Manoj Nair, Snyk | AWS re:Invent 2022
Manoj Nair, Chief Product Officer of Snyk, joins Mitch Ashley at AWS re:Invent to talk about how Snyk is leading the charge for developer security, delivering cyber resilience by embedding security through the development process.
Transcript
This is texturong TV. Well, we are really wrapping things up in a great way here and AWS reinvent. It's been a fantastic week in our Secret locations secret Studio.
That's at the win here in Las Vegas. So AWS reinvent 2022. So I have the great pleasure being joined by Manoj snare.
Who is Chief Products officer with sneak. Welcome man. Thank you.
Good to be back on Deck strong TV. You seem like you're holding up pretty well day three yes or whatever it is for this is that you know, you made it. Yeah go home here pretty soon.
Well, so a tough folks about yourself. We're trying a little bit about your background about coming in to security moving out and going to cloud and yeah coming back in the devil world. That's pretty I think is a cool story.
I love your background. Yeah, I know so, you know, I'm an engineer and maybe should have a t-shirt that I used to code or something like that in one point, but that was a cardinal developer and you know, I'll go back to that later on in the progression and then, you know started doing bunch of data management software and ended up. You know at RSA help building out a security analytics business and you know five years into it booming business and they get a nation state attack.
I learned from the first time like real, you know, kind of real life, you know, it's like that punch that hits you in the face that you're not ready for and then you're like, oh, wow that was compliance not really security. So the rest of the time there was like, okay, you gotta like really think about security from a different perspective. I spent a bunch of time after that doing, you know more Cloud SAS companies data protection and all that and so the opportunity it's snake because I was thinking of what to do next like do I want to go back to security and I said this different so this goes back to kind of my developer Roots, right?
That's a kernel dobre hated static analysis tools to you know, it's like too noisy scanners too. Noisy just down first one speed so and sneaks magic was really flipping the whole thing on its head instead of thinking about yet another security tool trying to solve a whole bunch of problems. No, let's go back to the real like as far into the start of the process of where the problems originate.
And that really resonated to me think okay, this flips the problem in the head, you know, we would stand on the stage at our say say, you know security needs to be built in not bolted on. No one really knew until sneak was created and guy put on the founders there just fundamentally took. Okay, let's make it easier for developers to do their job.
But you know subliminally in there the security keeps getting better and better and better and it's powered by amazing intelligence. So it's kind of you know feels like connection for a lot of parts of my Journey coming back together and circling back and yeah doing it the right way. Yeah exactly.
I tell people it's like we don't roll cars off the assembly line and say let's add some air bags. Yeah right for safety. You're gonna have to think about those things really early in the process and build it in.
Well, I'm curious so, you know, I've been in security world as well software world for a while, too and You know, if I put sort of my kind of jaded glasses on I could see him we're doing a lot of the same stuff but you know products I built in early 2000s and generations variations of that and sort of where's the new new innovation coming and yeah, there's there's been things happen, but it seems like the software developer World being part of blurring the the silos of network and security and software and and the infrastructure in a way that we have to address it. Yeah correctly. I mean it's a unique opportunity to do it, right?
Because if you think about the new stack it's all code. And the first party code software is composed not written out of Hope and source code deployed using IAC templates packaged and containers deployed on a cloud which is really code. And so can we take a different approach to secure a security in that context by and you know, the process has changed too.
You know Cloud native digital transformation all these buzzwords, right? But we'll deliver code what it's what it really is. Like we figured out how to do things in a more agile way and in the real meaning of the word You know terms like devops are thrown out some people think that okay.
That's also you know, is it a fad is it something else but I think that it's really about speed you think about business agility. Devops was the first step in the transformation. It's Devin Ops not working as I build code and toss it over we're working together.
So that was a transformation of it to make that happen. And so that it is more developers in it platform engineers and all that. Next Step security security needs to become part of that for devsecops to be real and it needs to do that's the transformation.
We have an opportunity. And you know, that's the Innovation we're focused on and there's a whole ecosystem of companies that are coming at it that way. I'll tell you what surprising for me is the other side of this and especially this week and walking the Expo floor and talking about it.
There's the other side. It's great. Here's a new set of problems.
Let me take the same old approach and I'll essentially build a scanner for the cloud. This is a prettier scanner. That's more correlation.
It looks better attack pads this that The risk there is the Christmas tree doesn't need more lights as one of the csos told me. and at the speed at which Cloud moves The next set of Lights in the next set of Lights you're throwing it in there. The whole thing is going to fall down right?
It's holiday season coming up. We all did our Christmas trees some of us did it, you know before they left so the timely analogy That is the risk the risk is to fall for a trap that loses a generational opportunity to change how we could secure things. You still need that safety net after the fact but that should catch very few and far between things not all the things and then pushing it back the other way.
So I think that's you know, there's philosophical differences. We come edit things opportunity of a lifetime to do it, right because the whole world is code and can you build it in so let's let's kind of take that open a little bit and talk about more specifically how to sneak do that. What's the approach that you take?
See fundamentally originated with what is an engineer one. They want to be faster. They want to be more productive.
So think about various code being written and IDs. Sneaks able to you know and real time do analysis as developers are writing instead of the old static analysis. It takes a few days, you know after and before you can shift this is doing real time analysis of your code and finding vulnerabilities.
It's powered by a security intelligence database that is world class. Even AWS uses our security Intel data. It'll just inspectors powered by it.
So and it's kind of the ultimate endorsement that you know, you think about okay that that intelligence is really powerful but for the dev it's in their context so it's and it's teaching them. Here's an issue. There's a recommendation based on all of our machine learning and how these kind of issues are fixed.
But if you want to learn more about, you know, cross-site scripting or anything real time, something called sneak learn will teach that you know, so developers are now learning about security but it's because we're helping them be productive where they live next thing, you know your packaging, you know your dependencies. Well, you don't know what those packages are using underneath. So we make that super easy and like map out the whole dependency graph and everything and then based on that instead of CVS and vulnerabilities you flag the risk of that in the wrist levels and okay.
What is it all per do they do a fixed PR they're merging their code in right there. Like we will allow them to generate of automatic fix PR. So Auto fixing the third party issues again, they have productivity with context and as a product management later, I always tell give the devopers context.
They'll build the best stuff. Don't tell them what to build and how to build tell them. Why what problem you're trying to solve.
So in the same approach we're taking and just rents and repeat along all the stages of the modern pipeline packaging containers, you know, which image of what layer what are the issues, you know, here's the best recommended and by the way, your company might have a custom image for that kind of issues. Here's that one in after doing the work, right? So we live where the developers live.
So they don't have to go somewhere else and we do those things in the workflow that they are actually doing their work so they don't have to change it and that's really the you know in a nutshell. It's like what snakes superpower we held the operation and formula one fan. We allowed them to go around the track faster with you know, the rules being outside of it like the guardrails but not putting speed bumps on the track the Outburst love that so yeah a really trusted friend of mine.
Said to me recently that. When it comes to security products, you can tell what security products have been developed by a developer for developers versus a security product. Right?
That's very apparent and I think developers like they can kind of stuff out whether you really believe in open source or not. They can tell if it's been created for developer and I think your point the metaphor I think about is think how far IDs have come today like I use my charm, you know for for python kind of stuff and it's all right there right as you're coding as you're writing stuff. Here's the here's the thing that this could be completed with like your autocomplete and then we're processor, but all the textual yeah content and your package managers right there and you can select and maybe there's a security rating.
Yeah something you can use to decide which you want to use but it's just the moment of creation. It's not calling for the city inspector after you've already framed ass to find out if they're going to pass it, right, you know, it's and the benefits show up for the security team, too. Right to the empowering but they're able to put policies they're able to put guardrails when lock for Shell happened 92% of our customers fixed it within 48 Hours not found it.
I the number of people I talked to this week saying clock for Shell was just like painful. It was eye-opening. It's you know, it took a month it took, you know, you didn't we had to cancel vacations.
And so I shared the stand and they go how is that possible and like it is build into how they know these companies are working. So, you know, that's That's the power for the security team, you know go from being reactionary. But when you need to be reactionary if you also have speed I'm going to talk about some of your recent announcements because you've kind of started developer-centric and then, you know thought about the bigger environment the cloud environment.
You know, as I said earlier, you know, we think about Cloud as code and it needs that same that is the opportunity that so we recently right before the conference launched sneak Cloud. So that's our fifth product in the portfolio. So we had you know code open source containers infrastructures code and now Cloud but it's really a platform.
These are not five products. They're like the OnePlus One Plus One you get a 10 kind of power in your hands and it now Maps the entire process and it brings context all the way back. So same thing again do we scan?
Yeah, you know, there's an assurance, you know safety net required, but it's not your classic cspm. It's more applications Centric. It's giving that I see engineer who might be platform engineer who might be writing something in a you know, a policy that exposes their bucket or some I am credentials.
In that context of you know, that's another you know, there's an IDE too right give them the context like this issue based on your Cloud configuration and what you're running is going to cost this kind of exposure and on the other hand on the Assurance side. Okay, here's an issue. What do you do with it?
Well, click here. This is the line of IAC code. You can fix it in or here's the best container package.
You can fix it in to go all the way back. So we're now connecting the whole Loop, right? So instead of you know, it's can't trust but verify and the way we think about it code to Cloud allows for that Loop to be completed.
So and and brings the context again all the way back to the person who can best fix it at the moment. And the security team is able to also empower the developers if there is something reactionary that needs to be addressed they know who to go to and this is the question I have with all the beautiful uis, and you know attack path and this and that. Who does this issue go to who fixes this the developer which developer who wrote the code?
In the modern devops shop, you're moving Sprint teams. You're moving an Engineers. You need that to be in what?
I don't know how to fix it. Right? It may not be obviously apparent that this is in my code here or whatever and security cannot support anywhere in that.
It'll break down right like so the scanning after the fact approach this knob work. Even you know on the stuff we did previously, right? It does not work at all in a modern Cloud native application devsecops Loop.
So that's sneak Cloud. You know, that's why we did it. We don't want to, you know, come at it from a cloud-centric, you know Cloud security, you know, big Market a lot of noise around it seen apps ESPN buzzword Bingo going on customers don't need more more acronyms more buzzwords.
They need an app-centric approach where the cloud issues all the way to the deployment configuration and back can be solved and it's exact same approach. We took for open source of exact same approach code. Now, we have connected the whole Loop.
So kind of turn your head around the other way and think about this from a security engineer perspective, right? They don't live and breathe the developers, you know environment and we're doing that kind of work. So part of that is a bit of a mystery just like the other way probably around.
How do Set this kind of approach does it look like? More I don't know how this works, but they seem to be doing something that's working for us or is it more red readily apparent and you can demonstrate how this is making an effect. And that's the journey in on the trick isn't even in the word that that you use security engineer.
You know, not somebody who's a you know, looking at it from an infosec reactionary perspective. But I think the part of this change here is is security teams now become more developer of air, you know security engineering and if you're having that mindset and you know, we have work to do to enable them and train them just like we train the help see developers fundamentally don't understand security issues. They know how to fix their code to make it work to do what it's doing.
There's too much a lot. You know, there's a lot to know so it was really making the developer security there now, it's making security debit there and that's that next, you know phase of the mission that were in the middle of but there's a cultural transformation and you know tools processes in context learning just like we did for the devs. How do we do it for the Security Professionals so that they can become more devere our customers who you know who are kind of made that transition.
It's a look what percentage of the world is that is in the cloud, you know, it's truly Cloud native you can it's all kinds of data out there. You know, it's a 10% 15% screw the early stages of them. Right?
And so this is the time to not let old bad habits. Just move to the new world, but you know just have the new approach indoctrinated and then make that transition to security engineering great. Well, it's been a lot of fun chatting with you, you know, given your your focused on developer.
I know you have a lot of ways to developers can get access and use your technology and kick the tires and try and work with it talk about how folks can can access or use what you have to offer. Yeah. This this is the this is the beauty of snakes.
io. And we have a free plan free forever. Right?
So if you're just a doctor who wants to you know, use it for the use they they subscribe to sneak and that's how we grew right? And so then that's how we continue to right. Fancy word again for this plg, but it's really about give them access let them use it and you know, like that's that's the continued philosophy.
So and anyone I meet I said look just go try it out. Like, you know, my kids are drying it up, you know, just, you know early coders the lights them to see that in context, you know, learning and verification so start there and you know, if an Enterprise wants to adopt it, that's usually what happens the biggest of the big companies in the world use, you know from starting Fortune One You're Snee but usually start with somebody in the dev team Who went found the Delight started using it and then it you know spread to the whole Colorful devro World democratization of them exactly technology. So well good.
I hope you've had a great conference and congrats on the announcements leading update. Obviously. Look forward to talking with you again.
So sneak that I/O sneak spelled a little bit differently. So Tom how Snyk, so now you know now, you know now you know, so now, you know, okay, is that really that is it that that is so now I know. Okay.
I was thank you very much for joining us today. It's been a pleasure talking with everybody. Thank you for listening on AWS reinvent with tech strong at our studio here in Las Vegas.
We look forward to visiting with you on other events as well as other great speakers and topics
