By NHI Mgmt Group Editorial TeamBased on Oasis Security: “Top 15+1 Identity Pros to Follow on LinkedIn” (May 1, 2026)

TL;DR: A curated list highlights 15 identity and cybersecurity professionals whose work spans IAM, NHI governance, standards, and emerging AI risk, offering practitioners a compact way to track the people shaping current identity debates, according to Oasis Security. The real value is not the list itself but the pattern it reveals: identity security is increasingly cross-domain, and practitioners need wider signal sources to keep pace.


At a glance

What this is: This is a curated list of 15 identity and cybersecurity professionals whose public work spans IAM, NHI governance, standards and emerging AI risk.

Why it matters: It matters because identity programmes are increasingly influenced by cross-domain thinking, and practitioners need to track the people shaping IAM, machine identity and AI risk debates together.


Context

Identity security is no longer a single-track discipline. IAM teams now have to watch machine identity governance, standards work, privileged access, AI risk and security research at the same time, because the boundary between those conversations keeps narrowing.

This article is essentially a signal curation exercise: it highlights practitioners whose public commentary, research and leadership help identity teams track where the field is moving. The useful part is the pattern, not the profile list itself.


Key questions

Q: How should identity teams choose which practitioners to follow for IAM and NHI guidance?

A: Prioritise voices that bridge standards, implementation and operational identity risk rather than staying inside one topic silo. The strongest signal comes from people who can connect human IAM, NHI governance and emerging AI-related access issues. That mix helps teams spot control gaps earlier and avoid building programmes around outdated assumptions.

Q: Why does following NHI-focused practitioners matter for IAM programmes?

A: Because service accounts, workloads and secrets now sit inside the same governance problem as human access. NHI specialists help identity teams think about ownership, inventory, lifecycle and privilege in ways that human-only IAM commentary often misses. That perspective becomes essential once machine identities are operationally material.

Q: What is the difference between human IAM controls and NHI governance?

A: Human IAM is built around people joining, moving roles, and leaving the organisation. NHI governance is built around credentials, workloads, integrations, and software change. That means machine identities need inventory, ownership, rotation, and offboarding tied to technical events, not just HR events or periodic access reviews.

Q: How can identity leaders tell whether their professional network is too narrow?

A: If most of the people you follow speak only about one sub-discipline, you will likely miss shifts at the boundaries between IAM, NHI and AI risk. A narrow network produces blind spots in governance design. A broader network gives you earlier warning when the field’s assumptions start changing.


Technical breakdown

Why cross-domain identity influence matters

Identity governance has become a convergence point for human IAM, NHI management and emerging AI risk. That makes practitioner signal sources more valuable when they bridge architecture, operations, standards and threat analysis rather than staying inside one niche. A leader who only follows human IAM commentary will miss changes in machine identity governance, while an NHI specialist who ignores standards and AI risk will miss the next control gap. The practical question is not who is popular, but whose work helps you connect access, privilege, lifecycle and emerging runtime behaviour.

Practical implication: Build your professional signal set around cross-domain voices that can inform both programme design and operational control decisions.

Standards, research and product experience shape better identity judgement

Several profiles in the article combine standards participation, vendor-side implementation, advisory work and independent research. That mix matters because identity controls are rarely judged well from one vantage point alone. Standards work shows where the control model is heading, field delivery shows where it breaks, and research helps separate real governance issues from marketing language. For practitioners, the value lies in reading across those lenses so that access, federation, privilege and lifecycle decisions are grounded in operational reality, not just abstract policy.

Practical implication: Use a mix of standards, research and implementation voices when evaluating identity architecture and governance changes.

NHI is now part of mainstream identity leadership

The inclusion of NHI-focused practitioners in a broader IAM list is itself a signal. Non-human identity management is no longer a side topic reserved for platform specialists, because service accounts, workloads and secrets now sit alongside human access as core governance assets. That changes how identity teams should think about inventory, ownership, offboarding and privileged access. Once NHI appears in the same conversation as IAM and AI risk, the programme boundary has already moved.

Practical implication: Treat NHI governance as a mainstream identity discipline, not a specialist add-on, when shaping programme priorities and ownership.


NHI Mgmt Group analysis

Cross-domain identity influence is now a control input, not a soft signal. IAM leaders can no longer treat standards contributors, NHI specialists and threat researchers as separate audiences. Their combined output increasingly shapes how organisations define ownership, privilege and lifecycle boundaries. Practitioners should treat curated expert networks as an operational input to governance design, not as professional interest alone.

NHI has crossed from specialist concern into core identity governance. The appearance of NHI-focused practitioners alongside IAM leaders shows that machine identity is now part of the same governance conversation as human access and privileged access. That shift matters because the same lifecycle questions now apply across users, services and workloads. Practitioners should expect ownership, inventory and offboarding discipline to be judged as a single identity programme capability.

Standards literacy is becoming a differentiator in identity leadership. The people worth following are not only those who comment on incidents, but those who help shape or interpret standards and operating models. That matters because identity controls increasingly need to be defensible across audit, architecture and implementation. Practitioners should build their viewpoint from both field experience and standards work if they want governance that survives scrutiny.

AI risk is pulling identity teams toward delegation and trust questions they cannot ignore. Even when a programme is not formally responsible for AI, the access implications of AI-enabled systems are already reaching identity governance. The critical issue is how trust, entitlement and accountability behave when digital actors become harder to classify cleanly. Practitioners should prepare for identity policy to absorb AI-adjacent access questions before the control model is fully settled.

What this signals

Cross-domain identity leaders are becoming more valuable to practitioners than single-topic commentators. The reason is simple: programme risk now sits at the intersection of human IAM, machine identity governance and emerging AI access questions. Teams that widen their signal network are more likely to catch governance shifts before they become operational debt.

NHI should be treated as part of mainstream identity planning. Once machine identity specialists appear alongside IAM and standards voices, the programme boundary has already moved. Practitioners should reflect that shift in ownership models, roadmap prioritisation and audit narratives.


For practitioners

  • Curate a cross-domain signal list Include people who span IAM, NHI, standards, privileged access and AI-adjacent risk so your monitoring is not trapped inside one specialty.
  • Separate commentary from capability Track whether a source adds standards insight, implementation experience or threat analysis, then use that distinction when evaluating guidance.
  • Add NHI voices to identity governance planning Bring machine identity and lifecycle specialists into roadmap reviews when your programme is still framed mainly around human IAM.

Key takeaways

  • The article’s main signal is that identity practice is widening beyond classic IAM into NHI, standards and AI-adjacent risk.
  • The value of the list is not the names alone but the pattern they reveal about where identity governance conversations are heading.
  • Practitioners should broaden the voices they follow so their programmes can react earlier to changes in privilege, lifecycle and trust assumptions.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-10 — Human Use of NHIThe article highlights NHI expertise as part of modern identity leadership and governance.
Recommendation — Include NHI specialists in governance reviews so machine identity issues are not treated as a side topic.
NIST CSF 2.0GV.OC-01 — Organizational ContextThe piece is about how identity leaders should broaden the context they monitor.
GV.RM-01 — Risk Management StrategyThe article is fundamentally about improving how teams spot and interpret identity risk.
Recommendation — Map identity signal sources to organisational context so governance decisions reflect the full risk surface. Use a wider practitioner network to inform risk strategy and detect emerging identity governance issues earlier.

Key terms

  • Identity signal network: The set of practitioners, researchers and standards voices a team follows to understand where identity security is heading. In practice, it is a governance input that helps leaders spot changes in access, privilege, lifecycle and emerging trust patterns before those shifts become control failures.
  • Cross-Identity Governance: A governance approach that links human users, service accounts, bots, and tokens to the resources and actions they can influence. It becomes necessary when AI workflows mix identity types and no single access review view can explain the whole control picture.
  • NHI Governance: NHI governance is the set of policies and controls used to manage non-human identities across their lifecycle. It covers issuance, access scope, monitoring, rotation, and retirement so machine credentials do not become hidden, durable attack paths.
  • Identity Lifecycle Event: A business event that changes a person’s access, obligations, or record status, such as hiring, role change, or offboarding. In HR programmes, these events often drive entitlement changes and evidence requirements, so they need to be governed as part of the identity lifecycle rather than handled as isolated paperwork.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 6, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org