Hello, I'm

David Ornstein

Software leader, architect, founder, and standards author with 40+ years building products and platforms people depend on.

scroll

About Me

I've spent my career at the intersection of technology leadership and hands-on engineering — building products, founding companies, shaping standards, leading teams, and securing the software ecosystem at scale.

Across 25+ years at Microsoft, I've been an architect, a compliance director, a Chief of Staff for Trustworthy Computing, and a platform founder. I conceived and led Liquid, the internal platform that automated security compliance for 8,000+ services company-wide. Before that, I architected the “Metro” document format that became the foundation for Office 2007 and XPS, built FlexWiki (1,000+ wikis inside Microsoft), and led engineering compliance programs managing $10M+ annually under the DOJ consent decree.

Before Microsoft, I founded a web-tools startup, helped invent the Rocket eBook as CTO of NuvoMedia (acquired for $200M), and served as President of the Open eBook Forum. I've been a chief architect, a standards chairman, a startup CEO, and an individual contributor — sometimes in the same year.

Most recently I’ve been building Indra — an AI-first app platform inside Microsoft’s CISO organization that gives security engineers the building blocks to turn their expertise into tools the whole organization can use. I lead Indra as its sole human architect, working alongside a team of eight specialized AI agents, each owning a distinct domain: engineering, strategy, security review, storytelling, advocacy, and more. It’s a new model for software development — one architect, a crew of AI collaborators, and the throughput of a full engineering org — and I’m building the proof of it.

I care about building things well, about the craft of software, and about helping the people around me grow.

40+ Professional Years
12+ Patents
3 Companies Founded
8K+ Services Secured
$200M Startup Exit
$250M Largest Budget Managed
150K+ Lines Shipped (Past 60 Days)
50+ Engineers Led

What I Bring

The intersection of deep technical skill, executive-level leadership, a builder’s instinct, and a proven ability to work natively with AI.

AI-Native Super-IC

I’ve proven that one experienced architect, working natively with a crew of specialized AI agents, can sustain a platform-scale software project. Indra — my current project inside Microsoft’s CISO org — is architected, coded, documented, and shipped by me alongside eight AI teammates, each owning a distinct role. This isn’t AI-assisted productivity. It’s a new engineering model.

Security at Scale

Two decades building the systems that keep Microsoft's 8,000+ services secure. I've done compliance from both sides — engineering the tools and setting the policy. I know how to make security a product accelerator, not a bottleneck.

Architect Who Codes

I don’t just draw boxes on whiteboards. From 100K-line C++ codebases to a 150K-line TypeScript platform I built with AI, I’ve written, shipped, and maintained real systems at every scale. I still write and review code daily — architecture grounded in implementation always wins.

Team Builder

I've built engineering teams from zero — at startups, at standards bodies, and inside Microsoft's CISO organization. I hire well, mentor intentionally, and create environments where engineers want to do their best work.

Platform Thinker

The Indra app platform, the Liquid compliance platform, platform-level document APIs and services on Windows, the Rocket eBook ecosystem, the CASE tool framework — I build systems that other teams build on. I understand what it takes to ship reliable, extensible infrastructure that thousands of engineers depend on daily.

Startup to Enterprise

Founded three companies. CTO through a $200M acquisition. Built a platform serving all of Microsoft. I've operated at every scale and know how to match the engineering approach to the stage — from scrappy MVP to enterprise-grade system.

Standards & IP

12+ patents. Chaired ANSI standards committees. Led the Open eBook Forum. When the work needs to cross organizational boundaries through standards, specifications, and patents, I know how to drive consensus and ship.

If you need someone who has built a compliance platform covering 8,000 services, led a $200M-exit startup's engineering org, and can still review a pull request — that's the intersection I live in.

Let's Talk

Career

From Sinclair to Microsoft — a journey through four decades of technology.

Filter by:
13 roles shown

Microsoft · Security & Compliance

2004 – Present (22 yrs)

Two decades leading security assurance, compliance engineering, and platform development at the heart of Microsoft's security organization.

Indra — AI-First Security App Platform

2025 – Present (1 yr)

Principal Security Architect & Project Lead · SIGMA (CISO)

Conceived and built Indra, an AI-first app platform inside Microsoft’s CISO organization. Indra solves a fundamental problem: security knowledge across dozens of CISO domains is fragmented across dashboards, Kusto queries, and engineers’ heads — inaccessible to leaders who need a cross-domain view, and invisible to AI. Indra gives SIGMA engineers the building blocks to turn their security expertise into tools the whole organization can use, and gives deputy CISOs a unified view of posture across verticals.

Lead Indra as its sole human architect, working daily alongside a team of eight specialized AI agents built as GitHub Copilot custom agents — each owning a distinct domain: engineering lifecycle, strategy, security review, narrative, builder advocacy, live demos, and editorial. The platform provides unified security reporting dashboards, a natural-language AI agent over security data, Kusto query integration under real user identity, Power BI embedding with pass-through permissions, an app hosting ecosystem for SIGMA engineers, and a full CI/CD pipeline with multi-environment promotion.

Deployed across dev, pre-production, and production environments. Unified Security Reporting dashboards ready for dCISO adoption. Proving the AI-native super-IC model: one architect sustaining a full platform ecosystem — architecture, code, documentation, strategy, and operations — with the throughput of a full engineering org.

Liquid Compliance Platform

2015 – 2025 (10 yrs)

Principal Engineering Manager / Senior Director · Assurance Engineering

Conceived and led Liquid, Microsoft's internal platform for continuous security assurance. Assembled a 20+ person Deep Engineering team to automate the SDL and compliance processes. Architected automated policy scanners, code compliance pipelines, and a unified dashboard. Co-incubated CodeQL Central for company-wide code analysis. Established the unified Security Bugs S360 KPI tracking vulnerabilities across 1,200+ repos and ~18,000 services. In parallel, drove the full Liquid team — PMs and engineers alike — toward AI-accelerated development practices, demonstrating AI-augmented workflows for design, coding, and analysis that became a model for the broader organization.

Automated SDL compliance for 8,000+ services company-wide. Transformed Microsoft's assurance from manual attestations to data-driven continuous monitoring. Executive acclaim for "incredible impact" on the security engineering ecosystem.

Security Strategy & Assurance

2008 – 2014 (6 yrs)

Chief of Staff · Trustworthy Computing (TwC)

Coordinated security initiatives across Microsoft as right-hand to CVP Scott Charney. Unified assurance programs spanning security reviews, SDL, and privacy across divisions. Shifted focus from pure compliance checklists to proactive security assurance. Managed executive communications and security review follow-ups. Oversaw TwC's reorganization into CELA in 2014.

Drove SDL requirements integration and incident response improvements. Elevated Microsoft's overall security posture and helped evolve the culture from compliance to secure-by-design.

Engineering Policy Compliance

2004 – 2008 (4 yrs)

Director, Compliance Engineering · Engineering Excellence

Ensured engineering teams complied with mandatory policies and DOJ antitrust consent decree requirements. Developed APIscan and CheckPoint Express to verify API compliance. Established company-wide governance processes for policy design, tracking, enforcement, and training. Managed program budget exceeding $10M annually.

Achieved full compliance with DOJ consent decree with no violations. Compliance frameworks became standard engineering workflow across the company.

Microsoft · Windows & Office

1999 – 2004 (5 yrs)

Document technologies, digital publishing, and the cross-company format initiative that shaped Office and Windows.

“Metro” Document Format (XPS)

2001 – 2004 (3 yrs)

Lead Program Manager · Digital Documents, Windows

Office 2007 Ribbon interface — built on the Metro/Open XML format

Led the cross-team initiative to develop the XML Paper Specification — coordinating between Windows and Office teams. Architected and evangelized the format, championed document standards bridging internal and external efforts. Built and led the team that shipped Rights Management Add-on for IE. Filed 12+ patent applications as primary inventor.

Shipped XPS as a core document format in Windows and Office 2007. Strengthened Microsoft's IP portfolio with 12+ granted patents for document and security innovations.

eBooks & FlexWiki

1999 – 2001 (2 yrs)

Architect · Emerging Technologies

Applied startup e-book expertise to Microsoft's digital reading initiatives, contributing to Microsoft Reader architecture and DRM for e-books. Built FlexWiki, a wiki engine in C#/.NET that became one of the most widely used internal collaboration tools.

FlexWiki grew to 1,000+ instances inside Microsoft, fostering knowledge sharing years before tools like Confluence. Later released as open source.

Open eBook Forum

2000 – 2003 (3 yrs)

Open eBook Standardization

2000 – 2003 (3 yrs)

President & Board Member

Led a 100+ member international trade and standards organization. Facilitated collaboration among major tech companies and publishers to create Open eBook Publication Structure — the XML-based standard for eBook content. Defined strategic plans, negotiated organizational partnerships, and managed frameworks for electronic publishing and digital rights management.

Published the first open eBook format specifications, laying groundwork for EPUB — now the dominant open standard for eBooks worldwide.

NuvoMedia, Inc.

1998 – 2001 (3 yrs)

The company that invented the Rocket eBook — one of the world's first dedicated e-readers, nearly a decade before the Kindle.

Rocket eBook & Platform

1998 – 2001 (3 yrs)

Director of Software Development → Chief Technical Officer

Led engineering for the Rocket eBook device software, secure content distribution system, and desktop software. Defined technical strategy and product roadmap. Built the development team and methodology. Promoted to CTO after successful product launch.

Launched the Rocket eBook in 1998 — a 22-ounce handheld holding ~55,000 pages. NuvoMedia acquired by Gemstar in 2000 for $200M, validating the e-book market.

eBookNet.com & Standards

CTO

Led cross-organization team of 12 who developed and launched eBookNet.com, described at launch as the world's largest eBook portal. Co-authored drafts of the Open eBook Publication Structure standard. Managed IP portfolio.

Pragmatica, Inc.

1995 – 1998 (3 yrs)

Internet Publishing Tools

1995 – 1998 (3 yrs)

Founder, President & CEO

Founded and led a web-tools startup building an object-oriented web programming language with SGML syntax (predating XML). Recruited executive team, secured multiple rounds of angel investment, and wrote substantial portions of the ~100,000-line C++ codebase.

Grew to 10 employees in addition to consultants and attracted ~5,000 customers. Established reputation as an innovative technology entrepreneur.

Independent Consultant

1994 – 1995 (1 yr)

Object-Oriented Technology Consulting

Consulting in OO technology, primarily Smalltalk. Clients included OOCL (international shipping) and Lockheed. Services included mentoring, design pattern coaching, and hands-on implementation.

LongView International

1993 – 1994 (1 yr)

Derivatives Trading Systems

Member of Technical Staff · Mountain View, CA

VisualWorks Smalltalk development environment

Architected and built the first versions of LongView's framework-based derivatives trading systems in VisualWorks Smalltalk. Built a direct-manipulation UI with drag-drop, templates, and folders. Designed persistence layer using GemStone object database.

INTERSOLV / Sage Software

1987 – 1993 (6 yrs)

Six years spanning multiple architecture and leadership roles across CASE tools, standards, and corporate technology.

Excelerator II & OS/2 CASE Tools

1990 – 1993 (3 yrs)

Director of Development & Chief Architect · San Jose, CA

OS/2 Warp logo

Led development of Excelerator II, a large OS/2-based CASE tool, and its LAN repository. Managed a bi-coastal team of 12. Built a pioneering interface between relational databases and Smalltalk's world. Created an ER data model compiler producing production-grade relational schemas.

Corporate Technology & M&A

1989 – 1990 (1 yr)

Chief Architect, Corporate Technology · Rockville, MD & Santa Clara, CA

Coordinated technology across INTERSOLV's four development centers. Led technical due diligence for successful acquisitions of Visual Software and Polytron Corp. Built the company's first internet-to-internal email gateway.

CDIF Standards Committee

1988 – 1991 (3 yrs)

Chairman · ANSI/EIA Technical Committee

A CASE tool — the type of software the CDIF standard was designed to interconnect

Chaired the CASE Data Interchange Format standards committee with ~30 voting members and 500+ on its mailing list. Completed and published the first version of the standard, including a two-volume entity-relationship model with over 700 entities and relationships.

PC Architecture & CRTS

1987 – 1989 (2 yrs)

Chief Architect, PC Product Development · Rockville, MD

Responsible for all PC-related technology. Built ER diagramming tools in Smalltalk. Conceived and implemented CRTS, a 100K+ line set of OS extensions and development tools for DOS. Proposed and built a 20-station LAN that eventually grew to span 7 states and 2 countries.

Access Technology Inc.

1986 – 1987 (1 yr)

Multi-User Software R&D

Member of Technical Staff · S. Natick, MA

Developed functional specifications and prototypes for multi-user software products. Led research into text management systems, text databases, and archival systems. Involved in due diligence for multiple acquisitions.

Multimate International Corp.

1984 – 1985 (1 yr)

Word Processor OEM & Porting

Project Manager · E. Hartford, CT

Managed the OEM/International group for Multimate's word-processing system. Ported the product to the Zenith Z-100 (for a US Air Force contract at the Pentagon) and the HP Portable Plus, making it run from ROM cartridges. Contributed to architectural design for next-generation products.

Timex Computer Corp.

1982 – 1983 (1 yr)

Timex/Sinclair 2000 Development

Member of Technical Team · Middlebury, CT

A Timex Sinclair 1000 computer

Worked across hardware and software teams developing the Timex/Sinclair 2000. Designed a memory bank-switching mechanism and a semi-custom chip to implement it. Authored the complete technical manual for third-party developers. Patented the bank switching memory system.

Heuristics

1981 – 1982 (1 yr)

Sinclair Technical Services

Founder & President · Newton, MA

Founded a technical services company for the Sinclair computing community. The only authorized Sinclair technical service center in the US. ~$50K revenue with ~40% pre-tax profit.

Sinclair Research Ltd.

1979 – 1981 (2 yrs)

ZX-80 Launch & Support

Manager of Technical Services · Boston, MA

The Sinclair ZX80 computer

One of the earliest employees at Sinclair's US operation, starting part-time before the ZX80 had even launched. Managed a team providing written support, telephone support, and machine repair services to ~300 customers per month.

What Others Say

From colleagues, executives, and partners across Microsoft.

Skills & Technologies

A career's worth of tools, languages, and platforms.

Languages

  • C#
  • C / C++
  • Smalltalk
  • JavaScript / TypeScript
  • Java
  • Z80 & x86 Assembly

Platforms & Frameworks

  • .NET Framework
  • ASP.NET
  • Azure DevOps
  • Windows / OS/2 / DOS
  • SharePoint
  • Unix / VMS

Technologies

  • XML / SGML
  • Public Key Cryptography
  • Digital Rights Management
  • Relational Databases
  • Object Databases (GemStone)
  • Entity-Relationship Modeling

Leadership

  • Security Architecture & SDL
  • Compliance Automation
  • Technical Architecture
  • Standards Development
  • Team Building & Mentoring
  • Startup Founding & Fundraising

Patents & Standards

Patents

12+ patents as primary inventor at Microsoft, focused on document technologies and formats. Additionally holds a patent for a bank switching computer memory system (Timex Computer Corp.).

View All Patents →

Standards

  • Open eBook Publication Structure — Co-author of first drafts; major participant in working group
  • CDIF (CASE Data Interchange Format) — Chairman of ANSI/EIA committee; published first version of standard
  • Metro / Open XML — Architect of document format adopted in Office 2007 and Windows

Beyond Work

The other parts of life that make the work better.

Music

Piano and guitar player.

Cooking

Spherification — a molecular gastronomy technique

Gourmet cooking, including molecular gastronomy.

Reading

Lifelong reader (and eBook pioneer, naturally).

Travel

International travel enthusiast.

Science

Fascinated by emerging infectious diseases.

More personal content coming soon — stay tuned.

Let’s Connect

Open to conversations about the right opportunity.

How I Can Help

  • Engineering Leadership VP/Director-level roles building and scaling security, platform, or compliance engineering teams
  • Architecture & Advisory Principal/Staff Architect roles, fractional CTO, or consulting on security architecture and compliance platforms
  • Standards & Strategy Technical strategy, standards development, or IP portfolio guidance for emerging technology initiatives

Get in Touch

I’m always happy to connect with people who build interesting things.

Resume available on request