= Omkhar Arasaratnam =

Omkhar Arasaratnam
- Occupation: Computer scientist, Cybersecurity executive

Omkhar Arasaratnam is a Canadian-American computer scientist and cybersecurity executive whose work has focused on cybersecurity, open-source software security and software supply chain risk. He served as general manager of the Open Source Security Foundation (OpenSSF), a Linux Foundation initiative, from May 2023 to September 2024. In this capacity, he participated in industry and government discussions on securing widely used open-source infrastructure, including meetings convened by the White House and the United Nations.

Since October 2024, Arasaratnam has served as distinguished engineer for security at LinkedIn.

== Career ==

Arasaratnam began his career at IBM, where he contributed to open-source software projects as a maintainer for Gentoo Linux on the PPC64 architecture and as a contributor to the Linux kernel. He later held security engineering and leadership roles at financial institutions and technology companies, including Deutsche Bank, JPMorgan Chase, and Google.

In May 2023, Arasaratnam was appointed general manager of the Open Source Security Foundation, succeeding Brian Behlendorf. OpenSSF coordinates industry efforts to improve the security of widely deployed open-source software used in commercial and government systems. As general manager, Arasaratnam coordinated foundation initiatives and represented OpenSSF in discussions with technology companies and public-sector stakeholders.

Arasaratnam departed OpenSSF in September 2024 and joined LinkedIn as distinguished engineer for security, where his work has focused on software supply chain risk and platform security.

== Public commentary and incident response ==

In 2024, Arasaratnam was quoted by multiple media outlets regarding a supply chain compromise discovered in XZ Utils, a data compression utility widely used in Linux distributions.

In these interviews, he discussed structural risks associated with volunteer-maintained infrastructure and the challenges of detecting long-term, socially engineered attacks on open-source projects. In technical interviews, he analyzed the attacker's methodology and commented on the limitations of existing defensive tools.

Following the incident, Arasaratnam and OpenJS Foundation executive director Robin Bender Ginn co-authored a public warning that similar social engineering attempts had targeted JavaScript projects, urging maintainers to scrutinize requests for elevated access from unknown contributors.

== Open-source security advocacy ==

In August 2023, Arasaratnam commented on the White House's National Cyber Workforce and Education Strategy, telling Nextgov/FCW that the strategy's focus on education and career placement would help address cybersecurity talent gaps.

In September 2023, Arasaratnam participated in the Secure Open Source Software Summit at the White House, a two-day meeting convening approximately 90 government officials and private sector executives to discuss open-source security.

In October 2023, Arasaratnam spoke at the Linux Foundation's Open Source Summit Europe, where he commented on proposed regulatory approaches to open-source software security in the European Union, arguing that the Cyber Resilience Act failed to account for how individual contributors and foundations support the open-source ecosystem.

In July 2024, Arasaratnam addressed the United Nations OSPOs for Good conference at UN Headquarters in New York, discussing how open-source contributors could support the Sustainable Development Goals.

In October 2024, Arasaratnam delivered a keynote address at SecTor, Canada's largest cybersecurity conference, presenting on the XZ Utils backdoor as a case study in software supply chain security.

== Academic and philanthropic work ==

Arasaratnam is a senior fellow at the NYU Center for Cybersecurity and serves on the NYU Cyber Fellows Advisory Council.

In 2021, Arasaratnam and his wife established the S&K Scholarship at New York University Tandon School of Engineering, supporting graduate students pursuing cybersecurity studies.
