This website uses cookies

Read our Privacy policy and Terms of use for more information.

What you'll learn

  • Why GitLab runs its own engineering org as customer zero — a dedicated team builds SSDLC agents for internal use first, then ships them as SKUs to a customer base that covers over 50% of the Fortune 500.

  • What composite identity is — GitLab's model for binding every agent action to direct human attribution — and why agent governance collapses without it.

  • Why Chaim thinks agentic AI makes corporate security, not the SDLC, the soft target — "a renaissance for CorpSec" — and why access tokens are the number one attack mechanism right now.

Description

Chaim Mazal is the CISO at GitLab and the former Chief AI and Security Officer at Gigamon. Before he took the seat, he spent eight years as a GitLab customer and roughly five on its advisory board — and this isn't his first customer-to-operator jump. An advisory relationship with Kandji turned into running product, engineering, and security there, effectively the CTO job. His career runs through product security, application security, and multiple DevSecOps transformations "before we gave them all these cool monikers." This conversation is about what it takes to secure the platform where agentic software development actually happens — and where the real exposure sits.

The through-line: agents are only as safe as the foundation underneath them and the identity model wrapped around them. Chaim walks through GitLab's composite identity — agent actions bound to the human who kicked them off — a governance platform that inspects every agent transaction, and a GRC engineering team that's replaced screenshot audits with data-collection agents. He argues the product-side SDLC is the easier problem because outcomes are deterministic; the corp side, where fleets of agents chase open-ended tasks, is where things get ugly. The evidence backs him: Drata's State of GRC found only 13% of GRC professionals have high confidence they know where AI lives in their org, Uber's agentic detection and response paper keeps circling back to access tokens, and the Shai-Hulud supply chain attack ripped through CI/CD credentials, not vulnerable code. If you're a CISO or product security leader who's been told to make agentic coding safe — or you're eyeing an advisory board seat and wondering how to make it count — this one's for you.

What we cover

  • "you can be the best technical resource on the planet, but you have to start thinking of how the company wins as a whole" — how Chaim turned advisory seats at Kandji and GitLab into operator roles, and how to build influence by framing security as a business lever.

  • "This is not Netflix. It's not 2012" — buy versus build at an all-engineering company, and the flywheel of converting internal security tooling into product SKUs.

  • "Composite identity is a mixture of agentic identity mixed with direct human attribution" — GitLab's identity model for agents, and the governance platform that watches every transaction end to end.

  • "this is gonna be a renaissance for CorpSec" — why non-deterministic agent fleets on the corporate side are a harder problem than the SDLC, and what agentic detection and response looks like.

  • "it's cutting out a lot of the repetitive tasks" — GRC engineering teams building data-collection agents, continuous assurance, and the end of screenshot evidence.

  • "once you get to a monolith and you look for context within a model, it falls apart instantaneously" — why CI/CD hygiene, golden images, and dependency scanning come before any agent deployment.

  • "that's one of the number one attack mechanisms today" — access tokens, Shai-Hulud, and why the big breaches hit developer tooling rather than code.

  • "you have to love this. This has to be your life" — the dual AI-and-security mandate, the missing playbook for chief AI security officers, and parting advice for the next generation.

Thank you to our Sponsors:

RISC Point is security & compliance consulting tailored to your business. Talk to RISC Point.

Hampton North is the premier US based cybersecurity search firm. Start building your security team with Hampton North.

Sysdig is the leader in AI-powered real-time cloud defense; stop watching and start defending.

The conversation

Eight years as the customer, then the CISO seat

Most security leaders who love a product join the advisory board and stop there. Chaim has now twice crossed to the other side of the table. At Kandji, advisory conversations turned into leading product, engineering, and security — the CTO role in everything but name. At GitLab, five-plus years of advisory work turned into the CISO job at a company he'd spent eight years buying from. When GitLab came calling, "all the other ones just kind of faded into obscurity."

His advice for security leaders craving that kind of influence is blunt: technical excellence isn't the bottleneck.

"You can be the best technical resource on the planet, but you have to start thinking of how the company wins as a whole and how you can use your area of influence and focus as a driver for those successful outcomes."

— Chaim Mazal

He gives a concrete example from Gigamon. Eight executives were running their own siloed data models, none of the numbers matched, and pitching a fix as "a security issue" went nowhere. Reframed as an operational win for the business — single source data, uniform controls, consistent reporting — it moved. Security got what it wanted by making the company better, and "once you start putting wins on the board, there's more investment that comes alongside of it."

The other pattern he calls out: pick advisory work based on genuine conviction about the product, not vanity metrics, and treat your own problems as industry problems. Your challenges are probably not unique to you — solving them collectively is how you leave an imprint beyond your own four walls.

Turning internal security work into a SKU

Chaim's main focus arriving at GitLab: take what the security team builds for itself and ship it. He has a dedicated team that "just builds SSDLC agents" — built for GitLab's own use cases, tested by GitLab's own engineers as customer zero, and pushed forward as product when they prove out. Because GitLab is an engineering company through and through, its internal problems turn out not to be unique — they're the same problems facing a customer base that includes "over 50% of the Fortune 500."

Conor's take: this is leverage the community should welcome rather than flinch at. Plenty of practitioners have an allergic reaction to vendors, but nobody has ever built a security program without partners. When a company converts a working internal program into a finished product, every customer inherits the benefit of that team's work — "Thank God someone was thinking about this problem space. Now I don't have to go build it, I just have to go buy it."

Chaim is equally clear-eyed about the other direction:

"This is not Netflix. It's not 2012, right? These are solved problems in some capacity."

— Chaim Mazal

GitLab buys plenty and builds where the outcome is unique to them — bring-your-own-model, agent flexibility, Duo across the platform — with the goal of being the center of the secure software development lifecycle wherever agentic development goes next. As Stu notes, the reason customers will accept SSDLC agents from GitLab at all is years of accumulated trust: they dogfood everything, and they wouldn't ship it if it didn't work internally.

Composite identity and governance built for agent fleets

The product-side answer to agentic risk starts with determinism: customers can enable or disable agents at any gate in the development lifecycle. On top of that sits composite identity.

"Composite identity is a mixture of agentic identity mixed with direct human attribution. So being able to look at who kicked off the action of an agent, what those outcomes were, and what they were supposed to be."

— Chaim Mazal

Yes — you're accountable for your agent's actions. Layered over that is a newly announced governance platform that watches every transaction, flags what was effective and what "went off the rails," stops processes when needed, and gives GRC teams the attribution trail regulators like the EU will demand. The platform also learns: approve the same exception ten times and it prompts you to promote it to a rule, so policy iterates on real behavior patterns instead of rotting in a document.

Conor pushes on the load-bearing weakness in that loop: verification. "Did I successfully achieve this outcome 10 times, or did I just hit the yes button 10 times?" There's a difference, and it pushes the burden back on engineers to define success in measurable terms before pointing agents at it. Chaim agrees — the platform is built so engineers can check whether effective outcomes match original intent and pivot mid-flight, because "it's very easy to set a fleet of things and say, 'Go do all the stuff'" and end up with half of it done and context lost.

The same philosophy is rebuilding GRC. GitLab's GRC engineering team now builds agents that do data collection across the business, with minimal human validation on the results — and a validation agent likely coming next. Chaim's answer to what GRC teams become: "it's cutting out a lot of the repetitive tasks," freeing people to work on the program instead of the evidence screenshots. Conor connects it to the continuous-assurance direction Ayub Fundi laid out in a prior episode — and given Drata's finding that only 13% of GRC professionals are confident they know where AI lives in their org ("Find me those 13%"), the shift can't come fast enough.

The CorpSec renaissance runs through access tokens

Here's the episode's title thesis. The SDLC is the easier half of the agentic problem because outcomes are deterministic — you can define expectations, gate access to secrets and tokens, and monitor all the way through. The corporate side is where it gets hard: large fleets of agents given open-ended tasks — "just like make this happen" — by everyone in the company, because at an engineering org, everyone's building, whether they're in engineering or not.

"I think this is gonna be a renaissance for CorpSec, to be honest with you, because the amount of inputs and outputs are so wild."

— Chaim Mazal

Conor calls that the kindest possible framing. Stu's version: what's old is new again — identity and corp sec, the parts of security nobody cared about seven years ago, are now the biggest problems in the industry. GitLab's response is an internal identity mesh for agents plus what Chaim happily borrows from Uber's branding as agentic detection and response: tracking and preventing third-party package delivery, browser extensions, and pulls from specific repos — corporate use cases, not developer workflows. Every laptop is in scope now, the same way the software supply chain era taught us it wasn't just about your package manager.

And when Chaim actually read Uber's paper, the takeaway wasn't in the first two paragraphs — it was that the paper mentions access tokens "like eight times." The stringencies Uber drew around token compromise were the headline outcome, and "that's one of the number one attack mechanisms today." Conor connects it to Shai-Hulud tearing through software supply chains via credentials for CI/CD-integrated tooling — none of it "vulnerable code," all of it compromised plumbing. His read on the Uber results: the wins came from pre-git hooks and years of shift-left foundation work, now validated with data. It works.

Foundations before fleets

Asked where a security leader should point their team to make agentic coding safe, Chaim's answer is deliberately unsexy:

"You got to start with the basics first and go back to all the previous principles that helped to get us here."

— Chaim Mazal

CI/CD pipelines, infrastructure as code, golden images, static analysis, dependency scanning and mapping, architectural patterns — not world-class, but healthy. Skip that and "it doesn't matter how much technology you throw at it, it's not gonna solve the problem." Unleash a fleet of agents on a weak foundation and you get the same outcomes you had before, just faster.

He's also honest about where models break. Point the smartest model at an established company's codebase and ask it to find every vulnerability and architectural mishap, and "once you get to a monolith and you look for context within a model, it falls apart instantaneously." You get spot checks, not the end-to-end line of sight you need.

Step two, once the foundation holds: find where you can remove hard process gates and let trusted, validated agents make decisions so development moves faster without new risk. Code review is his example — models aren't reviewing to expectation on their own, so companies are chaining two, three, four models until the output is acceptable. The layered approach that always worked still works; it just runs at machine speed now. All of it "predicated on having a solid foundation ahead of time."

The CISO profile this era demands — and the playbook that doesn't exist

Chaim held both AI and security in his Gigamon title, and the GitLab role is functionally the same dual mandate. Is that the future for every CISO? His honest answer: yes and no, depending on who's in the seat. For the "new modern wave of CISO" — the enabler figuring out how to say yes-and — the dual mandate is a business driver: "if you can figure out how to do it safely and fastly and set the business up for success, no-brainer." For the CISO whose whole identity is saying no and managing risk from the spreadsheet, "it's not an obvious place to be." The practitioners doing well right now are the ones with engineering backgrounds and real technical depth, not "managers of risk on spreadsheets."

Stu names the gap: there's no formulated knowledge base for being a chief AI security officer. You learned to be a CISO by doing security for years and watching others succeed and fail. Here, there's peer sharing and not much else. Chaim credits people like Gadi and the Secure Cloud Alliance for working on it, but doesn't sugarcoat it — "it's the Wild West all over again."

What it demands instead is intensity:

"You have to love this. This has to be your life... things are moving so fast you'll get left behind instantaneously. Like, you can't just show up for a job."

— Chaim Mazal

Conor's response — "Burnout is now on the risk register" — gets Chaim's driest line of the episode: "there's an agent for that."

His parting counsel to the next generation of leaders getting advisory and board seats lands where the whole episode started — influence earned by contribution:

"Look to do things from an altruistic perspective, not about what you're gonna get in return, but what you can contribute to the community, and I promise long term it'll pay off for you."

— Chaim Mazal

Show notes

Guests — Chaim Mazal, CISO at GitLab; former Chief AI and Security Officer at Gigamon; previously led product, engineering, and security at Kandji (effectively CTO); eight years a GitLab customer and roughly five to six years on its advisory board before taking the CISO role.

Books mentioned — None named in the conversation.

Frameworks / models / tools named — Composite identity; GitLab's agent governance platform; SSDLC agents; GitLab Duo; agentic detection and response (Uber's term); internal identity mesh for agents; GRC engineering; NIST software supply chain guidance; DevSecOps / shift left; CI/CD; infrastructure as code; golden images; static code analysis; dependency scanning; Anthropic's Mythos model; Kandji; Drata; Vanta; SafeBase; Sysdig threat research.

Other people / shows / resources referenced — Ayub Fundi (prior Zero Signal guest, GRC engineering); Al Yang (SafeBase, acquired by Drata); Drata's State of GRC report (13% AI-visibility confidence figure); Uber's agentic detection and response paper; the Shai-Hulud software supply chain attack; Gadi and the Secure Cloud Alliance; EU AI regulation; Gigamon; Kandji; Netflix (as a buy-vs-build reference point).

Hosted by Conor Sherman and Stuart Mitchell.