- GEN AI SECURITY
- Initiatives
Agentic AI Security Initiative
The Agentic Security Research Initiative explores the emerging security implications of agentic systems, particularly those utilizing advanced frameworks (e.g., LangGraph, AutoGPT, CrewAI) and novel capabilities like Llama 3’s agentic features.
- #team-genai-agentic-security-initiative
- GEN AI SECURITY
- Project
- Leadership
Leadership & Contributors
Project Leadership Team
Board of Directors
Scott Clinton
Co-chair, Co-founder, CCO, Co-lead - multiple
Scott Clinton
Co-chair, Co-founder, CCO, Co-lead - multiple
Scott Clinton is Co-Founder, Co-Chair, and Board Member of the OWASP GenAI Security Project, the global open-source initiative dedicated to identifying and mitigating security risks associated with generative AI and large language models. He leads strategy, operations, and growth for the project, which has grown to hundreds of volunteers and thousands of contributors worldwide, producing tools, frameworks, and guidance relied upon by security practitioners globally.
A 25+ year industry executive and 20-year veteran of commercializing open source and building industry consortiums, Scott has extensive experience leading and scaling open-source businesses, productization, and community development strategy across the DevOps, security, storage, big data, AI/ML, and analytics markets.
A published author and research lead, his work includes the Gen AI Security Landscape and the AI Security Center of Excellence Guide, among numerous other publications. Scott also holds multiple board and advisory roles with technology companies, helping guide organizational scale and growth.
Ads Dawson
Technical Lead
Ads Dawson
Technical Lead
Ads is a self-described “meticulous dude,” lives by the philosophy: Harness code to conjure creative chaos—think evil; do good. A seasoned AI Security Researcher and offensive security engineer, Ads brings over 13 years of expertise in red teaming, penetration testing, and MLSecOps with a knack for building tools to solve common hacking challenges, constantly enhancing his offensive arsenal. As the Technical Lead for OWASP’s Top 10 for LLM Applications, he uncovers emerging AI security threats.
Sandy Dunn
Co-lead AI Governance Initiative
Sandy Dunn
Co-lead AI Governance Initiative
Sandy Dunn, CISO at Knowtion Health has more than 20 years of experience in Information Security leadership roles at top technology companies. She is the project lead for the OWASP Top 10 for LLM Applications Cybersecurity and Governance Checklist, and a core Member of the OWASP GenAI Security Project and Gen AI Agentic Security Initiative.
She is a sought-after speaker and advisor, Sandy serves as an Adjunct Cybersecurity Professor at Boise State University and sits on the board of directors for Boise State University’s Institute for Pervasive Cybersecurity. She holds a Master’s degree in Information Security Management from SANS. Her certifications include a CISSP, SANS GSEC, GWAPT, GCPM, GCCC, GCIH, GLEG, GSNA, GSLC, GCPM, Security+, ISTQB, and FAIR.
John Sotiropoulos
Co-lead, Agentic Security Initiative
John Sotiropoulos
Co-lead, Agentic Security Initiative
John Sotiropoulos is the Founder of Deep Cyber Ltd, safeguarding national-scale AI programmes across government, healthcare, and finance. He co-leads the OWASP Agentic Security Initiative, chairs the OWASP Top 10 for Agentic Applications, and is a Board Director of the OWASP GenAI Security Project.
John liaises with national cybersecurity agencies and has authored the UK Government’s Implementation Guide to the AI Cyber Security Code of Practice, now the ETSI EN 304 223 standard, and sits on the ETSI SAI technical committee shaping standards for secure AI and agentic systems. He was Highly Commended for Security Professional of the Year at the 2025 UK IT Awards, and is the bestselling author of Adversarial AI Attacks, Mitigations, and Defense Strategies.
Steve Wilson
Co-chair, Top 10 for LLM Founder, Co-lead
Steve Wilson
Co-chair, Top 10 for LLM Founder, Co-lead
Steve Wilson is Chief Product Officer at Exabeam. Wilson leads product strategy, product management, product marketing, and research at Exabeam. He is a leader and innovator in AI, cybersecurity, and cloud computing, with over 20 years of experience leading high-performance teams to build mission-critical enterprise software and high-leverage platforms. Before joining Exabeam, he served as CPO at Contrast Security leading all aspects of product development, including strategy, product management, product marketing, product design, and engineering.
Wilson has a proven track record of driving product transformation from on-premises legacy software to subscription-based SaaS business models including at Citrix, accounting for over $1 billion in ARR. He also has experience building software platforms at multi-billion dollar technology companies including Oracle and Sun Microsystems.
Wilson is also a project leader at the Open Web Application Security Project (OWASP) Foundation where he has assembled a group of over 400 experts to create the first industry-standard, comprehensive reference project called the “Top 10 List for Large Language Model Applications.” The list educates developers, designers, architects, managers, and organizations about the potential security risks when deploying and managing generative AI and other large language models (LLMs). He holds a degree in Business Administration from the University of San Diego and a second-degree black belt from the American Taekwondo Association.
Initiative Leads and Core Team
Scott Clinton
Co-chair, Co-founder, CCO, Co-lead - multiple
Ads Dawson
Technical Lead
Ron F. Del Rosario
Co-lead Agentic Security Initiative
Ron F. Del Rosario
Co-lead Agentic Security Initiative
Ron serves as the Head of AI Security for SAP Intelligent Spend and Business Network (ISBN), where he plays a pivotal role in driving innovation at the intersection of cybersecurity and AI. As a pioneer in AI/ML security since 2018, he has developed internal frameworks for AI/ML security governance and AI Security Posture Management (AI-SPM), supported by a patent on utilizing AI/ML for secure software development.
His current focus area of research revolves around advancements in reasoning and prompt engineering techniques (Chain-of-Thought, Reason + Act, Chain-of-Verification, etc.) for Language Models and how it can benefit Cybersecurity use cases.
Sandy Dunn
Co-lead AI Governance Initiative
Emmanuel Guilherme
Co-lead Data Security Initiative
Emmanuel Guilherme
Co-lead Data Security Initiative
Emmanuel Guilherme Jr. is a Senior Global IT Auditor at a multinational enterprise, founding member of the OWASP Top 10 for LLM Applications (2023), and lead of the OWASP GenAI Security Project — Data Security Initiative.
He is the primary author of the OWASP GenAI Data Security Risks and Mitigations 2026 and creator of the OWASP GenAI Security Crosswalk, mapping GenAI risks to NIST AI RMF, MITRE ATLAS, ISO/IEC 42001, and the EU AI Act. He served as technical reviewer for AI-Native LLM Security (Packt, 2025), holds multiple cybersecurity certifications, contributes to Canada’s ISO/IEC AI Mirror Committee, and advises startup founders on building GenAI security programs that stand up to audit.
Rachel James
Co-lead Threat Intel Initiative
Rachel James
Co-lead Threat Intel Initiative
Rachel C. James is a pioneering AI security engineer and governance architect with a career built at the frontier of machine learning and adversarial risk. Before “AI security engineer” was even a recognised job title, Rachel was building anomaly detection and beaconing models in TensorFlow and PyTorch — grounding her governance work in deep technical fluency.
At AbbVie, she serves as Chair of the Enterprise AI Governance Committee and core member of the AI Enablement Community of Specialists. She authored the Agentic Controls Framework that governs all AI deployments across the organisation — a document that reflects both her engineering depth and her systems-level thinking.
As Prompt Injection Lead for the OWASP GenAI Top 10 and Threat Intelligence Co-Lead, Rachel helps write the standards that AI Governance Officers will themselves be audited against. Her adjunct research role at RAND extends that influence into policy, where she conducts highly technical research into AI testing, red teaming, and adversarial AI use.
She also builds agentic applications for threat and risk management — closing the loop between policy, research, and working software.
Sonu Kumar
Co-lead, Red Teaming
Rock Lambrose
Co-lead, Top 10 for LLM Initiative
Rock Lambrose
Co-lead, Top 10 for LLM Initiative
Kyriakos “Rock” Lambros serves as Director of AI Standards and Governance at Zenity and Founder of RockCyber, where he leads AI security standards work, policy advocacy, and cybersecurity governance consulting for Fortune 500 clients. A recovering CISO with 30 years of experience, Rock has built and led security programs for multibillion dollar organizations across energy, eCommerce, government, banking, and manufacturing.
He co-leads the OWASP Top 10 for LLMs, serves as a core team member of the OWASP GenAI Security Project and OWASP Agentic Security Initiative, and is a project author for the OWASP AI Exchange. He is a contributor to CoSAI and AIUC-1, holds a Distinguished Fellow position with the Enterprise Risk Quantification Institute (ERQI), and is a certified AI Governance Professional (AIGP) and Qualified Technology Expert (QTE).
Rock co-authored “The CISO Evolution: Business Knowledge for Cybersecurity Executives, and publishes “RockCyber Musings” a bi-weekly newsletter distilling AI security developments for executive leaders. He is a frequent keynote speaker, panelist, and industry commentator on agentic AI security, AI governance, and enterprise risk. Rock holds an MBA in Finance and Entrepreneurship from Arizona State University, a B.S. in Management Information Systems from the University of Nevada Las Vegas, and is currently pursuing an M.S. in Applied Data Science and AI at the University of Denver.
Bryan Nakayama
Co-lead Threat Intel Initiative
Bryan Nakayama
Co-lead Threat Intel Initiative
Dr. Bryan Nakayama is a cyber threat intelligence analyst and GenAI security researcher whose work spans enterprise security, open standards, and national security policy. At UnitedHealth Group, he leads quantitative threat actor analysis — automating intelligence pipelines and matching telemetry to real-world adversary behaviour at scale.
As CTI Initiative Co-Lead for the OWASP GenAI Security Project, he co-authors industry guidance on deepfakes, LLM exploit generation, and AI incident response, with coverage in Dark Reading and presentations to UN delegations. He also serves on the invite-only Health-ISAC Threat Intelligence Committee. A PhD graduate of the University of Minnesota, Bryan’s academic research on domains of warfare — air, space, cyberspace — underpins a distinctive ability to connect technical threat intelligence with the broader strategic picture.
Helen Oakley
Co-lead AIBOM Initiative
Helen Oakley
Co-lead AIBOM Initiative
Helen Oakley, CISSP, GPCS, GSTRT, is VP of Software & AI Security at SAP and a leader in AI software supply chain security. She is part of the core leadership team of the OWASP GenAI Security Project and co-leads initiatives on AIBOM and Agentic Security, contributes into industry papers like Agentic AI Threats & Mitigations Guide, OWASP Top 10 for Agentic Apps, and more.
Helen has co-led AIBOM efforts with CISA, and is the original creator of the OWASP FinBot CTF and the first open-source OWASP AIBOM Generator for Hugging Face models.
Dmitry Raidman
Co-lead AIBOM Initiative
Dmitry Raidman
Co-lead AIBOM Initiative
Dmitry Raidman is Co-Founder and CTO of Cybeats and a long-time leader in software supply chain security.
He is one of the original creators of SBOM formats, has co-led AIBOM efforts with CISA, and co-created the AIBOM Generator to advance transparency across AI and software supply chains.
Jason Ross
Co-lead, AI Red Teaming Initiative
Jason Ross
Co-lead, AI Red Teaming Initiative
Jason Ross is a passionate cybersecurity expert with a diverse skill set in generative AI, Penetration Testing, Cloud Security, and OSINT. As a product security principal at Salesforce, Jason performs security testing and exploit development with a specific focus on generative AI, Large Language Models, and Agentic systems.
Jason is a frequent speaker at industry conferences, and is active in the security community: participating as a core member of the OWASP Generative AI Security Project, and serving as a DEF CON NFO goon.
Talesh Seeparsan
Localization and Language Translation
John Sotiropoulos
Co-lead, Agentic Security Initiative
Steve Wilson
Co-chair, Top 10 for LLM Founder, Co-lead
Project Contributors
Already submitted? Request updates to your profile.