This article was accepted into the corpus but its outbound wikilinks were never NER-processed — typical at the deepest BFS hop or when the run's entity cap was reached. No expansion funnel to show.
| Katie Moussouris | |
|---|---|
| Name | Katie Moussouris |
| Occupation | Computer security researcher, consultant |
| Known for | Vulnerability disclosure, bug bounty programs, cybersecurity policy |
Katie Moussouris is an American computer security researcher and policy advisor known for pioneering vulnerability disclosure and bug bounty programs and for consulting on cybersecurity policy for public and private sector organizations. She has advised technology companies, standards bodies, and government agencies on vulnerability management, incident response, and secure development lifecycle practices. Moussouris's work spans industry, nonprofit, and intergovernmental engagement, influencing debates in vulnerability coordination, cyber norms, and software assurance.
Moussouris grew up in a period influenced by rapid advances in computing and networking alongside figures such as Tim Berners-Lee, Linus Torvalds, Dennis Ritchie, Margaret Hamilton, and Grace Hopper, and pursued studies that connected to the cultures represented by Massachusetts Institute of Technology, Stanford University, Carnegie Mellon University, University of California, Berkeley, and Harvard University. Her formative experiences intersected with communities around DEF CON, Black Hat (conference), USENIX, ACM, and IEEE, shaping an approach resonant with practitioners at Microsoft Corporation, IBM, Google, Apple Inc., and Oracle Corporation. During her education and early career she engaged with open source projects and standards efforts involving The Linux Foundation, OpenSSL, Apache Software Foundation, Mozilla Foundation, and W3C.
Moussouris’s professional trajectory includes roles at major technology firms, security vendors, and advisory organizations influenced by industry leaders such as Microsoft Corporation, Symantec Corporation, Google, Facebook, Intel Corporation, and Cisco Systems. At corporate and startup workplaces she collaborated with teams informed by practices from NTT Security, CrowdStrike, FireEye, Check Point Software Technologies, and Tenable, Inc.. Her career involved interactions with research and disclosure communities represented at DEF CON, RSA Conference, Black Hat (conference), OWASP, and SANS Institute, and with standards and policy entities like IETF, ISO, NIST, ENISA, and ICANN. Moussouris has also engaged with venture and advisory ecosystems including Andreessen Horowitz, Y Combinator, Kleiner Perkins, Techstars, and Accel Partners.
Moussouris is recognized for leading early vulnerability disclosure and bug bounty initiatives comparable to programs at Microsoft Corporation, Google, Facebook, Apple Inc., and HackerOne. She advocated disclosure practices drawing on coordination models used by CERT/CC, US-CERT, MITRE Corporation, CVE, and NVD and promoted payment and policy frameworks similar to those from Bugcrowd and Synack. Her writing and talks have cited coordination precedents from Vulnerability Coordination Committee, FIRST, ISO/IEC 29147, ISO/IEC 30111, and regulatory conversations involving European Commission, US Department of Homeland Security, UK National Cyber Security Centre, and ENISA. Moussouris has participated in community events with leading security researchers such as Charlie Miller, Chris Valasek, Marc Maiffret, HD Moore, and Kevin Mitnick, emphasizing processes echoed in publications from ACM, IEEE Security & Privacy, and Communications of the ACM.
Moussouris has consulted for governments and intergovernmental bodies on vulnerability disclosure, cyber norms, and offensive cyber policy, engaging with organizations like United Nations, NATO, European Union, United States Department of Defense, National Security Agency, and Department of Homeland Security. Her advisory roles intersected with standards and public policy actors such as NIST, ISO, ENISA, ICANN, and OECD, and with legislative and oversight institutions including the United States Congress, European Parliament, UK Parliament, House Committee on Oversight and Reform, and Senate Armed Services Committee. She has contributed to dialogues alongside diplomats, policymakers, and technologists from Estonia, Israel, Germany, France, and Japan on topics related to Tallinn Manual, Budapest Convention on Cybercrime, UN GGE, OSCE, and norms for state behavior in cyberspace.
Moussouris has received industry and civic recognition reflective of contributions to cybersecurity policy and practice, in company with awardees from institutions like Electronic Frontier Foundation, MIT Technology Review, Forbes, WIRED, and SC Magazine. Her thought leadership has been cited alongside recipients of honors from ACM, IEEE, Women in CyberSecurity, Female Founders Fund, and Harvard Kennedy School programs, and she has been profiled by media outlets including The New York Times, The Washington Post, The Guardian, BBC, and Reuters. Institutional acknowledgments have connected her work to initiatives at Microsoft Research, Google Research, Harvard University, Stanford University, and Carnegie Mellon University.
Category:Computer security specialists Category:American cybersecurity experts