Chief Security Officer at Descope.
Most breaches start with a login. I work on the login.
I work on identity for humans and machines: OAuth and OIDC, FAPI 2.0, token exchange, DPoP, workload identity federation, and what “authorized” should mean when the caller is an agent.
I have worked in incident response since 2008, founded IL-CERT, and helped build security teams and programs across startups and global companies.
- verity — signed, SBOM-attested, Wolfi-based container images with FIPS flavors
- opencode-plugin-langfuse — tracing for OpenCode agents
- vscode-acp — Agent Client Protocol in VS Code
- dbot — 1,100+ XSOAR integrations as MCP tools, no XSOAR required
- paseo-plugins — plugins for the Paseo agent orchestrator
- BurpJDSer-ng — Java deserialization for Burp
- Honeycomb — extensible honeypot framework presented at DEF CON 26
I write about identity, security, incident response, and agents at omer.cohen.io/writing.





