John Lambert

CTO Of The CISO Organization, Security Fellow, Corporate Vice President

Redmond, Washington, United States
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts

Summary

👤
Senior
🎓
Top School
John Lambert is a seasoned security executive and engineer who serves as CTO of the CISO organization and Corporate Vice President at Microsoft, overseeing research and intelligence across Defender, Sentinel, M365 Compliance and MSTIC. He founded and led the Microsoft Threat Intelligence Center, building adversary-focused hunting, incident response, and tooling capabilities that shaped Microsoft’s modern threat posture. With a career spanning product security, network defense and security science at Microsoft—and an early software engineering background at IBM—he blends deep technical rigor with programmatic leadership. An active practitioner in threat detection, he contributes to notable open-source projects such as the ransomware vaccine Raccine and YARA signature repositories, highlighting hands-on malware and IOC development. Based in Redmond, he pairs strategic vision with field-proven engineering, and away from work he is an avid hiker and outdoorsman.
code9 years of coding experience
job24 years of employment as a software developer
bookBachelor of Science (BS) Computer Science, Bachelor of Science (BS) Computer Science at Tulane University
github-logo-circle

Github Skills (26)

c-language10
wp-api10
memory-management10
eventlog10
winapi10
c1110
security10
c1710
threat-intelligence10
malware10
error-handling10
ws-api10
cprogramming-language10
yara10
anti-malware10

Programming languages (11)

C#PowerShellC++CVisual BasicNimJavaScriptHTML

Github contributions (5)

github-logo-circle
Neo23x0/Raccine

Oct 2020 - Nov 2020

A Simple Ransomware Vaccine
Role in this project:
userSecurity Engineer
Contributions:48 commits, 27 PRs, 33 comments in 1 month
Contributions summary:John contributed to the `raccine` project, a ransomware vaccine, by enhancing its detection capabilities. Their commits focused on adding checks for various ransomware-related activities, specifically targeting processes known to be involved in shadow copy manipulation. They also integrated Windows Event logging, enabling the capture of Raccine events for SIEM integration and rule creation. Furthermore, the user addressed compiler warnings, improved logging settings, and incorporated support for GPO override.
vaccineransomwareinfosecmalwarethreat-intelligence
Neo23x0/signature-base

Feb 2018 - Nov 2020

YARA signature and IOC database for my scanners and tools
Role in this project:
userSecurity Engineer
Contributions:24 commits, 21 PRs, 5 comments in 2 years 9 months
Contributions summary:John's contributions primarily involve creating and updating YARA rules within the `signature-base` repository. They are focused on identifying and detecting malicious activity, including reverse shells, PowerShell payloads, and exploits targeting vulnerabilities like CVE-2017-10271 and in-office macro-based techniques. The user also develops rules to detect suspicious MacOS launch agent configurations and various malicious XLL add-ins, demonstrating a strong focus on threat intelligence and malware analysis. Their work contributes directly to enhancing the repository's ability to identify and classify threats.
databaseyarasignatureyara-rulesioc
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.
Request Free Trial