Modulo Security builds and runs security programs for engineering-led companies. Fractional CISO leadership, AI enablement, penetration testing, and the compliance work that comes with selling to enterprises.
Most security slows teams down because it arrives as a checkpoint. I build it into how software already gets made, so the secure path is also the fast one.
They can. Most of the caveats are security, and a few are budget.
Every exec team has already decided AI is the priority. Engineering adopts it in weeks. Security shows up a year later, once the data flows are built and nobody can say which tools touch what.
The work is making that adoption safe without slowing it down, and without tying you to one vendor. No matter which tool a team picks, the guardrails stay in place.
Teams pick their own tools, and they change them every few months. The controls sit in your pipeline instead of inside a vendor, so swapping a model does not undo your security.
AI writes code faster than anyone reviews it. The checks run where your code already runs, so AI-written code passes through the same gate as everything else.
One shared set of AI skills any team can pull from, which reviews code for security before it merges. One standard, instead of every team improvising its own.
AI spend gets away from companies quietly. The same standardization caps what gets consumed, so everyone keeps access and finance still recognizes the bill.
Prompt injection, insecure output handling, data leakage. Threat modeled against your architecture and your agents, not scored against a generic checklist.
Engineers should not have to make the secure choice. They should get it by taking the normal path, because the normal path is the one that was built properly.
Companies do not need permission to use AI. They need the guardrails that make it defensible.
Six things. Most engagements are one or two of them, and they tend to grow into the others.
Senior security leadership for teams that need the strategy, the roadmap, and someone accountable, but not a full-time executive. I own the program, run the vendor and audit relationships, and sit in the rooms where security decisions get made.
Your engineers are already using AI. The job is making that safe without banning it. I set the guardrails, review how models and agents touch your data, and build the approval paths so teams move fast inside a boundary instead of around it.
Testing that finds what is genuinely exploitable, then tells you what to fix first. Reports are written for the engineer who has to close the ticket, with a reproduction and a fix, not a scanner dump with severity labels attached.
The first-security-hire work, without the hire. I have done this from zero more than once: pick the controls that matter at your stage, get them running, and leave a program your team can operate after I step back.
Audits turned into real security instead of a screenshot exercise. I have owned exception-free SOC 2 Type 2, PCI SAQ-D, HIPAA, and GDPR, and built the trust portal that answers customer questions before sales has to ask you.
AI agents that do the tedious security work end to end. Vulnerability triage, dependency upgrades, cloud alert validation, and customer questionnaire answers, each with a human only where judgment is required.
Matthew Marji. Software engineer by training, a decade writing code, and a security leader since. Most recently the first security hire at WorkOS, the identity platform behind OpenAI and Plaid, where the function grew from one person to a team of eight. Before that, security engineering at Narvar and three years on product security at Auth0, through the Okta acquisition.
Security here is a collaborative function, built with engineering rather than imposed on it. AI-native in practice rather than in pitch: there are agents in production today doing real security work.
More background at matthewmarji.com.
If there is a fit I will say so, and if there is not I will tell you that too, usually with the name of someone better suited. No pitch deck, no discovery sequence.