You are shipping fast, and your engineers are already using AI everywhere. I find where that leaves you exposed, fix it alongside your team, and set the defaults that keep you secure after I step back.
You are not buying advice. I get in the weeds on the architecture and build it with your team.
Most companies know roughly where they are weak. Very few have the time to go and prove it, then close it properly.
You are moving fast, your engineers are using AI everywhere, and nobody has mapped what that actually exposes. None of this is a template, because the work is built against the architecture you actually have.
I get inside how you build and ship, then map where your weakest links are.
prod db reachable from stagingcritical
agent key with org-wide scopecritical
no review on agent-authored PRshigh
You are not buying a report. I work in the architecture decisions and in the code, so the fixes land.
Engineers should not have to pick the safe option. I build the baseline so the normal path is already the right one.
Security review runs on every release, so code from a person and code from an agent meet the same standard.
security-reviewhuman
security-reviewagent
secrets scanclean
A generic checklist is something anybody can run. The work that matters is built on how your company is actually put together.
Most engagements start with one or two of these and grow into the others.
Senior security leadership for teams that need a roadmap and someone accountable, without a full-time executive.
enforce SSO org-wideeng · oct 3
vendor access reviewops · oct 10
prod access tieringclosed
Your engineers already use AI. I make that safe without banning it, and keep the bill predictable while you do.
Testing that finds what is genuinely exploitable, written for the engineer who has to close the ticket.
The first-security-hire work, without the hire. I have done this from zero more than once.
secure sdlc & paved roadsrunning
iam & access reviewrunning
incident responserehearsed
Audits turned into real security instead of a screenshot exercise. I have owned SOC 2 Type 2, PCI SAQ-D, HIPAA, and GDPR.
Agents absorb the tedious security work and triage first, so your people spend their time on what matters.
Matthew Marji. Software engineer by training, over a decade writing code and securing software, and a security leader for the last five years. Most recently the first security hire at WorkOS, the identity platform behind OpenAI and Plaid, where I grew the function from one person to eight. Before that I owned the security engineering roadmap at Narvar, and spent three years on product security at Auth0, through the Okta acquisition.
Security works best when it is built with engineering instead of imposed on it, and what matters most is meeting a company where it actually is. I treat every engagement as if the business were mine, which means learning how you operate before recommending anything. I have agents in production today doing real security work.
More background at matthewmarji.com.
No sales pitch. I want a real understanding of your current state first, and then I will be straight about what I can help with. If someone else is better suited to the problem, I will say so and point you to them.