Checkmarx’s Innovations in Cloud-Native Security with Kobi Tzruya at AWS re:Invent 2024
Kobi Tzruya, chief product officer at Checkmarx, discusses his journey from engineering to product leadership. He highlights the launch of Checkmarx’s cloud-native application security platform, which is gaining traction among large clients. The conversation covers the significance of microservices, enhancing developer experience, and the role of AI in security. Recent product advancements in supply chain security and repo health are also shared.
Transcript
This is Textron tv. Hey, everyone back here. This is Alan Shimmel back here in, uh, Las Vegas.
We're at the Wind, uh, wind Studio at The Wind Hotel right across the street from AWS Reinvent Expo floor. Was able to pull my friend Kobe Siria. Did I get that right, Kobe?
Yeah. Uh, off, or, well, he wasn't really on the floor either. He's been in meetings since he got here, but he, we, he took some time out to come sit with us and talk a little bit.
Kobe is the, uh, chief Product Officer Check Marks company. We, we follow for a long time. Kobe, first of all, welcome.
Thanks for coming up. I know you're busy as heck, so I appreciate it. Thank you.
Thank you for having me here. No, it's a pleasure. Very much appreciated.
Um, Kobe, you've been on before, but I don't know if everyone remembers. Give us a little bit of your kind of background, your story to be as you became the Chief product officer at check marks. Yeah.
Well, I've been with, with check marks, uh, for more than 11 years now. Um, you know, for my first seven years, I actually built the engineering in the field, meaning, uh, the entire group that, uh, that deals with sales, engineering, professional services, technical account management as customer success about a bit more than four years ago, uh, our former CEO, he asked me to, uh, to take over a product in order to build our next generation product, which is, uh, check Markwan. Yes.
Our, our cloud name platform, uh, for, for application, secure for application security. And this is what I've done. Like we, uh, you know, we, I had, I spearheaded the leading building this platform.
Um, we actually officially launched it, uh, uh, three years ago. Yeah. Now we have over one, you know, um, about half of our a RR actually lives on that platform.
That's great. Just within, uh, three years, hundreds of hundreds of, uh, hundreds of customers, large customers are using it. It utilization of the platform is, uh, uh, skyrocketing.
Um, I think there's two, two things that that says though. Number one is you built a good product, right? Check Marks.
Bills. Thank you. Check marks, guys.
You're welcome. Check Marks has good. We talk about app dev and, and, and, and so forth.
Check Marks is a leader and builds has great product. Number two though, is the cloud native market. Right?
The cloud native market has really over the last three, four years, it is the stack now, right? It is the compute stack. If you are building something, you know, they use this euphemism modernizing applications.
When they say modernizing applications, they mean for the most part microservices, cloud native architecture. Exactly. I describe it as a Lego.
Yeah. You know, that's exactly what we did. It's like, you know, the former generations of, of apps where, you know, you had your front, your front end layer, your business logic, your database, right?
Right. Now it's a whole Lego. You have your propriety code.
Most of the code is, uh, is open source, open source. You have your microservices. Um, you, you, you have, uh, infrastructure is code that, that, that actually builds the, uh, the runtime environment that, uh, that, that, uh, that sure.
That, that, you know, that the material that you run, um, and then you api Yeah. Have exactly, you have, they stitch in all in one api. The other, you, you have, yeah.
You have APIs, so um, you have APIs, you have, um, you know, all kind of secret detections. Yes. All, you know, all of that kind of, you need kind of, if you really want to provide security, you need to build solutions for all that.
And this is why we thought that, you know, the right way to do it is actually to have a platform that will have, uh, you know, multiple, multiple scanners. But since you have so many scanners, because the technology is, is kind of Lego mm-hmm. Uh, Lego, you need on top of it an A SPN layer, that, that will provide you actionability.
Um, you also need, uh, you also need connectivity to runtime in order to provide you the runtime context. So it actually takes you to, to the next level of, of actionability. Does it really run in, uh, does it really run in runtime or it just lies in my repo, right?
In dev in the dev place. Yeah. In, in, in the dev place.
And of course, the entire developer experience. Today, our customers are the developers and kind of, we, we, we kind of will build that. So, so developers will feel comfortable and will have a, a very, uh, smooth and very good experience, uh, using, using the, using the checkbox, uh, platform.
You mentioned developers are your customer, you know, and look, I've been in developers are are users, users, necessarily users, but they're very, very impactful users. Yes. They're also highly impacted by this.
Right. com in March of 2014, so over 10 years, almost 11 years now. And, you know, shift left shift, left shift as far left as you could go.
Right. And then I think what we've seen again in the last three, four years maybe Yeah, two, three years, is that developer, a lot of companies made the mistake, especially security companies, not Jack Marks, but a lot of security companies that they gave security tools to developers and developers are not security people. You need developer tools for developers that help them build better, better secure, more secure code.
Not, don't mistake them for the security professional, but some companies made that mistake. Right, exactly. So, kind of, you know, when we started to build the, the, um, the CX one platform, we actually realized that, you know, that, that because the burden of security was actually shifting to developers, and they are the most, as you said, impacted Right.
And impactful users. We need to provide, we need to provide them an experience. And the experience is speed is, um, actionability and less noise.
Okay. Because you cannot waste your time. And also simplicity.
Yeah. Okay. Simplicity.
So kind of, these are the pillars that, that, that we work by. This is why I mentioned code to cloud, uh, the, the cloud integration runtime. Mm-hmm.
Before, why is it so important? We think that it's going to, we think that it's going to change the way application security is being done. Because if I can tell you, Hey, deal with, uh, vulnerability, X, Y, and ZY because there are the ones who really impact your runtime.
Right? Okay. And, and kind of, they're, they're the ones who are actually open to the internet.
So start with them. Okay. Yep.
So, I mean, but this is a lesson. Look, I started a company in 2001 called Still Secure, 2003. We came out with a, something called van Vulnerability.
Access and Management was a scanner, not not in runtime, uh, in runtime only, not, you know, pre-deployment. It was the same thing. Then, you know, we would, we used to internally, we would call it the bad news generator because it was a bad news generator.
We would scan your infrastructure, and we give you thi this is nothing, we give you something like a telephone. People don't know what a telephone book is anymore, but like a telephone book, you remember? Yeah.
A lot of people out here don't, but a telephone book full. And then, you know, some poor guy there would have to go through and say, okay, well, this is a priority. This one's not really accessible.
This one's not reachable. This is a, a Linux device. We don't have to worry about window stuff.
This is a port that doesn't get you. There was all kinds of things that allowed people to say, Hey, we're gonna get the biggest bang from my buck in terms of remediation, in terms of lowering my risk, which is what it's all about. So, so kind of, so here comes the next thing, uh, uh mm-hmm.
First of all, uh, first of all, you know, um, we also, we're not also, we're not only giving you the headache, you know, as, as you said, right. But bad news, Joe. So kind of let's say, you know, I give the bad news start and work on, uh, vulnerability, X, Y, and Z.
Okay? Right. I'm with ai, we're also helping developers to remediate.
Okay. So, uh, we, uh, uh, we have either autom remediation, right? Okay.
Uh, or guided remediation, because a lot of time developers don't like, they don't, like, don't like with their code. So kind of we guide them. This is all done with ai.
Okay? So we didn't have AI in 2003. It made it a lot harder.
But, but that brings up this whole AI issue, right? And the role it's playing here, uh, I mean, no pun, but it gets smarter every day, right? It's getting smarter every day.
And, and as we train it better and everything else, um, if it follows other adoption curves that I've seen, there will come a time where developers are gonna say, let the AI fix it. Right? I'd rather, you know, right now they're going slow because they don't have confidence, and maybe rightfully so.
So, so kind of the REI strategy is actually built again, on, on three pillars. One is detection, right? Okay.
Detection. Uh, we do that through, uh, integration with, uh, uh, with copilot. Mm-hmm.
Uh, integration with, so you're already integrated check Well, with chat GPT uhhuh, uh, we also have an engine of our own, which is called, which is called the VPA uhhuh. We embed all of that into the IDE. Okay.
So that's where it's at Today, the id, this is kind of, this is where it lives, so mm-hmm. It helps you detect things like, you know, SCA hallucinations, uh, bad practices of, of, of coding in real time within, within the ID for your AI generated code. So kind of, this is the, this is the detect the pillar, right?
The second pillar is what I talked before, is remediation. Okay. And maybe, maybe you, you're probably right.
Maybe there will come a time that, that the remediation will be it's a confidence build date. Exactly. So maybe there'll probably come a time that the remediation will kind of will be done automatically.
Okay. Automatically, yeah. For, for, for the garden variety stuff, right?
Yeah. There'll be corner cases. There's always corner cases.
And, and the third pillar is to secure your LLMs. Okay. Which I think it's also one big issue that the market is only now starting to, uh, to, to approach and build solutions for.
We are already deep in the research work on how we secure, how we secure LLMs, how we secure open source LLMs. I believe that that, just like people today, 80% of the code is not proprietary open, right. By open source.
This what will happen to, uh, this, this also, what, what will happen to, uh, to LLMs. I, I think you're gonna have sort of LLM marketplaces, most probably. You, you already have these, uh, you already have such, such companies that, and, and you, you know what, what they're doing.
That LLM you download from the marketplace might have 80%, 90% of what you need. And you'll customize just like real code. Today's the same thing.
Just, just like you do with Yeah. Building code, just like you do with open source. This is why securing, securing open source of lens is, is going, is going to become, is probably going to become very, very big.
I, I, I agree with you a hundred percent. We are at AWS reinvent. I gotta bring some AWS.
So they made some announcements also around AI and ai, the Q developer tools, and actually came out, they came out with their own ai, their own GPU Silicon and their own sort of Chad, GPT, I think it's called Nova, Nova Light, Nova Pro. Um, you mentioned working with copilot. Uh, you're a, you're a, uh, a partner at AWS.
We partner, are you working with the Q Tools yet, or the a Yeah, we're, uh, we're, we're working on integration with, uh, with qq with Q Tools also working, uh, on integration with, with Bedrock. Yeah, with Bedrock. These are the, these are kind of the, the two, the two AI pillars that, that we're, we're working on with, with AWS.
Okay. We have very close relationship and, um, you know, the outcome will probably be seen, uh, sooner, sooner than later before RSA in the end of, uh, April. Yeah.
Okay. Yeah. I'm, I'm gonna press, I'm gonna press the button.
You'll press the button on that. I wanna bring up another area though that Sure. Uh, I think is important and at the part of the learning of developers not being Security Pros has been the emergence of what we call platform engineering.
Yeah. Right. So if we can give the developers a better house, a better environment, a better environment to work in, that already has some security rules in it that already has sort of guardrails in it, it allows them to go faster and again, not have to worry about certain things.
They just worry about their code. How does check Marks view that whole, I mean, a lot of people say, eh, we call platform engineering when it's really ops, right? And, and it it is and it isn't.
Right. They do. It is, there's a lot of the old ops stuff is in there, but how do you guys look at platform engineering?
We think that it'll become a domain. Yeah. Okay.
This, this, this is what we think of it. And you know, we, you know us for a long time. Yeah.
We're the first one who were integrated into pipelines into IDE and, and also into the, uh, what before it was called the Dev, uh, DevOps. Yeah. It was DevOps, dev SecOps, dev SecOps, and SecOps.
So I, I see it as the kind of the next step of the DevSecOps, and I think that if we'll be, that will be able to provide solutions that will be part of that. Okay. That, that, that will be part of that and kind of will give the, uh, you said guardrails, right.
Uh, for, for security, either in, uh, the DevOps part of the, uh, platform engineering, um, and also with the, uh, also, also with the direct tools that developers use, like IDs and stuff like that I mentioned before mm-hmm. Which is kind of an engine that provide you real time feedback on your, on best practice of, of security. I love it.
I, I, I think that this is where it goes. The, and these are the solutions that, that, you know, we, we are, we are building excellent at, at the end of the day, you know, we live there. Absolutely no one.
I know it'll be real when you come here and tell me. Developers and platform engineers are our users. Yeah.
Oh, okay. Yeah. Right.
That's when I know, okay. It's real. Right?
Yeah. Um, but I agree right now, you know, um, platform engineering is something that people start to talk about. Yeah.
We have to see kind of how catchy it'll be in, in, in, in reality in the market. But we are building tools for it. You have to, you have to.
com, our site, our platform Eng. 'cause Yeah, I've been doing this a little while and I, I watched these things. I watched because you don't wanna miss the boat.
Of course. You don't wanna be too early. org, the community, they got 300,000 people in the community there.
When I go to CubeCon, I don't know if you were out in Salt Lake City, uh, recently for Con, a couple weeks ago, months ago, I was lot of talk around platform engineering. I, I think this is, as you said, this is becoming a domain and Absolutely. Now is the time, I think to kind, not a land grab, but put your flag down, stay, you know, claim your, your, your, no.
Right. As, as I told you, you see that kind of word. Yep.
But I think it'll have, its, I think what we're gonna see is AI is gonna bring all DevOps, dev, SecOps, platform engineering, SRE, traditional security pros. AI is like shortening the distance between all of that. Of course.
Also observability. Yeah. Also observability of Yeah.
Observability. Well, yeah. And how you fix issues once you, once you, uh, you know, once you identify something in your observability, you know, we run cloud platforms, so kind of we are eating your own dog food with Yeah.
You see for yourself. Exactly. Absolutely.
What else? Exciting from check marks. I know we talked, we probably overtime, but what else do we got?
What else do we got? Um, you know, we released a supply chain security model, uh, just last, last month. Uh, which actually includes, uh, first of all, secret, uh, secret detection.
Yeah. I mentioned earlier. Yes.
Secret detection and also repo health. Oh. So what exactly is that?
Meaning we look at your repo, uh, the code and open source, uh, and mainly open sources that are in there and based on our knowledge, and we have a huge database of, uh, open source packages. Mm-hmm. Not only kind of the standard vulnerabilities, but also malicious, and uh, also based on info that kind of, we track the contributors themselves.
We can kind of provide you a, a grade of your, of your, of, of, of your What about, what about of, of your, of, of your, of your, of your overall half of, yeah. So it doesn't make a difference how many different repos I'm pulling on. You know, you're just looking at all of that.
And, um, you know, we also, um, uh, we're also working hard on our, that solution. Uh, you know, we, uh, um, zap is now powered by, uh, by Zap, by by Checkmarks. Yes.
The core team of Zap is actually employees. Employees of, of Checkmark. So kind of we are impacting, uh, we, we we're, we're impacting there.
Um, we also released a new, uh, containers, uh, security model really in, in August. Yeah. Which is, uh, kind of topnotch.
Uh, we have very, very good, uh, very good, uh, feedback for that. We have our, uh, we have our integration with Wiz, which is making a lot of noise and getting a lot of, a lot of attraction also with Cystic. That's, that's the runtime, eh?
Yeah. I know. Cys, we, so both companies, we cover a lot.
Yeah. Uh, that we have. Um, and we are, um, as I said before, we're working very hard on improving the developer experience and user experience of, of, of the platform.
We're getting good feedback. So for that, uh, for, for, for that as well. Mainly on the simplicity.
Mainly on the simplicity side, so, sure. Kind of. Well then, and we need that and AI will change it every day.
And ai, we talk about it all the time. You, you ask me, you it, that the, the study, it just sucks the, of every conversation. No doubt.
No doubt. Anyway, Colby, thanks for stopping up. It's always a pleasure my to see you.
Thank you. Check Marks. com.
Dot com. Exactly. Go check them out.
We're live here in Vegas at a Ws reinvent. I hope it won't be till RS actually, you might be doing something with me, a panel I'm doing on Predict. Did they mention this to you?
Um, not yet. I'm doing a c I'm doing a CPO panel. Okay.
I'll, I'll be more than happy to, to be there. January 9th. Our Predict 2025 conference, Kobe will be there.
We've got, uh, David DeSanto, the CPO from GitLab and a few others. Well, I'll talk to you about it. Right.
All right. We're live at AWS reinvent. We'll be back in a little bit.
This is Alan Shimel. Until then, stay tuned.