
Securing AI at the Speed of Engineering | DoorDash | Forward Deployed Security | GRC Engineering
Keywords
Summary
220 words
Critical Evaluation
Value of the Information & Strength of the Argument
The podcast provides valuable insights from practitioners actively working on AI security challenges. Nick Reva’s argument for ‘forward deployed’ security teams is compelling, backed by his experience at DoorDash and previous roles at Snap and SpaceX. He makes a strong case for embedding security engineers directly into product teams to keep pace with AI development speed. The concept of ‘shift far left’ and using tools like PromptFoo for automated testing is practical and actionable. Shivani Doke’s perspective on GRC engineering is equally valuable, highlighting the need to modernize compliance practices for AI. She argues convincingly that traditional compliance frameworks are inadequate and that GRC must evolve to integrate with development workflows. The discussion on using AI agents to automate evidence collection is forward-thinking. However, the arguments are largely anecdotal and based on personal experience rather than empirical data or formal research. The conversational format sometimes lacks depth, and some claims could benefit from more rigorous evidence. Overall, the value lies in the practical, real-world perspectives shared, though the argumentation could be strengthened with more concrete examples and data.
Scientific Rigor, Source Quality, Title Accuracy
The podcast demonstrates a reasonable level of scientific rigor, with speakers referencing specific tools (e.g., PromptFoo) and frameworks (e.g., SOC2, ISO 27001). However, the discussion is primarily based on personal experience and opinions rather than cited research. The title accurately reflects the content, focusing on securing AI at engineering speed through forward deployed security and GRC engineering. The description provides links to the podcast’s website, newsletter, and LinkedIn, but these are not direct sources for the claims made. The speakers do not cite external studies or reports, which limits the verifiability of their statements. The adéquation between title and content is strong, as the episode directly addresses the topics mentioned. Overall, the rigor is moderate, with practical insights but limited formal sourcing.
315 words
Title / Content Match
The title accurately reflects the content, which focuses on securing AI at engineering speed through forward deployed security teams and GRC engineering.
Quality & Reliability
7/10
The podcast features two experienced security professionals (Nick Reva from DoorDash and Shivani Doke) sharing practical insights and real-world examples. The discussion is grounded in their direct experience, but lacks formal citations or references to external research, and the format is conversational rather than rigorously evidence-based.
Chapters
- Introduction: Live from San Francisco
- Audience Story: How an AI Agent Exfiltrated Data via a Vibe-Coded App
- Meet Nick Reva: Securing DoorDash at Silicon Beach
- "Shift Far Left": Embedding Tiger Teams in AI Development
- Using PromptFoo for Automated Prompt Injection Testing
- Why Security Must Operate at the Speed of Engineering
- The Netflix Model: Forward Deployed Security Engineers
- AI-Enabled Threat Modeling and PR Reviews
- Build vs. Buy: Why Speed Matters More Than Money in AI Security
- The Rise of the "Claude Kiddie" in Bug Bounties
- Who Owns AI Risk in the Enterprise? (Business vs. Security)
- Meet Shivani Doke: The Evolution of GRC Engineering
- Why Traditional Compliance Standards (SOC2/ISO) Fail with AI
- Owning Third-Party AI Risk vs. In-House AI Risk
- The Death of PDF Policies: Shifting GRC Left into CI/CD
- The New Privacy Paradigm in Third-Party SaaS Reviews
- Dealing with Unauthorized AI Software Expensed on Corporate Cards
- Fourth-Party Risk and Transitive Dependencies in the Cloud
- Will GRC Agents Finally Automate Compliance Screenshots?
Cited Sources
- AI Security Podcast Website — Official website of the podcast, providing additional resources and episodes.
- AI CyberSecurity Newsletter — Newsletter associated with the podcast, offering updates on AI security topics.
- AI Security Podcast LinkedIn — LinkedIn page for the podcast, where listeners can engage and follow updates.
Concurring Sources
- OWASP Top 10 for LLM Applications — This framework aligns with the podcast's emphasis on prompt injection and other AI-specific vulnerabilities.
- NIST AI Risk Management Framework — Supports the discussion on GRC and compliance in AI, offering a structured approach to risk management.
Dissenting Sources
- Traditional Compliance Standards (SOC2, ISO 27001) — The podcast argues that traditional compliance standards are inadequate for AI, which contrasts with the widespread use of these standards in industry.
Contribution & Novelties
The podcast offers a fresh perspective on integrating security into AI development by introducing the concept of ‘forward deployed security engineers’ and ‘GRC engineering.’ It provides practical strategies for embedding security teams directly into product development and for modernizing compliance practices. The discussion on using AI agents to automate evidence collection is particularly innovative. The episode also coins the term ‘Claude Kiddie’ to describe a new type of attacker, highlighting the evolving threat landscape.
Pour aller plus loin :
- PromptFoo — Open-source tool for testing prompt injection, directly relevant to the discussion.
- OWASP Top 10 for LLM Applications — Framework for understanding AI security risks, complements the podcast’s themes.
- NIST AI Risk Management Framework — Provides a structured approach to managing AI risks, relevant to GRC engineering.
127 words
Radar Profile
The radar profile shows high scores in quantity of information and technical level, reflecting the depth of practical knowledge shared. The quality and reliability scores are moderate, indicating that while the content is valuable, it relies heavily on anecdotal evidence. The overall profile suggests a resource that is informative and technically sound but could benefit from more rigorous sourcing.