Helen Oakley

Co-Founder

Toronto, Ontario, Canada18 yrs experience
Most Likely To SwitchAI ML Practitioner

Key Highlights

  • Leader in AI security and software supply chain.
  • Pioneered open-source initiatives in AI security.
  • Recognized among top women in cybersecurity.
Stackforce AI infers this person is a leader in AI security and software supply chain management.

Contact

Skills

Core Skills

Ai SecurityLeadershipSoftware Supply Chain SecuritySecurity RegulationsSecure Software Development LifecycleSoftware SecurityQuality AssuranceSecurity TestingProject ManagementRelease ManagementAi Systems GovernanceAi Risk & Failure AnalysisAi Supply Chain TransparencyAibomAgentic Ai SecurityAi Threat ModelingAdversarial Ai TestingAi Security Training & ExercisesAi Security Mitigation DesignAi Risk Taxonomy DevelopmentPublic SpeakingOrganizational LeadershipCommunity EngagementAi TransparencyAi Supply Chain SecurityStandards DevelopmentBusiness StrategyCybersecurity Education

Other Skills

Agentic AIAI SBOMSystem ArchitectureArtificial Intelligence (AI)MLSecOpsSoftware Bill of Material (SBOM)People ManagementSoftware TransparencySoftware ArchitectureDevOpsMachine LearningSecurity OperationsSDLCCloud SecurityApplication Security

About

Helen Oakley, CISSP, GPCS, GSTRT, is an executive leader at the intersection of AI, cybersecurity, and enterprise software, driving innovation and resilience where technology, trust, and regulation converge. With a proven record leading multi-million-dollar implementation initiatives across Fortune 500 environments, she has delivered secure and scalable transformations spanning software development, AI adoption, and third-party integration. Beyond the enterprise, Helen leads several of the industry’s most recognized open-source initiatives in AI security. She created the first open-source AIBOM Generator for Hugging Face models and the OWASP Agentic AI CTF (FinBot), pioneering practical ways to bring transparency and accountability to intelligent systems. Helen is a driving force behind AI security initiatives and white papers within the OWASP GenAI Security Project. Her work turns emerging AI risks into practical frameworks, tools, and standards adopted by the industry. Helen’s leadership unites deep technical insight with strategic execution, translating complex security and AI programs into measurable business impact. Recognized as one of the Top 30 Women Entrepreneurs to Watch in 2025 and among Canada’s Top 20 Women in Cybersecurity, she continues to shape how enterprises and innovators alike secure, implement, and scale AI responsibly.

Experience

18 yrs
Total Experience
3 yrs 3 mos
Average Tenure
5 yrs 4 mos
Current Experience

Aelion path

Independent Researcher

Jan 2026Present · 5 mos

  • Conduct independent research on AI systems, governance models, and failure patterns at scale. Focus on early-stage decision points that shape AI risk, accountability, and long-term sustainability, translating research insights into practical frameworks and public thought leadership.
AI Systems GovernanceAI Risk & Failure AnalysisSocio-Technical Systems DesignDecision-Making Under UncertaintyAI Operating Models

Owasp genai security project

4 roles

Creator & Co-Lead, AIBOM Initiative

Dec 2025Present · 6 mos

  • Co-lead the definition and evolution of AIBOM requirements, use cases, and open-source tooling to improve transparency and risk management across AI supply chains.
AIBOMAI Supply Chain TransparencyAI Risk & Compliance EnablementAI Asset Traceability & MetadataStandards MappingCycloneDX+1

Co-Lead and Core Contributor, OWASP Agentic Security Initiative (ASI)

Sep 2025Present · 9 mos

  • Serve as an initiative lead and core team member shaping OWASP’s approach to securing agentic AI systems, including threat modeling, guidance, and community direction. Core contributor for security papers, including OWASP Top 10 for Agentic Applications.
Agentic AI SecurityAgentic AIAI Threat ModelingMulti-Agent System Risk Analysis

Creator & Co-Lead, OWASP Agentic AI CTF (FinBot)

Jul 2025Present · 11 mos

  • Created and co-lead OWASP FinBot CTF, an open-source agentic AI CTF that operationalizes real-world agentic threat scenarios and translates research into hands-on security learning. Adopted by academia and security training programs, with ongoing expansion through new modules.
Adversarial AI TestingAgentic Attack SimulationAI Security Training & ExercisesApplied AI Threat ScenariosOffensive AI Security TechniquesCTF

Co-Author & Co-Lead, Agentic AI Threats & Mitigations Guide

Nov 2024Present · 1 yr 7 mos

  • Co-author and co-lead OWASP Agentic AI guidance defining key agentic AI threats and practical mitigations, helping organizations understand and address emerging agentic risk patterns.
Agentic AI Threat ModelingSecure AI Architecture PatternsAI Security Mitigation DesignAI Risk Taxonomy DevelopmentAI Security Guidance & Frameworks

Sap

9 roles

VP, Software & AI Security

Promoted

Apr 2025Present · 1 yr 2 mos

  • As part of SAP’s Global Security & Cloud Compliance organization, Helen leads the strategy for securing software and AI systems across SAP’s ~€36 billion global business. She drives the implementation of security-by-design across development, CI/CD, and open-source ecosystems supporting about 40,000 engineers worldwide.
  • Helen advances SAP’s AI and agentic AI security initiatives — spanning MLSecOps, trustworthy AI development, and readiness for the EU AI Act and ISO 42001 — ensuring innovation, compliance, and resilience move together. Her leadership shapes how secure and responsible AI is designed and implemented across one of the world’s largest enterprise software portfolios.
LeadershipAgentic AIAI TransparencyAI SecurityAI SBOM

Director of Secure Software Supply Chains and Secure Development

Promoted

Apr 2024Apr 2025 · 1 yr

  • Helen plays a pivotal role in SAP’s Global Security and Cloud Compliance organization, driving strategic initiatives that embed security-by-design and security-by-default principles across SAP’s vast engineering ecosystem. She spearheads the optimization of security processes for thousands of teams through Secure Development and Operations Lifecycle automation and leads efforts to secure SAP’s software supply chains, including safeguarding CI/CD pipelines, enhancing open-source security, and advancing AI security with cutting-edge MLSecOps and AI transparency practices. As a recognized leader, Helen directs a team of senior security experts, developers, and architects, ensuring alignment on critical objectives. Her ability to cultivate strong stakeholder relationships and communicate effectively with executive leadership underscores her position as a trusted authority in driving SAP’s security strategy.
LeadershipSystem ArchitectureAgentic AIAI TransparencySoftware Supply Chain SecurityArtificial Intelligence (AI)+7

Lead Security Architect for software supply chain security, SAP Global Security & Cloud Compliance

Feb 2022Apr 2024 · 2 yrs 2 mos

  • Helen Oakley, CISSP, GPCS, GSTRT, is a Lead Security Architect for software supply chain security at SAP - a multi-pillar environment, complex landscapes of technologies and pipelines. She defines the strategy and architecture for software supply chain security, including AI/ML software supply chain and security, defining automation and orchestration of software bill of material (SBOM) across all pipelines and assemblies, leading a team of architects, senior developers and DevOps professionals who implement the solution. Helen directs a team of security professionals to document and implement security requirements for DevSecOps and MLSECOPS, defining the safeguards and open-source & 3rd party software practices to mitigate software supply chain risks across cloud application infrastructure.
Security RegulationsSystem ArchitectureDevOpsSoftware SecurityMachine LearningSecurity Operations+11

Sr. Product Security Architect and Security Standard Owner, SAP Global Security

Promoted

Jul 2021Apr 2024 · 2 yrs 9 mos

  • Product standard security and secure software development and operations lifecycle owner.
  • As part of SAP Global Security, Helen is responsible for defining requirements and controls for SAP’s Secure Software Development & Operations Lifecycle, Product Standard Security and Data Protection. It is accomplished through the tasks and responsibilities that support these 3 main pillars:
  • Translate legal requirements and industry standards into software and architectural requirements, contributing into a cross-product architecture at SAP, provide direction to product / development teams to implement the correct technical capabilities
  • Define and continuously improve SAP’s secure software development & operations life cycle that guides development teams to apply an appropriate level of security measures, including mitigation of software supply chain risks
  • Provide training and consulting to the product / development teams to ascertain their understanding of the data security and data protection product standard requirements are correct, and the technical capabilities will be implemented correctly
JIRASecurity RegulationsSystem ArchitectureThreat ModelingDevOpsSoftware Security+19

Product Security Architect

Promoted

Nov 2020Jul 2021 · 8 mos

  • Collaborating with business and technology stakeholders to define and enhance security solutions based on changing threat and regulatory landscape. Translating business requirements into well-defined architecture guidance for development teams.
Security RegulationsSystem ArchitectureThreat ModelingDevOpsSoftware SecurityMachine Learning+15

Security Product Owner

Jan 2018Nov 2020 · 2 yrs 10 mos

  • Responsible for security of applications across Financial Services portfolio, banking and insurance, at SAP. Responsibilities include but not limited to: data protection and privacy, security assessments, security compliance processes and procedures throughout software development lifecycle, penetration test.
Security RegulationsThreat ModelingSoftware SecurityMachine LearningSecure Software Development LifecycleIoT+13

Security Expert

Dec 2016Jan 2018 · 1 yr 1 mo

  • Applied application security practices to Financial Services solutions, banking and insurance applications, ensuring compliance, risk mitigation, and secure development practices.
Security RegulationsThreat ModelingSoftware SecurityMachine LearningSecure Software Development LifecycleIoT+13

Security Test Lead

Jul 2015Dec 2016 · 1 yr 5 mos

  • Led security and quality assurance testing efforts, including penetration testing, installation testing, component and process integration testing, upgrade/migration testing, and full system validation.
  • Defined test strategies and plans; coordinated test execution across teams; delivered training, reviewed test cases/scripts, and prepared comprehensive test summaries.
  • Conducted manual and tool-assisted penetration testing using tools like Burp Suite and OWASP ZAP; identified software vulnerabilities and designed targeted test attacks.
  • Developed installation and upgrade test strategies based on supported platforms and application dependencies, ensuring smooth deployment for new and existing customers.
  • Designed end-to-end process integration tests by mapping cross-system dependencies and validating successful business flow integration through white-box and black-box testing approaches.
JIRADevOpsTest Strategy & PlanWeb ApplicationsProcess ImprovementQuality Assurance+14

Project, Program & Release Manager

Jan 2014Dec 2016 · 2 yrs 11 mos

  • Planning and executing complex development projects for insurance applications.
  • Responsible for the planning, management and co-ordination of the Release deliverables across teams of on-premise and on-demand (SaaS) web applications; working with SAP technologies such as HANA, NetWeaver, Enterprise Services, SAPUI5 / Fiori
  • Provides release strategy and delivery method based on product vision, architectural design, complex integrations with other SAP components and SAP Product Standards compliance
  • Develops, audits, monitors and enforces established release management and change management processes and policies
  • Acts as the gatekeeper through SDLC, ensuring completeness, consistency and accuracy in policies and operational procedures; assures compliance across SDLC (including security)
  • Develops a common understanding of priorities for multiple complex releases spanning across multiple customer projects; facilitates information to involved teams
  • Provides details on improvements for process areas, such as procedural changes, staff training, technology changes
JIRADevOpsWeb ApplicationsProcess ImprovementSoftware Project ManagementRelease Management+8

A-speakers

Professional Keynote Speaker

Jan 2025Present · 1 yr 5 mos

  • Delivering high-end keynotes on the intersection of AI and cybersecurity, including topics such as agentic AI, software supply chain security, and software transparency. Represented by A-Speakers — an award-winning global speakers bureau known for its focus on growth and exceptional service.
Keynote SpeakingMotivational SpeakingPublic SpeakingArtificial Intelligence (AI)Leadership

Ai integrity & safe use foundation (aisuf)

Founding Partner

Sep 2024Present · 1 yr 9 mos

  • The AI Integrity and Safe Use Foundation (AISUF) is a non-profit organization dedicated to developing an AI transparency framework that empowers organizations to create and acquire secure, resilient, and ethically sound AI systems.
Organizational LeadershipStrategic PartnershipsCommunity EngagementMentoring

Tiebreaker ai

Strategic Advisor, vCISO

Jul 2024Feb 2025 · 7 mos

  • Helping the company navigate the dynamic industry landscape, ensuring innovative approaches and robust security measures.

Cybersecurity and infrastructure security agency

Co-Lead, AIBOM Tiger Team (CISA SBOM Initiatives)

May 2024Jun 2025 · 1 yr 1 mo · United States · Remote

  • Co-lead the AIBOM Tiger Team under Cybersecurity and Infrastructure Security Agency (CISA), driving definition and publication of AIBOM use cases and aligning AIBOM requirements with CycloneDX and SPDX standards to support real-world adoption.

Secureworld

Advisory Council Member

Nov 2023Jun 2025 · 1 yr 7 mos · Toronto, Ontario, Canada

AI Supply Chain SecurityStandards DevelopmentPublic-Private Cybersecurity CollaborationAI Governance & Risk ManagementAIBOMAI SBOM

Security education conference toronto (sector)

Member of the Board of Advisors

Feb 2023Present · 3 yrs 4 mos · Toronto, Ontario, Canada

  • Advisory for SecTor Executive Summit - Canada's Premier CISO Event, regional BlackHat event.

Humint

Advisory Board Member

Feb 2021Present · 5 yrs 4 mos

Siberx

Advisory Board Member

Oct 2019Present · 6 yrs 8 mos · Toronto, Ontario, Canada

Artificial Intelligence (AI)AI TransparencySecurity RegulationsRegulatory GuidelinesSecurity Standards

Leading cyber ladies

Co-Founder

Nov 2018Present · 7 yrs 7 mos · Toronto, Ontario, Canada

  • Co-founded and lead the Toronto chapter of a global community advancing women in cybersecurity. Drive strategy, partnerships, and long-term growth, scaling programs across meetups, education, and mentorship while building strong cross-community and industry collaboration.

Hackstudent

Cybersecurity Teacher and HackStudent Management Team

Oct 2018Dec 2021 · 3 yrs 2 mos · Toronto, Canada Area

  • Providing educational sessions and mentoring in cybersecurity for kids.
Business StrategySecurity StandardsSecurity RegulationsSoftware Supply Chain SecurityArtificial Intelligence (AI)vCISO

Camilion solutions

3 roles

Project & Release Manager

Sep 2012Dec 2013 · 1 yr 3 mos

  • Responsible for the planning, management and co-ordination of the Release deliverables of on-premise and on-demand (SaaS) applications
  • Develops, audits, monitors and enforces established release management processes and policies
  • Acts as the gatekeeper through SDLC, ensuring consistency in policies and operational procedures
  • Develops a common understanding of priorities for multiple complex releases spanning across multiple customer projects
  • Provides details on improvements for process areas, such as procedural changes, staff training, technology changes
Cybersecurity Education

Quality Assurance Lead & DevOps Engineer

Sep 2010Sep 2012 · 2 yrs

  • Team lead for test projects: test planning and daily coordination of activities according to plan; test case review and training
  • Development of test documentation: test plan, test summary / report, test cases; system test scenarios (E2E, including data migration and integration) and other supporting documentation as configuration specs, test matrix and more
  • Test execution: functional, system, regression, white box test, black box test, web services and more; developing scripts for test data; intercepting HTTP requests and responses using Fiddler for test verification
  • Installation, configuration, migration, integration of web application
  • Incident logging with JIRA and analysis
  • Deployment of web application across various technology stack
  • Automation test scripting (TestPartner, NeoLoad)
  • QA process improvements: defining, implementing and documenting new processes, following industry best practices and adjusting to company's needs
  • Participated in hiring process for Quality Analysts and Testers
JIRADevOpsWeb ApplicationsProcess ImprovementSoftware Project ManagementRelease Management+8

Quality Assurance Engineer

May 2008Sep 2010 · 2 yrs 4 mos

  • Development of test documentation: test cases, system test scenarios and other supporting documentation as configuration specs, test matrix and more
  • Test execution: functional, system, installation, configuration, regression, white box test, black box test, web services and more
  • Incident logging and analysis
  • Deployment of web application
  • Automation test scripting
JIRADevOpsTest Strategy & PlanWeb ApplicationsProcess ImprovementQuality Assurance+14

Education

George Brown Polytechnic

Stackforce found 100+ more professionals with Ai Security & Leadership

Explore similar profiles based on matching skills and experience