About Katie Moussouris
Born 2000. Katie Moussouris is a writer, entrepreneur, security researcher, CEO and security hacker, known for Bug bounty program and Vulnerability disclosure.
Katie Moussouris is an American computer security researcher, entrepreneur, and pioneer in vulnerability disclosure. She is the founder and CEO of Luta Security.
After early work in systems administration at MIT and penetration testing at and @stake, Moussouris established Microsoft's bug bounty program. She was involved in creating the U.S. Department of Defense's "Hack the Pentagon" initiative, the first federal government bug bounty program to identify security vulnerabilities. She previously served as Chief Policy Officer at HackerOne, a vulnerability disclosure company based in San Francisco, California.
Biography Moussouris was born in Boston. At eight years old, Moussouris taught herself to program BASIC on a Commodore 64 that her mother bought her. She was the first girl to take AP Computer Science at her high school. She was active within the West Coast hacker scene and formally joined @stake as a penetration tester in 2002 by invitation of Chris Wysopal.
Symantec Moussouris joined Symantec in October 2004 when they acquired @stake. While there, she founded and managed Symantec Vulnerability Research in 2004, which was the first program to allow Symantec researchers to publish vulnerability research. The program has coordinated the response to several significant vulnerabilities, including Dan Kaminsky's DNS flaw, and has also investigated bugs in third-party software affecting Microsoft customers (subsequent examples of this include Google's Project Zero).
From September 2010 until May 2014, Moussouris was the Senior Security Strategist Lead at Microsoft, where she ran the Security Community Outreach and Strategy team for Microsoft as part of the Microsoft Security Response Center (MSRC) team. She instigated the Microsoft BlueHat Prize for Advancement of Exploit Mitigations, which awarded over $260,000 in prizes to researchers at BlackHat USA 2012. At the time, the grand prize of $200,000 was the largest bounty offered by a software vendor. She also created Microsoft's first bug bounty program, which paid over $253,000 and received 18 vulnerabilities over the course of her tenure.
ISO vulnerability disclosure standard
Moussouris has helped edit the ISO/IEC 29147 document since around 2008. In April 2016, ISO made the standard freely available after a request from Moussouris and the CERT Coordination Center's Art Manion.
HackerOne In May 2014, Moussouris was named the Chief Policy Officer at HackerOne, a vulnerability disclosure company based in San Francisco, California. In March 2016, Moussouris was directly involved in creating the Department of Defense's "Hack the Pentagon" pilot program, organized and vetted by HackerOne, the federal government's first bug bounty program.
Moussouris followed up the Pentagon program with "Hack the Air Force". HackerOne and Luta Security are partnering to deliver up to 20 bug bounty challenges over three years to the Defense Department.
Luta Security In April 2016, Moussouris founded Luta Security, a consultancy to help organizations and governments work collaboratively with hackers through bug bounty programs.
New America fellow Between 2015 and 2017, Katie Moussouris served as a Cybersecurity Fellow at New America, a U.S.-based think tank.
Wassenaar Arrangement amendment In 2013, the Wassenaar Arrangement on Export Controls for Conventional Arms and Dual-Use Goods and Technologies was amended to include "intrusion software". Moussouris wrote an op-ed in Wired criticizing the move as harmful to the vulnerability disclosure industry due to the overly-broad definition and encouraged security experts to write in to help regulators understand how to make the right changes. She was invited as a technical expert to directly assist in the US Wassenaar Arrangement negotiations, and helped rewrite the amendment to adopt end-use decontrol exemptions based on the intent of the user.
Exploit labor market research Moussouris was a visiting scholar at the MIT Sloan School of Management and affiliate researcher at the Harvard Belfer Center for Science and International Affairs, where she conducted economic research on the labor market for security bugs. She coauthored a book chapter on the first system dynamics model of the vulnerability economy and exploit market, published by MIT Press in 2017.
Congressional testimony In 2018, Moussouris testified in front of the U.S. Senate Subcommittee on Consumer Protection, Product Safety, Insurance, and Data Security about security research for defensive purposes.
In 2021, Moussouris testified in front of the U.S. House Committee on Science, Space, & Technology about improving the cybersecurity of software supply chains.
Anuncia Donecia Songsong Manglona Lab for Gender and Economic Equity In 2021, Moussouris donated $1 million to found the Anuncia Donecia Songsong Manglona Lab for Gender and Economic Equity, at Penn State Law, named after her mother. The “Manglona Lab” will start with a gender equity litigation clinic intended to address workplace financial discrimination while promoting economic equity under the law.
Awards In 2014, SC Magazine named Moussouris to its "Women in IT Security" list. She was also named as one of "10 Women in Information Security That Everyone Should Know," and the "One To Watch" among the 2011 Women of Influence awards. In 2018 she was featured among "America's Top 50 Women In Tech" by Forbes.
Presentations
Publications
Microsoft lawsuit In September 2015, Moussouris filed a discrimination class-action lawsuit against Microsoft in federal court in Seattle. She alleged that Microsoft hiring practices upheld a practice of sex discrimination against women in technical and engineering roles with respect to performance evaluations, pay, promotions, and other terms and conditions of employment.
Don’t just read it —
keep it.
Full-length biographies made to live with: read them, listen on the way to work, watch them tonight.
- E-book
- Audio
- Video
Instant download · yours to keep · every purchase keeps this site free
Important facts
People in Katie Moussouris's life
Named in this biography and alive at the same time
Contemporaries
People whose lives overlapped Katie Moussouris's
Frequently asked questions
Who is Katie Moussouris?
Computer security expert
When was Katie Moussouris born?
Katie Moussouris was born in 2000.
What is Katie Moussouris's occupation?
Katie Moussouris is a writer, entrepreneur, security researcher, CEO and security hacker.
What is Katie Moussouris known for?
Katie Moussouris is known for Bug bounty program and Vulnerability disclosure.
Sources & further reading
Cite this page
APA: Biography.guide. (2026). Katie Moussouris. https://biography.guide/katie-moussouris/
MLA: "Katie Moussouris." Biography.guide, https://biography.guide/katie-moussouris/.
Chicago: "Katie Moussouris." Biography.guide. https://biography.guide/katie-moussouris/.
Data last updated: 2026-09-26 · Spot an error? Report a correction.
Page generated 2026-09-27 05:15 UTC