North Jersey/ Science, Tech & Medicine

Jersey City's ThreatModeler Lands $60M, Then Buys Its Biggest Rival for More Than $100M

AI Assisted Icon
Published on September 28, 2026
Jersey City's ThreatModeler Lands $60M, Then Buys Its Biggest Rival for More Than $100M101 Hudson St #2100 — ThreatModeler Headquarters Location
Google Street View

ThreatModeler Software Inc., the Jersey City-based cybersecurity firm behind an automated threat modeling platform used by large enterprises, announced its first institutional financing on June 5, 2024, raising $60 million from Invictus Growth Partners. The deal put fresh capital behind a company founded in 2010 that helps enterprises find and fix design flaws early in software development. Over the following roughly year and a half, the company also underwent a leadership change and acquired a rival.

As reported by Dealroom.co, the financing brought two new additions to ThreatModeler's board of directors: John DeLoche and Jeremy Lai. ThreatModeler said it planned to use the capital for sales, marketing, and AI-driven product development. At the time of the raise, Archie Agarwal was described as the company's founder and CEO, with the firm's stated mission centered on what it calls one-click threat modeling.

The platform itself spans two core products: CloudModeler, which covers cloud infrastructure, and IaC-Assist, which covers Infrastructure-as-Code workflows. Together, the tools check cloud environments for drift from their intended design, a capability that technical reviews in 2026 identified as central to a broader shift away from legacy manual frameworks like STRIDE and toward automated analysis of cloud infrastructure, according to VerSprite.

A New CEO Takes the Wheel

Roughly eight months after the funding closed, ThreatModeler restructured its top leadership. In February 2025, the company appointed Matt Jones as Chief Executive Officer, while Agarwal, who had served as both CEO and chief technical architect since founding the company in 2010, moved into the role of Chief Innovation Officer to drive strategic innovation, including in AI and cloud threat modeling, according to Newsfile Corp.

In January 2026, ThreatModeler acquired its chief rival, Spanish threat modeling platform IriusRisk, in a deal reported as valued at more than $100 million. The acquisition consolidated two of the market's leading automated threat modeling platforms under one roof; IriusRisk had previously been backed by Paladin Capital Group, according to PR Newswire.

Behind the Money: Invictus Growth Partners

The investor driving ThreatModeler's expansion has its own growth story. Invictus Growth Partners, founded in 2019 by John DeLoche and William Nettles, closed its second flagship fund at $574 million in May 2025, significantly exceeding its initial $350 million target, per PR Newswire's coverage of the firm's fundraising. That followed the firm's debut fund, which closed at $216 million in 2022. The San Mateo-based firm credits an in-house AI-driven deal intelligence platform called DIANE with sourcing 83% of its completed portfolio deals, offering a glimpse into how it identified ThreatModeler as a target.

ThreatModeler was not Invictus Growth Partners' first foray into enterprise security automation. In November 2022, the firm led a $36 million investment in Binary Defense, a Managed Detection and Response provider specializing in open XDR and threat hunting technologies, PR Newswire reported at the time.

Legal and Market Context

Law firm Rimon P.C., which operates across 50 international offices, advised ThreatModeler on the $60 million financing. The deal team was led by transactional attorney Brian Keeler alongside Victoria Yang, Craig Tanner, and Roy W. Gillig, according to Rimon Law. The firm's release also noted that ThreatModeler's raise came as the global DevSecOps software market was projected to grow from $6.1 billion in 2023 to $10.1 billion by 2027, an 18% compound annual growth rate.

NIST SP 800-218 includes threat modeling among secure software development practices, and federal guidance discusses procurement and software security attestations, per the National Institute of Standards and Technology. Executive Order 14028 directed NIST to issue software supply-chain security guidance and OMB to require agency compliance with that guidance.