Securing AI at the Speed of Engineering | DoorDash | Forward Deployed Security | GRC Engineering

Securing AI at the Speed of Engineering | DoorDash | Forward Deployed Security | GRC Engineering

🎙 AI Security Podcast 👥 20K 📅 June 3, 2026 ⏱ 63 min 👁 8K 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

AI securityforward deployedGRC engineeringprompt injectioncompliance automation

Summary

This live podcast episode from San Francisco explores two critical aspects of AI security: proactive offensive security and the evolution of GRC (Governance, Risk, and Compliance). In the first half, Nick Reva, Head of Security Engineering at DoorDash, discusses the challenges traditional AppSec teams face in keeping up with AI development. He advocates for a ‘shift far left’ approach, embedding small ’tiger teams’ of security engineers directly into product development teams. Nick introduces the concept of ‘forward deployed security engineers,’ a model inspired by Netflix, and explains how they use tools like PromptFoo for automated prompt injection testing. He also coins the term ‘Claude Kiddie’ to describe a new breed of script kiddies who use AI to generate sophisticated bug bounty reports. The second half features Shivani Doke, a GRC engineer, who discusses the transformation of GRC in the AI era. She argues that traditional compliance standards like SOC2 and ISO fail to address AI-specific risks and that static PDF policies are obsolete. Instead, GRC must ‘shift left’ by embedding guardrails into CI/CD pipelines and using AI agents to automate evidence collection. The conversation also covers third-party and fourth-party AI risks, unauthorized AI software usage, and the future of compliance automation. The episode includes audience interaction and real-world anecdotes, such as an AI agent exfiltrating data from a vibe-coded app.

220 words

Critical Evaluation

Value of the Information & Strength of the Argument

The podcast provides valuable insights from practitioners actively working on AI security challenges. Nick Reva’s argument for ‘forward deployed’ security teams is compelling, backed by his experience at DoorDash and previous roles at Snap and SpaceX. He makes a strong case for embedding security engineers directly into product teams to keep pace with AI development speed. The concept of ‘shift far left’ and using tools like PromptFoo for automated testing is practical and actionable. Shivani Doke’s perspective on GRC engineering is equally valuable, highlighting the need to modernize compliance practices for AI. She argues convincingly that traditional compliance frameworks are inadequate and that GRC must evolve to integrate with development workflows. The discussion on using AI agents to automate evidence collection is forward-thinking. However, the arguments are largely anecdotal and based on personal experience rather than empirical data or formal research. The conversational format sometimes lacks depth, and some claims could benefit from more rigorous evidence. Overall, the value lies in the practical, real-world perspectives shared, though the argumentation could be strengthened with more concrete examples and data.

Scientific Rigor, Source Quality, Title Accuracy

The podcast demonstrates a reasonable level of scientific rigor, with speakers referencing specific tools (e.g., PromptFoo) and frameworks (e.g., SOC2, ISO 27001). However, the discussion is primarily based on personal experience and opinions rather than cited research. The title accurately reflects the content, focusing on securing AI at engineering speed through forward deployed security and GRC engineering. The description provides links to the podcast’s website, newsletter, and LinkedIn, but these are not direct sources for the claims made. The speakers do not cite external studies or reports, which limits the verifiability of their statements. The adéquation between title and content is strong, as the episode directly addresses the topics mentioned. Overall, the rigor is moderate, with practical insights but limited formal sourcing.

315 words

Title / Content Match

The title accurately reflects the content, which focuses on securing AI at engineering speed through forward deployed security teams and GRC engineering.

Quality & Reliability

7/10

The podcast features two experienced security professionals (Nick Reva from DoorDash and Shivani Doke) sharing practical insights and real-world examples. The discussion is grounded in their direct experience, but lacks formal citations or references to external research, and the format is conversational rather than rigorously evidence-based.

Chapters

Cited Sources

Concurring Sources

Dissenting Sources

  • Traditional Compliance Standards (SOC2, ISO 27001) — The podcast argues that traditional compliance standards are inadequate for AI, which contrasts with the widespread use of these standards in industry.

Contribution & Novelties

The podcast offers a fresh perspective on integrating security into AI development by introducing the concept of ‘forward deployed security engineers’ and ‘GRC engineering.’ It provides practical strategies for embedding security teams directly into product development and for modernizing compliance practices. The discussion on using AI agents to automate evidence collection is particularly innovative. The episode also coins the term ‘Claude Kiddie’ to describe a new type of attacker, highlighting the evolving threat landscape.

Pour aller plus loin :

127 words

Radar Profile

The radar profile shows high scores in quantity of information and technical level, reflecting the depth of practical knowledge shared. The quality and reliability scores are moderate, indicating that while the content is valuable, it relies heavily on anecdotal evidence. The overall profile suggests a resource that is informative and technically sound but could benefit from more rigorous sourcing.

Reliability 7/10