Career update: Iโve joined
@OpenAI to lead Cyber with
@michaelaiello.
Why I joined, and what weโll be building:
Itโs clear that AI is fundamentally changing how software is being written and secured.
Coding agents are writing the majority of code for many developers, software is getting shipped more quickly, and vulnerabilities that were latent for 20 years are being discovered at a rapid pace. The time to bug discovery, and exploitation once discovered, are trending down (H/T
@EppSecurity and
@gadievron).
I believe we have an unparalleled opportunity to fundamentally ๐ช๐ฎ๐ฑ๐ณ๐ฐ๐ท๐ฆ cybersecurity in ways that were previously impossible. (H/T
@bubblewireโ BSidesSF keynote on reasons for optimism)
Over 6 years at
@Semgrep, I had the privilege of working with an amazing team building what has become the most popular open source security code scanning tool in the world, that many companies have built their application security program around.
Now, at
@OpenAI, Iโm thrilled to be a part of a company helping shape how software is written, and how security work gets done. It is a massive opportunity, and responsibility, and I donโt take that lightly.
Here are my current thoughts about where things are headed:
๐๐๐ฌ๐ข๐ฅ๐ข๐๐ง๐ญ ๐๐ฒ ๐๐๐ฌ๐ข๐ ๐ง. Defenders are not going to win playing bug whack-a-mole. We need to systematically eliminate classes of vulnerabilities, via generating secure code and streamlining the detect โ validate โ fix process.
๐๐ฎ๐ ๐ฆ๐๐ง๐ญ ๐๐ง๐ ๐๐ฆ๐ฉ๐จ๐ฐ๐๐ซ ๐ฉ๐๐จ๐ฉ๐ฅ๐. We should build models and tools that give defenders โsuperpowers,โ enabling them to be more ambitious in the scope they tackle, shift from being reactive to proactive, and allow them to automate the drudgery so they can focus on the highest leverage work.
๐๐๐๐ฎ๐ซ๐ ๐ญ๐ก๐ ๐๐จ๐ฆ๐ฆ๐จ๐ง๐ฌ. The world runs on open source software. OpenAI has already spent
$Ms finding and patching vulnerabilities in the most popular and widely run software, including browsers, operating systems, and core libraries. More on this soon. Weโre also working on helping secure critical infrastructure.
๐๐จ๐ฆ๐ฆ๐ฎ๐ง๐ข๐ญ๐ฒ ๐๐ง๐ ๐ฉ๐๐ซ๐ญ๐ง๐๐ซ๐ฌ. Securing the world is a community effort. Iโm looking forward to partnering with cybersecurity vendors, researchers, practitioners, governments, and more to do together what we canโt do alone.
๐๐ข๐ฆ๐ ๐ญ๐จ ๐๐ฎ๐ข๐ฅ๐.ย Tactically, here are some domains Iโm excited about:
- Finding, validating, and reliably patching software vulnerabilities at scale.
- Eliminating classes of vulnerabilities and making software resilient by design.
- Giving broad access to the best cyber models to empower defenders, not just to a select few.
- Creating and sharing Skills and playbooks that help in many security domains.
- Building platforms that enable defenders to easily orchestrate security work.
- Making enterprise agents safe and reliable.
Time to build ๐
โ
What would help you most? What should we build?
Let me know.