About Robert Lackey

Robert Lackey, Product Security Engineer

Robert Lackey is a product security engineer who writes about product security, AI security, threat modeling, offensive-informed defense, and practical security learning.

I focus on the parts of security that help engineering teams make better decisions while software is still being shaped: secure design, threat modeling, code review, cloud security, AI security, vulnerability research, and clear risk communication.

My public writing is intentionally practical. I am interested in methods people can reuse, not private implementation details. That means learning paths, review patterns, communication habits, and security judgment that can help teams build safer software without exposing employer, customer, or project-specific information.

What I Write About

  • Product security programs that partner with engineering instead of acting as a late gate.
  • Threat modeling that finds trust boundaries, risky assumptions, and decisions worth changing early.
  • Code review that traces from sensitive operations back to input, authority, and evidence.
  • Offensive practice that helps defenders reason about real product behavior.
  • AI-assisted security work that uses models as leverage while keeping human judgment in charge.

Public Writing

I have written for Dark Reading, TechRadar Pro, and the Cribl blog on threat hunting, hands-on exploitation, product security, and practical security judgment.

Start with my published writing, the product security manifesto, or the Product Security For Beginners guide.

Where To Find Me

The best places to connect are LinkedIn and GitHub. My external author pages include Dark Reading and Cribl.