CTO Of The CISO Organization, Security Fellow, Corporate Vice President
Redmond, Washington, United States
Join Prog.AI to see contacts
Join Prog.AI to see contacts
Summary
👤
Senior
🎓
Top School
John Lambert is a seasoned security executive and engineer who serves as CTO of the CISO organization and Corporate Vice President at Microsoft, overseeing research and intelligence across Defender, Sentinel, M365 Compliance and MSTIC. He founded and led the Microsoft Threat Intelligence Center, building adversary-focused hunting, incident response, and tooling capabilities that shaped Microsoft’s modern threat posture. With a career spanning product security, network defense and security science at Microsoft—and an early software engineering background at IBM—he blends deep technical rigor with programmatic leadership. An active practitioner in threat detection, he contributes to notable open-source projects such as the ransomware vaccine Raccine and YARA signature repositories, highlighting hands-on malware and IOC development. Based in Redmond, he pairs strategic vision with field-proven engineering, and away from work he is an avid hiker and outdoorsman.
9 years of coding experience
24 years of employment as a software developer
Bachelor of Science (BS) Computer Science, Bachelor of Science (BS) Computer Science at Tulane University
Contributions:48 commits, 27 PRs, 33 comments in 1 month
Contributions summary:John contributed to the `raccine` project, a ransomware vaccine, by enhancing its detection capabilities. Their commits focused on adding checks for various ransomware-related activities, specifically targeting processes known to be involved in shadow copy manipulation. They also integrated Windows Event logging, enabling the capture of Raccine events for SIEM integration and rule creation. Furthermore, the user addressed compiler warnings, improved logging settings, and incorporated support for GPO override.
YARA signature and IOC database for my scanners and tools
Role in this project:
Security Engineer
Contributions:24 commits, 21 PRs, 5 comments in 2 years 9 months
Contributions summary:John's contributions primarily involve creating and updating YARA rules within the `signature-base` repository. They are focused on identifying and detecting malicious activity, including reverse shells, PowerShell payloads, and exploits targeting vulnerabilities like CVE-2017-10271 and in-office macro-based techniques. The user also develops rules to detect suspicious MacOS launch agent configurations and various malicious XLL add-ins, demonstrating a strong focus on threat intelligence and malware analysis. Their work contributes directly to enhancing the repository's ability to identify and classify threats.
databaseyarasignatureyara-rulesioc
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.