Innovating Cybersecurity: Insights from RAD Security’s CTO Jimmy Mesta
Jimmy Mesta, Co-founder and CTO of RAD Security, shares his journey in cybersecurity and the evolution of RAD Security. The focus is on enhancing cloud and container security for ephemeral workloads using AI and autonomous agents. He discusses the balance between AI’s efficiency and the new vulnerabilities it introduces. The conversation emphasizes the need for vigilance in the fast-paced cybersecurity landscape and invites collaboration with RAD Security.
Transcript
Hey everyone. Welcome back here to Tech Trunk tv. My next guest is Jimmy Mea.
Jimmy is co-founder and CTO of Rad Security, RAD Rad Security. And Jimmy's pretty well known within the cybersecurity world. I've, I've known Jimmy for years.
It's great to have you back on Tech Drunk tv, Jim. How you been, man? Good, Alan?
Yeah. I think the last time we hung out was in, was in Singapore at, uh, at, I was at RSA, oh, that Was I think an RA, uh, apac. Yeah, that was a while ago.
Yeah, right before COVID, I bet, right? Yeah. Yep.
Right around that time. Yeah. So could have Sworn I saw you in RSA.
Yeah, it probably ran India there, but I think we actually, uh, yeah, that's sort To Have a One of these. Yeah. Yeah.
Yeah. That was pretty cool. Yeah.
Yeah. I wish RSA would do that again, like do the, the worldwide Maybe they will, you know, they, they, they're on this new trajectory now to be the community and I, I hope they'll start expanding again in, into, uh, Asia, Europe. Yeah.
Anyway. Hey, but enough about them. Let's talk more about you, Jimmy.
Tell people a little bit about kinda your background and your journey. Sure thing. Yeah.
Um, I, I've had a long, long tenure in cybersecurity, so, uh, 16 or so years. Uh, fun fact, I had the, the first cybersecurity degree from Penn State, so it was NSA sponsored, um, you know, kind of computer science switch over into offensive hacking and CISO roles. Uh, worked a lot at AppSec and then all, all the roads led to infrastructure security.
And, um, then about four years ago, uh, you know, joined up with, with Brooke, my co-founder, and we started what was, what called KS O. And now, uh, we've been RAD security for, you know, a little over a year. And, uh, yeah, it's been, it's been a journey.
So done a lot, um, still a lot more work to be done now. Agreed. Agreed.
Um, talk about rad security a little bit. Yeah, so, uh, we, we started with the mission of, um, kind of rethinking how, how cloud security and container security, you know, are done. Um, the evolution of rad security was, uh, always, always meant to be, you know, real time solving real problems with all of the context that you need to, you know, secure, um, highly ephemeral, fast moving, um, cloud workloads and, and cloud assets.
And that has, uh, been kind of snowballing into, uh, what we are today, which is still, you know, those, you know, solving those problems at our core, but, you know, helping teams do more with less. Uh, the big, the big thing our sort of AI offering these days, um, and our AI native tooling and detection offers is, is really that, that team extension. Um, so we have a lot of different, uh, you know, we call them rad bots, uh, that, you know, act as, as independent autonomous agents that can, you know, take on complete tasks, uh, from start to finish for security teams.
Um, so that's what the platform does. Uh, and we've been hard of work just, just trying to solve those problems, um, and using AI in the process. Very cool.
Very cool. We all seem to be using AI in our process, Jimmy, right? And we, that's right.
And we, uh, you know, you, you can't walk three feet without tripping over ai. And now of course, agen, I had a guy tell me today that, uh, you know, the whole generic AI experience was sort of ephemeral a halo, and it's all about agentic ai and that's what, you know, where it's at. And of course, today that it is, maybe yesterday it wasn't, and tomorrow it probably won't be again.
But right now anyway, it's, you know, not the age of Aquarius. It's the age of agentic ai. So talk to us about, now, I've always, well, I have thoughts about how much of a agentic AI is just dressed up APIs, right?
API integrations, how much of it is just, uh, generative ai, you know, wrapped up? Tell us, you know, gimme your thoughts on this. Yeah, there's a lot of, uh, yeah, mar marketing, uh, speak circulating on a GI AG agentic ai, and it is hard to kind of differentiate what's real, what's not.
Every, if you don't have an AI offering in your product, you're, you're behind. Um, and I think for us, the, we started using, well, I'll say LLM inference for core detection capabilities, um, a while ago. So we never, our runtime product, you know, has always been, you know, AI centric.
So we, we kind of learned the ins and outs of how to do that at scale in very high throughput environments. And then, um, we, I guess, saw the light because it worked and continues to work really well for that use case. But it's not as easy as kind of slapping an LLM on top of a, you know, data or, you know, just summarizing a finding that existed prior.
It is different, um, when you're, you know, deeply embedding ai, we'll say like AI infrastructure or, you know, agents into the, into the, into a product or a workflow. Um, so, you know, an AI agent itself, things that we do, um, you don't know if we check every box of an agent, but we do, uh, a lot. And a lot of that is, is the ability to, to plan, right?
And, um, be autonomous. So run and execute based off of triggers or conditions, passing data from one agent to the next one, bringing a, a human in the loop when necessary. Um, integrating with other systems where it's, you know, you know, uh, external third party SaaS products or databases or, um, things like that.
So you really have more of a goal oriented autonomous AI enabled workflow versus the chat GPT one, one-shot prompt experience, right? Where it's like, you can get a lot out of that. You could paste your logs in, you know, file and send it to chat CPT and ask it to do things, but it stops there, right?
It's not, it's not doing that in a autonomous fashion. So, um, I think a lot of cybersecurity tools have just done the, like, I'm gonna summarize my findings with, you know, an LLM and have a little, you know, magic wand next to it, and we're gonna call that, you know, we're AI native, it's useful, but it's not really leveraging AI to its fullest extent, um, to get tasks done, which is what we're, we're trying to accomplish with our product. You know, I, I'm a, after I'm done in this studio or in this setting, our studio, I'm, I'm heading number to our shimmy said set over there, and I'll be talking about AI and a Microsoft, you know, announced this thing this week, a study, but AI being four x more accurate with diagnosis for doctor, you know, for medical conditions than human doctors.
The fact of the matter is, as it relates to generative ai, it seems like, excuse me, all of the attention is being focused on how well it could write, which is kind of what you were talking about, right? You give it a bunch of stuff and say, write me a summary, and it, it's good for that. Uh, marketing writing is, it's good for, but then you get like, um, uh, you know, what else?
Is it good for coding? People are using it for coding a lot, right? Yeah.
Like, there's an outsize amount of attention spent on that, it seems, I don't know, Jimmy, um, where, you know, it, it, it, it's, it's, there's a magical element to it. I'm not like, I, I don't want to be, I'm not crapping on it, you know what I mean? Yeah.
But how much better is the, a true agent AI experience gonna be? I think we're in the biggest boom that of, you know, technology boom that I, through my lifetime, um, I, I, it's the experience, it almost sounds dis dystopian, um, is, you know, we're, we're go, we're not gonna need to hire, you know, instantly think of hiring somebody when we have a problem or a project or, you know, a long, long-term, um, goal. We're going to think, can I, you know, and, and should I deploy an AI agent to own this task and have it report back to me?
Only one appropriate? And I think we're headed in that direction pretty quickly, where yeah, it's not perfect, right? But humans have never been perfect in, in their assessment of large data sets and, you know, noise, and the people make their own level of hallucinations.
So I, I think what AI is gonna be really good at for security practitioners is, is just distilling and contextualizing the volume of data that you have to deal with on, on a day to day. Um, and just knowing where to look for those things that, you know, getting, getting tasks done that you typically would've planned for a quarter, uh, a year. It, it, it really is, you know, heading in a direction where, yes, you need expert security engineers to know how to interact and prompt and ask the questions, where to get the data, but a lot of that heavy lifting of, you know, just boilerplate, um, you know, stuff is gonna be taken care of by ai.
And I, I think we're way closer to that than a lot of people think. I, I don't disagree with you. I don't disagree with you at all.
Um, let's talk specifically about security, though. What does this mean for security? Well, it's ev it's, it's everything.
It feels like insecurity is always a, a, a trade off or like a double-edged sword, right? On one side, I think the efficiency gains that will get, um, for compliance, security, engineering, the traditional roles, uh, they're, they're huge, right? And, um, they can't be ignored.
But on the other side, now we have to protect this new extremely sort of volatile morphing infrastructure that is ai. Um, you know, we have to protect ourselves from that, right? We're, we're, we're now unleashing new technology that we don't really know how it's gonna respond.
Uh, MCP servers and, uh, you know, vector databases and RAG and all this stuff is like, becomes yet another data problem. Um, so we have to protect the tool that we have to protect the ecosystem that's giving us all these efficiencies also. So it means security teams have, um, in one side, you know, maybe some of the boring stuff that we've been doing for years gets automated.
On the other side, we have to level up in how we actually protect AI workloads and, and the usage of, of this kind of infrastructure, which is still very nascent. Got it. Um, Jimmy, I wanted to just mention another term.
You get your GTP wrappers. Mm-hmm. What do we mean?
Yeah, I think when people say, yeah, GPT wrappers, it's, it's a, it's a way to leverage, you know, a a, a popular frontier model. You know, like, uh, you know, four oh or something kind of the chat GPT experience, um, leverage that inside of a product to kind of say that you are doing ai and we see this all the time, right? It's like, um, it's, it's the, the generic chat bot that comes up in the product and you can ask it questions or the intelligent summary feature, right?
These are useful things, but they're really just throwing your traditional hardcoded finding text into a GPT wrapper and giving you like, you know, a better overview. Um, and, you know, there's, there's, there's nothing wrong with that inherently, it's just, it, you know, it shouldn't be confused with actually building AgTech workflows that Right. Our autonomous, right.
Very different. Well, I think what missing is autonomy there, right? Yeah, exactly.
I mean, to me, the, the classic GPT wrapper is, you know, when you do a Google search now and it comes up with the little Gemini think first. Mm-hmm. Yeah.
It's a little bit of a better mouse shot for search maybe, but maybe if it's accurate. But, um, yeah, I mean, I, I'm, I'm, I'm glad Google's embedding Gemini somewhere at least, so it's not, you know, it's a step in the right Direction. So they changed the name and do something else.
Who the heck knows? But yeah, I, you know, it, it's interesting, you know, so from where I sit, right, it's not just security, it's development, it's cloud, it's infrastructure, it, and ai of course. And it's just, you know, you see, like you said, it, it's hitting everything, but some of it sticks and some of it doesn't.
That that's kind of my, you know, and a lot of it is more hype than real. But here, I think what you said is true though, too. Like every, all of these kinds of things when it comes to security, it's a double-edged sword.
'cause the bad guys are doing using it really well too already. That's True. Yeah.
That's, uh, we were talking about this yesterday, like when a new CVE comes out, um, and that CVE could actually have been discovered by AI coding analyzers also, but it used to be the turnaround time from like discovery publication to exploitation. You maybe had a little bit of time. Right now, I think it's changing quite a bit because if you have a little bit of information on the package that's vulnerable, where it's used, like the attackers can literally supercharge their, their methods on deploying that, finding those issues and exploiting a CD like, that's just one example.
But yeah, they're moving fast for sure. Agreed. All right, Jimmy, we're about outta time.
Did we mention Rads website? Yeah, we're not yet. ai of course.
Um, of course, yeah. As, as as Warren does. Um, yeah, and I'm, I'm, you could find me on LinkedIn.
Easy to find Jimmy Mea, uh, happy to chat. Uh, um, we're at all the conferences. We'll be a black hat and um, you'll Be a black, we'll be there, actually, we're gonna be doing video on the show floor there.
Okay. So If you see me come over and say hello, I'll, I'll definitely come, come, uh, say hi. Yeah, we have a booth and we have a bunch of new team members.
We're growing. Um, we're hiring engineers, so if you like building AI agents also, um, definitely let me know. Very cool.
Alright, I'll see you in, uh, summer camp. It's gonna be hot. Yeah.
Oh man. I'll be i'll inside it there in August. Me too, man.
Don't look for me outside. All right, Jim, it's great seeing you. Good luck with Rad.
Keep us posted it. It's gonna be an exciting time. For sure.
Yep. Thanks Alan. Good to see you.
All right, Jimmy Master the co-founder CTO Rad Security here on Tech Trunk tv. We're gonna take a break. We'll be back.