Cyber News / Article / Top 16 cloud security experts you should follow in 2023

Top 16 cloud security experts you should follow in 2023
Handpicked by our research team: The annual list of 16 thought leaders you need on your feed.
Cloud security isn't just about keeping up with change, it's about being part of the conversation. We've asked our talented cloud security researchers at Wiz to share with us, and you, who they look up to in the industry.
Here's who they think you should follow to stay sharp this year:
Amitai Cohen, our Attack Vector Intel Lead, recommendsAnna McAbee, a Senior Solutions Architect, Security at Amazon Web Services (AWS). Anna excels in articulating complex AWS Security concepts through her blog posts and whitepapers on incident response in the cloud, and her regular engagement with the cloud security community is awesome.
Leading Wiz's research on networks,Danielle AminovendorsesClint Gibler. As the head of Security Research in Semgrep and the creator of the‘tl;dr sec’ newsletter, Clint's original research and security insights provide pivotal contributions to the cloud security space.
If you're interested in AWS news and insights,Rotem Lipowitch's pick,Corey Quinn, is the person to follow. Creator of "Last Week in AWS", Corey provides a keen and analytical lens on AWS's developments. His engaging podcast and his commentary on AWS updates make him an invaluable resource.
As Wiz's Threat Detection Lead,Itamar GiladendorsesJohn Lambert, one of Microsoft's leading security gurus. Known for his innovative and influential threat-hunting work, John brings a blend of deep expertise, industry insights, and a forward-thinking approach. His contributions in cyber threat identification and risk mitigation make him a valuable addition to your following list. In addition to his substantial contributions to the cybersecurity world, John also shares captivating photos from his nature excursions. His love for nature gives a refreshing and human touch to his profile, reminding us that there's life beyond the cloud!
Shay Berkovich, our Kubernetes expert, suggestsKelsey Hightower— a well-known Kubernetes and Cloud pioneer and a co-founder of KubeCon. Kelsey describes themselves as a minimalist, advocating for the simplification of processes and removal of unnecessary complexities in cloud operations. A big part of their work nowadays revolves around increasing Kubernetes adoption by simplifying the Kubernetes processes and making it "approachable". Kelsey spoke at numerous conferences on Container and Kubernetes Security, Open-source and even published multiple books. Kelsey's tweets always get tons of attention, and it’s really easy to understand why.
Specializing in app & net security,Oren Oferrecommends following theBishop Foxaccount. While Bishop Fox is an organization, its collective insights on app & net security, especially on innovative projects on Linux/container hacking, make it a must-follow. Bishop Fox's hands-on approach and practical demonstrations are a valuable resource for anyone working in the same space.
Our vulnerability intel researcher,Merav Bar, endorsesMaddie Stone. Maddie’s comprehensive review of 0-days exploited in-the-wild in 2022, presented at Zer0Con 2023, offers deep insights into the latest in the field of cloud security. Her research approach and expertise are sure to enlighten your understanding of the industry.
Scott Piper, who helps customers secure their AWS environments, recommends followingIlya Epshteyn. Ilya works on the Identity team at AWS, and writes about how to use data perimeter concepts to create security guardrails for AWS environments. The data perimeter labs he built are a great resource for a better understanding of how IAM works in combination with resource and network capabilities.
Nir Ohfeld, the researcher behind theBig IAM Challengeand one of the researchers behind vulnerabilities such asChaosDBandOMIGOD, recommends followingAndy Nguyen. His expertise offers valuable insights and updates on container and Linux security, making him a must-read for those interested in staying updated in these areas.
Lior Sonntag, our lateral movement expert, endorsesKarl Fosaaen. As VP of Research at NetSPI and an Azure Security expert, Karl delivers deep insights into Azure Security concepts, including exploiting misconfigurations, vulnerabilities and more. His posts and articles on Azure are valuable resources for an in-depth understanding ofAzure security.
Sagi Tzadik, the researcher behindChaosDB, recommends followingNick Frichettefor his creative and insightful content on cloud security. Nick, with his practical, hands-on approach showcased in his creation 'Hacking the Cloud,’ an encyclopedia of tactics and techniques that offensive security professionals can use in cloud exploitation. His unique, hands-on approach to cloud security is not only enlightening but also incredibly valuable for professionals navigating the complexities of the field.
Hillai Ben Sasson, the researcher who discovered the#BingBangattack vector in Azure Active Directory (AAD) that affected Microsoft’s Bing.com, recommendsJames Kettle. James is a web security expert who specializes in innovative attack techniques such as Request Smuggling and Cache Poisoning. He posts interesting research pieces in the field, as well as useful research tools and Burp extensions. He also posts educational content such as tutorials and demo labs that can be helpful for beginners.
Avigayil Mechtinger, a cloud threat detection expert, highly recommendsChris Doman. Chris's tweets are a rich source of information on cloud forensics, a discipline that covers the collection, analysis, and interpretation of evidence found in the cloud to investigateincident response. His expertise in different aspects ofcloud threats, coupled with his timely sharing of knowledge, makes him a must-follow for anyone wanting to stay on top of the latest trends in cloud forensics.
Barak Sharoni, our GenAI and attack vectors researchers, recommendsMark Ermolov, a researcher from PT Security. Mark has been publishing insightful and forward-thinking content about the Intel CPU, including management engine (ME) and microcode vulnerabilities, offering valuable insights for hardware security researchers. Throughout the years, he successfully established his personal brand as a pioneer in the intel realm of research.
Shir Tamari, the Head of Research at Wiz, recommendsAidan W Steele. Aidan has been a pioneering voice in the cloud-native security space for over five years, consistently proposing new approaches and solutions to complex security problems. His consistent delivery of quality content and innovative thought leadership sets him apart in the industry.
Alon Schindel, our Director of Data & Threat Research, recommendsScott Piper, a cloud security historian known for his obsession with examining the geologic records of AWS SDK commits. In addition to this, Scott is a Threat Researcher at Wiz. He has developed tools such asflaws.cloud, CloudMapper, and Parliament. Furthermore, he is a founding member of the annualfwd:cloudsecconference.
In cloud security, it's all about staying in the loop. By following these experts, you're taking an important step to stay up-to-date, understand industry trends, and keep your organization safe. So grab a coffee, open up Twitter, and start exploring what these incredible thought leaders have to share. Happy learning!
To recap, here's our list of top cloud security voices you should follow in 2023:
Anna McAbee
Clint Gibler
Corey Quinn
John Lambert
Kelsey Hightower
Bishop Fox
Maddie Stone
Ilya Epshteyn
Andy Nguyen
Karl Fosaaen
Nick Frichette
James Kettle
Chris Doman
Mark Ermolov
Aidan W Steele
Scott Piper
P.S. Got any recommendations of your own? We’d love to hear from you! Let us know by tagging us on Twitter:@wiz_io
Enhance software security and supply chain risk management with Wiz's agentless scanning technology for effortless SBOM creation
Our investigation of the security incident disclosed by Microsoft and CISA and attributed to Chinese threat actor Storm-0558, found that this incident seems to have a broader scope than originally assumed. Organizations using Microsoft and Azure services should take steps to assess potential impact.
Gain a deeper understanding of why it's essential to monitor non-standard pods and containers, including static pods, mirror pods, init containers, pause containers, and ephemeral containers within your Kubernetes environment.
Get a personalized demo
©2026Wiz, Inc.
StatusPrivacy PolicyTerms of UseModern Slavery StatementCookie Settings
Related articles
Your Cloud Security Checklist Doesn't Work the Way You Think It Does
4 days ago
Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws
7 days ago
HelmGuard Raises $7.3 Million for Agentic GRC and Security
1 day ago

