security operator and a board-level advisor provides Cobalt with unique insights into the risk reduction needs of the enterprise market.
“Cybersecurity has reached an inflection point where traditional defensive strategies alone are no longer sufficient,” said Tony Spinelli. “Organizations need continuous, intelligence-driven approaches that reflect how attackers actually operate today with humanistic intent. Cobalt has built a platform that combines elite human expertise with scalable technology to deliver that capability, and I’m excited to join the board and support the company’s next phase of growth.”
The addition of Spinelli to the board underscores Cobalt’s momentum in the enterprise sector, specifically regarding the adoption of Continuous Threat Exposure Management (CTEM) strategies. By combining a network of over 500 security experts with a unified platform, Cobalt enables organizations to identify vulnerabilities and integrate findings directly into remediation workflows. This integrated approach allows businesses to accelerate risk mitigation and innovate within secure parameters.
About Cobalt
Cobalt is the pioneer in pentesting as a service (PTaaS) and a leader in human-led, AI-powered offensive security solutions. We are focused on combining talent and technology with speed, scalability, and expertise. Thousands of customers and hundreds of partners rely on the Cobalt Offensive Security Platform, along with 500+ trusted security experts, to find and fix vulnerabilities across their environments. By enabling faster pentest launches, real-time collaboration with pentesters, and seamless integration with remediation workflows, we help organizations identify critical issues and accelerate risk mitigation so they can operate fearlessly and innovate securely.