Yonatan Zunger
Yonatan Zunger — Microsoft security leader; bylined author of the 2026-02-03 Microsoft Security Blog post [[microsoft-sdl-evolving-security-practices|Microsoft SDL: Evolving Security Practices for an AI-Powered World]] that announced the explicit extension of Microsoft SDL to AI workloads. The single-author byline on a major framework-extension announcement signals significant editorial weight at the Microsoft Security organization.
Stub
Public biographical detail beyond the Microsoft Security Blog author byline is not transcribed here. Prior public record (commonly cited) describes Zunger as a long-tenured trust / privacy / identity engineering leader with prior roles at Google (Distinguished Engineer for privacy and identity) and other platforms. Confirm bio details against a primary source before adding them to this page. Pending: official Microsoft bio, role title, team affiliation within Microsoft Security (Cybersecurity organization vs. RAI org), other Microsoft Security Blog authorship.
Surfaced contributions on this wiki
- 2026-02-03 — Microsoft SDL: Evolving Security Practices for an AI-Powered World. Strategic preamble announcing six SDL-for-AI focus areas (threat modeling, observability, memory protections, agent identity & RBAC, model publishing, shutdown mechanisms) and six operating pillars (research, policy, standards, enablement, cross-functional collaboration, continuous improvement). Anchors the “SDL is a way of working, not a checklist” framing for the wiki’s secure-SDLC framework-stack thesis.
Why this entity appears
Yonatan Zunger’s single-author byline on a major secure-SDLC framework-extension post is itself signal — Microsoft routinely publishes Security Blog posts under multi-author or organizational bylines; a single-author strategic post indicates the named individual carries weight on the framework. The wiki tracks him as the named author for the 2026 SDL-for-AI announcement and as a likely future byline on the promised per-area follow-up posts.
See also
- Microsoft — current affiliation
- Microsoft Secure Development Lifecycle — the framework his 2026 post extends
- the 2026-02-03 announcement paper