Ex-Facebook & Uber CISO: Why AI Changes Everything for Cloud Security
What happens when a former federal prosecutor turned CISO of Facebook, Uber, and Cloudflare turns his attention to AI and cloud security? In this episode of Techstrong TV, Alan Shimel sits down with Joe Sullivan, security advisor at Upwind Security, for a wide-ranging conversation about the state of cybersecurity in 2026.
Joe shares his remarkable journey from the US Department of Justice to building security teams at Facebook, leading security at Uber, taking Cloudflare through its IPO, and now working in the VC world advising companies like Upwind. He offers a unique multi-angle view of the security landscape.
The conversation dives into why runtime security is the next frontier in cloud defense, how AI is transforming software engineering with companies seeing 10x increases in code output, and why vulnerability management needs a complete rethink in 2026. Joe explains why agentic AI solutions are the future of security operations and why this is the best time ever to be a cybersecurity leader.
Transcript
Hey everyone. Welcome back here to Techstrong TV. I'm really happy to have this next gentleman on.
I've heard him by name and reputation, but I've never actually met him, and he's never been a guest here with us on Techstrong TV, so it's a first. Let's welcome Joe Sullivan. Joe is an advisor at Upwind Security.
We're going to talk about Upwind in a second. But Joe's had a pretty venerable career already in security, and let's hear about his journey. Joe, welcome to Techstrong TV.
It's great to have you on here. Hey, thanks for having me on. It's good to be here.
A pleasure. I've had quite a journey in security. I've looked at it from every different angle you can.
I started out as a federal prosecutor, so eight years with the US Department of Justice. I was the first federal prosecutor in the US Attorney's office who was just doing high tech stuff full time. Went to eBay in the early days, 2002, built out their fraud investigations team and did a bunch of interesting stuff at eBay and PayPal before I went to Facebook when you'd never heard of it in 2008, and built their security function from three people to hundreds into the big public company that it is.
Did the same at Uber, went there in 2015, and then went to Cloudflare. It was my last stop as a CSO in 2018. I went there and got to go through the IPO with them and built their security team from three people to very large.
So I spent many years as a CSO. I also had the misfortune of being a defendant in a criminal case, so I got to see cybersecurity from another direction. Yes.
And then, thankfully, I landed on my feet, and I've been doing security consulting and working in the VC world since then, so I also look at cybersecurity from an investment standpoint and advise companies like Upwind, so get to think about it from a vendor standpoint as well. That's quite a tale, Joe. More power to you, and I remember with the whole legal thing, I just thought it was, what a crock that was.
But anyway, we're not here to discuss that, I promise you. Of course, Cloudflare is a company we work with a lot, and I think, is their new CSO Graham Bazookar. Grant.
Grant. Yeah. He's an interesting fellow, too.
I've interviewed him a bunch of times. You were at Uber after the original team, I assume. Or was that when- No, I got to Uber at the beginning of 2015.
It was at the point where the board had wanted to bring in some new blood with some experience- Yeah ... to help the company scale. But it was under Travis.
I reported to Travis Kalanik- Yeah ... until the board, and he had their falling out, and then I reported to... Actually, I was part of the leadership team when we had no CEO.
We were effectively co-CEOs, all of us who had been reporting to Travis for a few months, and then we hired Dara. Yes. I remember.
Yeah. I had friends who were investors there. But anyway, you know what?
It's been an interesting arc. As you said, you're working now with a lot of VCs, advising some companies, one of which, Joe, is this Upwind Security that I don't think a lot of our audience is probably familiar with. Why don't you, if you don't mind, and I recognize you're an advisor.
You're not there full time, and it's a different kind of relationship. But if you can, get our audience a little familiar, what's Upwind Security about? Sure.
Well, if you think about the transformations in technology we've been through, and we're going through one right now with this kind of world of AI, the biggest transformation that we're actually living with was the transformation movement to the cloud. " But when everybody started moving to the cloud a decade ago, we opened up a bunch of security vulnerabilities and risks that didn't exist before. When I was building the security team at Facebook, we didn't have a cloud sec team.
There wasn't anybody dedicated to cloud security. But by the time I got to Uber, we needed to start thinking about it. In fact, the security incident at Uber that we had that set me on the path that I've been on ever since was an AWS S3 bucket vulnerability situation.
And so, I think that making sure that we're able to protect our cloud infrastructure, all those workloads, the containers, the APIs, everything about it, it's too much to hire a bunch of engineers to just constantly look at the configuration and map out what's happening in real time. And so we buy security products for things like that, and that's where Upwind comes in. Upwind is not the first generation of cloud security, but it's, I think, the most modern version that exists now.
The early versions of cloud security solutions looked at, okay, there are a bunch of settings. Let's make sure all the settings are right. And then, you're good.
What we realized, and there's this really important thing called runtime, which is when things are operating is when things go bad. Security has always been about prevention and detection and monitoring. There's always two sides to every security organization and every set of security tooling, and that's where a product like Upwind comes in, I think.
In modernizing cloud security, it's focused on not just the configuration, but also the runtime. Absolutely. We were talking off-camera, Joe, about this Mythos and Project Glasswing and the Cloud Security Alliance report that came out over the weekend.
You were on the, I guess like advisory team to the three authors or whatever it is. It's funny. A lot of the folks in the AppSec world that were always focused on finding vulnerabilities, patching them, making the code more secure, are now all of a sudden waking up to, hey, runtime.
We got to worry about runtime. Runtime security. If you're not worried about the runtime security, you're kind of missing the boat, and you're focusing over here.
So it is interesting. But the other thing you spoke about, Joe, is the world doesn't move homogeneously in one thing. It's lumpy out there.
Right. There are some people who, like you said, they're just starting their cloud journey. There are other people who are saying, "You know what?
We've been through this cloud. " The cloud is more expensive. It's not more secure.
It's not what we thought. And that's the market. It always is.
Is your early adopters, your laggards, and everything in between. " You know what I mean? All of a sudden, decisions need to be made, it seems like, daily as our world is changing around us.
And we see potentially, especially in security, all these new security vulnerabilities and everything else. I had this discussion with another CISO earlier today. For the people watching this show, Joe, what do they do?
How do they cope? " What do you do? Well, I've been involved in a lot of the conversations about what advice should we be giving right now.
And the interesting thing is, if you boil it all down, the advice is take care of the basics. You always got to start with the fundamentals. And, so in the case of, what has AI transformed already?
It's transformed the role of the software engineer. Software engineering is a completely different profession than it was a year ago. Than it was three months ago, even, I think.
Right. Mm-hmm. And so most jobs are not fundamentally redone, but software engineering has been redone.
And we don't actually know what the end state is on software engineering yet because it's still evolving so quickly. But what we do know is that the AI tooling is really good at generating code at an incredible speed. 5 million lines of code a month.
And so a security organization that isn't ready for that is going to get swamped. And so I think that's an example of area number one, where security teams are looking at new and different products right now. How do we get on top of and handle this?
And then if you specifically look at Mythos and this whole conversation about the new cloud model that hasn't been released to the world yet, what everyone is saying is that it's really good at finding vulnerabilities. Well, what is the foundation team that we already have that we probably haven't invested enough? Vulnerability management.
A lot of the times we didn't take care of a vulnerability because it was three layers in, and we're like, "Ah, no. For an attacker to get to that three-layer-in vulnerability, the odds are so low. " Well, what the AI is doing now is showing that they can string vulnerabilities in the way that a pen tester or an offensive red teamer can.
And so that means we got to get a lot better at vulnerability management in 2026. And that's an area- And it- ... we can invest in.
There are good tools for vuln management, and there are better tools coming all the time. And we already have teams, so maybe resourcing them some are. I think those are the two areas that we can't just assume that what we did in 2025 was good enough.
I don't disagree with you at all. So Joe, my history, right? I've been in security about 25-plus years, started a security company.
2001 was the last one I started, and we had a vulnerability management system then. This is before AppSec and pen testing. It was testing your production environment.
I learned this lesson, and nothing has changed in 25 years. We were never good at fixing vulnerabilities or remediating or whatever you want to call it. Not every vulnerability needs a patch.
Sometimes we remediate around them. But we never got to all the vulnerabilities. We always had to prioritize and say, "Okay, let's make our bets here.
" This one patch will fix 70 instances of this vulnerability. Yep. This one is more than likely very impossible to get to.
AI has changed all that. It's the sheer number of vulnerabilities we can find. It's the ability for it to write exploit code, as you mentioned.
Because-That was always the thing. Just 'cause you're vulnerable doesn't mean it's exploitable. Well, if this thing's going to start writing exploit code, that changes the equation.
Yeah. But Joe, is it the security guy's problem, or do we need to shift this whole remediation thing to project engineering, IT in general? Or how do we deal with it?
Well, I think that whenever you're doing security at a company, at the end of the day, I always remember I had two spreadsheets. One was a list of my vendors and the cost and what I expected from them, and the other was a list of my employees and how much each of them cost. Now, with the massive volume of code that's coming and the vulnerabilities that are coming, which of those two tabs on the spreadsheet am I going to lean on more?
Initially, I'm going to lean on my team because I need them to tell me what's actually changing. But I also think that we're going to be counting on our vendors more. Companies like Uphind, in 2026, it's not good enough for them to just tell us about the things that are wrong.
They actually are building agentic solutions into their products, too. Right. And this is across the board.
Companies are trying to figure out. And what I want as a security executive is I want the products that I'm buying to not just tell me about the problems, but to remediate them. Right.
In the Uphind context, they're building out agents that will be an extension of my security team. There'll be red team type agents, there'll be green team type agents, blue team type agents, all working together to get me the outcome I need. I can't hire 500 more people, but if my products can bring 500 defensive agents to work for me, then I'm going to have a level playing field with the attacker.
Absolutely. So I boil that down, Joe, as we need AI to fight this AI, right? Not fight, but to offset it, right?
Because- Yeah ... AI is bringing volume and speed that we can't keep up with as humans, and so we need to match that volume and speed with AI. You're not going to hire enough people, that's for sure.
So I want to bring it back to Upwind. I don't know if you know off the top of your head, but what's the website for Upwind Security? You can find them on the AWS Marketplace.
io. Beautiful. If you still use search engines, you can Google them.
You'll get the Gemini results. It's out. It's going to be on LinkedIn.
Yeah, LinkedIn. So I've actually heard of Upwind before, and it's funny you mentioned Google search. I just had a discussion earlier today about that.
Meta, Facebook Meta, just supposedly surpassed Google in ad search, in ad revenue. Because I think people with Google and search are starting to realize Google's keeping all that traffic over there. You may search Uphind on Google, and it'll tell you about Uphind, but you got to really hunt to click through to the Uphind site, because this is what Google's doing today.
Joe, you're in an interesting place where you're sitting, you have a good view of what's going on from a vendor point of view, the market, investors. Is it the apocalypse? Is it the greatest opportunity ever?
Is it the cauldron that we're going to pass through to finally make more secure code? I think it's the best. Or all of the above?
It all depends on who you listen to. Personally, I think it's the best time ever to be in technology, and I'm excited to work with AI first companies, companies that are bringing innovation to the table, because you can build so much faster now. You can get things done.
And I believe there are going to be some bumps along the way, but I do believe that AI will be better for the defenders than it will be for the attackers. I also think that 2026 is an amazing time to be a cybersecurity leader because the rest of the executive team needs you more than ever before. Every company is going through a, quote-unquote, "AI transformation," and they can't do it well without cybersecurity leaders riding along and driving the innovation, to be honest.
If security is blocking it, the security team is going to get minimized and pushed aside because- Run over ... the bigger risk in the world of AI is that the company loses product market fit, loses revenue, and goes out of business. So CEOs and boards are pushing the companies forward to aggressively adopt AI.
This is a great time for security leaders to step up and say, "Hey, I can help this transformation. " But we'll get that budget if we're part of the vanguard rather than bringing up the rear. Absolutely.
I couldn't agree with you more. Hey, Joe, we're about out of time. Thank you so much for coming here on Techstrong TV.
I hope this isn't the last time you'll be on. We look forward to having you back more. We discuss this kind of stuff every day, so love your input.
io? Yes. Okay.
Uphind Security. We're going to take a break. We'll be back with more.
You're watching Techstrong TV.