OWASP 2026 Global Board Elections

Bio
I am a cybersecurity and software engineering professional with more than 25 years of experience spanning software development, application security, product security, and international standards development. I'm a Principal Consultant in Product Security at CyberCX. As well as being one of the project leaders for OWASP CycloneDX, and an elected member of the Ecma International Executive Committee.
My journey with OWASP began back in my software development years. From leveraging OWASP guidance and tools right through to helping lead one of OWASP's flagship projects, CycloneDX. I helped grow the project from a small opensource initiative into a globally adopted international standard used by governments, critical infrastructure providers, technology vendors, and opensource communities around the world. Along the way, I have worked closely with contributors, standards bodies, industry leaders, and public sector organisations to advance software transparency and software supply chain security.
Throughout my career, I have balanced hands on technical work with strategic leadership. I have led product security initiatives, grown and managed teams, performed hands on technical software engineering and security work, and helped organisations improve the security of products used by millions of people. I remain an active practitioner who understands both the challenges faced by individual contributors and the broader strategic needs of organisations and communities.
As a candidate for the OWASP Board, I am committed to strengthening OWASP's role as the world's most influential open security community. I believe OWASP succeeds when it empowers volunteers, supports project and chapter leaders, fosters a welcoming and inclusive culture, and delivers practical resources that help developers, defenders, and organisations build more secure software.
OWASP has had a profound impact on the security industry and on my own professional journey. I would be honoured to help guide the foundation's future, support its members and volunteers, and contribute to its mission of making the worlds software more secure for everyone.
Questions
What unique strategic goal do you intend to bring on board, if you are elected?
My strategic goal is to help increase OWASP's influence and visibility as the leading global authority on software security.
OWASP already produces world class projects, guidance, and standards. I believe the next opportunity is to further expand their adoption and impact across industry, standards bodies, and educational institutions worldwide. Drawing on my experience co-leading the OWASP CycloneDX Standard, and participating in international standards development through Ecma International, I have seen firsthand how community driven initiatives can shape industry practices at a global scale.
By expanding OWASP's international reach, and industry presence, we can increase the value delivered by the Foundation and amplify the impact of the community's work.
What is your vision for OWASP over the next three to five years?
My vision for OWASP over the next three to five years is for it to strengthen its position as the world's leading voice on software security, while remaining the home of the industry's most trusted opensource security projects and communities.
What makes OWASP unique is its grassroots, community driven model. Anyone, anywhere in the world, can contribute, lead, and help shape the future of software security. I want to see OWASP continue to invest in and empower that community while expanding its influence with industry, standards bodies, and academia.
What contributions have you personally made to OWASP or other open source projects?
I have made numerous contributions to opensource projects over the years. Some small, some big.
My biggest contributions would be to the OWASP CycloneDX project. When I started contributing to the project it wasn't even an OWASP project. I contributed code including new features and tool implementations. Worked on developing the specification. As well as creating the project's governance framework that supported it in the transition from a small opensource project to a large globally adopted standard.
I'm also involved in the development of open international standards in my role on the Executive Committee of Ecma International, of which OWASP is a member organisation.
What strategies would you implement to increase community engagement and participation in OWASP?
Internally, I believe there is an opportunity to improve how the Foundation and Board communicate with members, project leaders, and chapter leaders, ensuring the community has greater visibility into priorities, initiatives, and opportunities to contribute.
Externally, I want to help position OWASP as an even more influential voice in shaping software security practices worldwide. By building stronger relationships with standards organisations, educational institutions, and industry leaders, we can increase the adoption and impact of OWASP projects, guidance, and educational resources while creating new opportunities for the community to contribute to initiatives that shape the future of software security.
What will be your efforts to ensure OWASP continues to be a centerpiece in software security?
I see advocacy as a key part of ensuring OWASP remains a centerpiece in software security. That means championing the work of our projects, chapters, and contributors, and helping connect their efforts to broader opportunities. As well as raising OWASP's profile with industry, governments, regulators, standards bodies, and academia so that OWASP's guidance, projects, and expertise continue to influence how secure software is built around the world.