diff --git a/elections/OpenSSF-TAC-GB-Nomiations-2024.md b/elections/OpenSSF-TAC-GB-Nomiations-2024.md index ca5c8acd..9af97ad3 100644 --- a/elections/OpenSSF-TAC-GB-Nomiations-2024.md +++ b/elections/OpenSSF-TAC-GB-Nomiations-2024.md @@ -90,4 +90,26 @@ practices. I also am a founding member of the Sigstore TSC where we have built a As part of the OpenSSF TAC, I would continue to bring a breadth of experience and industry & academic connections to bear to help accelerate the impact of the various working groups. I am eager to support the OpenSSF's continued growth as both a forum for evangelizing best practices and as an sponsoring organization for projects that are laser-focused on helping OSS communities and users improve their security posture. +
+
+Company: Intel +
+
+
+LinkedIn +
+Her main contributions to OpenSSF have been through the SCI WG. Since 2020, she has helped develop and promote the SLSA framework as a SIG member and OpenSSF Tech Talk panelist. She also co-led a new SLSA workstream enabling trusted hardware for enhanced build integrity. As a core maintainer for the CNCF in-toto project on supply chain attestation, she brought insights and connections from other areas of OSS. She will work on opportunities for fostering closer collaboration with CNCF communities via the OpenSSF TAC. As Governing Board chair of both CNCF and OpenSSF, I'll work closely with her to make this a reality. +
+She is eager to contribute to newer OpenSSF initiatives in 2024. The holistic best practices of the Security Toolbelt strongly align with my research approach. The DEI WG’s work to create a community in which underrepresented folks feel empowered to contribute their ideas is vital. Understanding the impact of emerging areas like GenAI on OSS security and developing suitable solutions are interesting challenges for the AI/ML Security WG. +
+While these initiatives each cover very distinct topics, she believes they are all crucial for achieving long-term OSS security. Driving work that ensures all sectors are ready to tackle the big supply chain problems of today and tomorrow is why she seeks to join the OpenSSF TAC. +
-Company: New York University
+Company: TestifySec
+John's engagement with OpenSSF began with his contributions to Project Sigstore. He has since actively contributed to the SBOMit project, Supply Chain Integrity (SCI) Working Group, SCI Positioning SIG, the SLSA Specification, and the Security Toolbelt. Beyond OpenSSF, he maintains Witness and Archivista, sub-projects of in-toto, under the CNCF. His role in the CNCF TAG Security Supply Chain Security Working Group further showcases his commitment to this domain. +
+With extensive experience in software engineering and management, John has built open-source and commercial products from scratch. This experience equips him with vital skills for the TAC role, including community building, mentorship, feedback integration, problem analysis, and effective communication with stakeholders. John led the initial development of supply chain security features for VMware's Tanzu Application Platform and currently serves as the Director of Open Source at TestifySec, focusing on enabling supply chain security for all.
-I'm a big believer in open source and in the free exchange of ideas. I don't think any organization or group has a monopoly on good ideas and I think that all should be treated fairly and equally. I believe that a greater representation for vendor-neutral, security-focused voices in the OpenSSF will strengthen the TAC and the OpenSSF overall. +John’s blend of practical experience, active contributions to projects, and experience in supply chain security make him an ideal candidate for the TAC, ready to contribute to OpenSSF’s mission.
-Company: TestifySec
+Company: Ericsson
-LinkedIn -
-John's engagement with OpenSSF began with his contributions to Project Sigstore. He has since actively contributed to the SBOMit project, Supply Chain Integrity (SCI) Working Group, SCI Positioning SIG, the SLSA Specification, and the Security Toolbelt. Beyond OpenSSF, he maintains Witness and Archivista, sub-projects of in-toto, under the CNCF. His role in the CNCF TAG Security Supply Chain Security Working Group further showcases his commitment to this domain. -
-With extensive experience in software engineering and management, John has built open-source and commercial products from scratch. This experience equips him with vital skills for the TAC role, including community building, mentorship, feedback integration, problem analysis, and effective communication with stakeholders. John led the initial development of supply chain security features for VMware's Tanzu Application Platform and currently serves as the Director of Open Source at TestifySec, focusing on enabling supply chain security for all. -
-John’s blend of practical experience, active contributions to projects, and experience in supply chain security make him an ideal candidate for the TAC, ready to contribute to OpenSSF’s mission." +
+As a member of the OpenSSF TAC, I will commit my time and expertise to facilitate and enable our Technical Initiatives - to make them, and the OpenSSF as a whole, successful. This means building on top of the excellent work of refining community processes done by the current TAC. With this solid foundation in place, I want to help the OpenSSF to enter a new phase, which is focusing on broad adoption of our work - both in open source communities as well as in end user organizations. Working in an OSPO, my role is to bridge between groups and facilitate collaboration - and this is what I want to bring to the OpenSSF TAC.