About

About Rock Lambros

I've spent nearly three decades in technology and security, most of it with the pager on. I was the most senior information security leader at MarkWest through its ~$20 billion combination with MPLX and Marathon, and that is where I learned what security looks like when the stakes are a real company and a real balance sheet.

These days I advise. Boards and executive teams bring me in when AI risk stops being theoretical and starts showing up in their diligence, their audits, and their customers' security questionnaires. I help them see which risks threaten the business and build the governance that holds. When the work needs someone in the seat, I take the virtual CISO or fractional Chief AI Officer role, and the deliverable is the same either way: judgment a board can act on.

I help write the standards the field uses. I co-lead the OWASP Top 10 for LLMs, I sit on the core team of the OWASP Agentic Security Initiative, and I co-led the 2026 State of Agentic AI Security and Governance report. I'm a named author on the AAGATE and LAAF papers, and I co-wrote The CISO Evolution with Matthew K. Sharp. The record is the point: the governance I recommend comes from someone who has had to answer for it.

On the technical side, I'm finishing a master's in Applied Data Science and Artificial Intelligence at the University of Denver, expected December 2026, because I would rather understand how the models fail than take a vendor's word for it. I'm a Distinguished Fellow of the Enterprise Risk Quantification Institute, and I hold the CISSP, CCSP, AIGP, and QTE credentials. Home base is Denver.

Some of the writing here starts as an AI-assisted draft. Rock Lambros reworks those drafts and holds editorial responsibility for everything published under his name. What the pipeline does, what it checks, and what it does not check are set out in the authorship policy.

Rock Lambros ziplining in the Colorado high country