Avatar

Omar Santos

Distinguished Engineer

Cisco Product Security Incident Response Team (PSIRT) Security Research and Operations

Omar Santos is a Distinguished Engineer at Cisco focusing on artificial intelligence (AI) security, cybersecurity research, incident response, and vulnerability disclosure. He is the co-chair of the Coalition for Secure AI (CoSAI) and a board member of the OASIS Open standards organization. Omar is also the chair of the OpenEoX and the Common Security Advisory Framework (CSAF) technical committee. His work led the creation of the CSAF ISO standard.   Omar's collaborative efforts extend to numerous organizations, including the Forum of Incident Response and Security Teams (FIRST) and the Industry Consortium for Advancement of Security on the Internet (ICASI). Omar is the co-chair of the FIRST PSIRT Special Interest Group (SIG) and was the lead of the DEF CON Red Team Village for several years.   Omar is the author of over 25 books, 21 video courses, and over 50 academic research papers. Omar is a renowned expert in ethical hacking, vulnerability research, incident response, and AI security. Omar's work in cybersecurity is also recognized through multiple granted patents. Prior to Cisco, Omar served in the United States Marines focusing on the deployment, testing, and maintenance of Command, Control, Communications, Computer, and Intelligence (C4I) systems.

Articles

The Domains and Organizational Functions of AI Security

2 min read

When your CISO mentions “AI security” in the next board meeting, what exactly do they mean? Are they talking about protecting your AI systems from attacks? Using AI to catch hackers? Preventing employees from leaking data to an unapproved AI service? Ensuring your AI doesn’t produce harmful outputs? The answer might be “all of the […]

January 20, 2026

EXECUTIVE PLATFORM

Building Trust in AI Agent Ecosystems

4 min read

Explore how enterprises build secure AI agent ecosystems using frameworks and tools like Project CodeGuard and MCP Scanner to ensure trust and accountability.

Announcing a New Framework for Securing AI-Generated Code

3 min read

Software teams worldwide now rely on AI coding agents to boost productivity and streamline code creation. But security hasn’t kept up. AI-generated code often lacks basic protections: insecure defaults, missing input validation, hardcoded secrets, outdated cryptographic algorithms, and reliance on end-of-life dependencies are common. These gaps create vulnerabilities that can easily be introduced and often […]

April 16, 2025

SECURITY

The Need for a Strong CVE Program

2 min read

The CVE program is the foundation for standardized vulnerability disclosure and management. With its future uncertain, global organizations face challenges.

Advancing AI Security and Contributing to CISA’s JCDC AI Efforts 

1 min read

Discover how CISA's new AI Security Incident Collaboration Playbook strengthens AI security and resilience.

Introducing Cisco’s AI Security Best Practice Portal

2 min read

Cisco's AI Security Portal contains resources to help you secure your AI implementation, whether you're a seasoned professional or new to the field.

July 18, 2024

SECURITY

Introducing the Coalition for Secure AI (CoSAI)

2 min read

Announcing the launch of the Coalition for Secure AI (CoSAI) to help securely build, deploy, and operate AI systems to mitigate AI-specific security risks.

June 21, 2024

SECURITY

Enhancing AI Security Incident Response Through Collaborative Exercises

2 min read

Take-aways from a tabletop exercise led by CISA's Joint Cyber Defense Collaborative (JCDC), which brought together government and industry leaders to enhance our collective ability to respond to AI-related security incidents.

May 31, 2024

SECURITY

Introducing the Open Supply-Chain Information Modeling (OSIM) Technical Committee

4 min read

OSIM is a great advancement towards a more secure and resilient supply chain ecosystem.