Omar Santos is a Distinguished Engineer at Cisco focusing on artificial intelligence (AI) security, cybersecurity research, incident response, and vulnerability disclosure. He is the co-chair of the Coalition for Secure AI (CoSAI) and a board member of the OASIS Open standards organization. Omar is also the chair of the OpenEoX and the Common Security Advisory Framework (CSAF) technical committee. His work led the creation of the CSAF ISO standard.
Omar's collaborative efforts extend to numerous organizations, including the Forum of Incident Response and Security Teams (FIRST) and the Industry Consortium for Advancement of Security on the Internet (ICASI). Omar is the co-chair of the FIRST PSIRT Special Interest Group (SIG) and was the lead of the DEF CON Red Team Village for several years.
Omar is the author of over 25 books, 21 video courses, and over 50 academic research papers. Omar is a renowned expert in ethical hacking, vulnerability research, incident response, and AI security. Omar's work in cybersecurity is also recognized through multiple granted patents. Prior to Cisco, Omar served in the United States Marines focusing on the deployment, testing, and maintenance of Command, Control, Communications, Computer, and Intelligence (C4I) systems.
An Open Specification for Agentic Security Evaluation
In the age of AI, the real game changer is more than the latest LLM, it’s how you put it to work. That’s why we’re open-sourcing the Foundry Security Spec, a battle-tested blueprint for........
Today, I’m excited to announce that Cisco is donating Project CodeGuard to the Coalition for Secure AI (CoSAI). We collectively recognize that securing AI-generated code is a challenge that belongs to the entire industry, and that open collaboration is the path forward. Our Journey with Project CodeGuard When we first open–sourced Project CodeGuard in October 2025, our goal was clear: make secure […]
When your CISO mentions “AI security” in the next board meeting, what exactly do they mean? Are they talking about protecting your AI systems from attacks? Using AI to catch hackers? Preventing employees from leaking data to an unapproved AI service? Ensuring your AI doesn’t produce harmful outputs? The answer might be “all of the […]
Explore how enterprises build secure AI agent ecosystems using frameworks and tools like Project CodeGuard and MCP Scanner to ensure trust and accountability.
Software teams worldwide now rely on AI coding agents to boost productivity and streamline code creation. But security hasn’t kept up. AI-generated code often lacks basic protections: insecure defaults, missing input validation, hardcoded secrets, outdated cryptographic algorithms, and reliance on end-of-life dependencies are common. These gaps create vulnerabilities that can easily be introduced and often […]
The CVE program is the foundation for standardized vulnerability disclosure and management. With its future uncertain, global organizations face challenges.
Announcing the launch of the Coalition for Secure AI (CoSAI) to help securely build, deploy, and operate AI systems to mitigate AI-specific security risks.