John Amaral, Slim.AI | RSA Conference 2023
Vulnerability management is crucial in today’s software ecosystem. The world has access to plenty of efficient vulnerability scanners, but we are lacking a scalable way to manage and remove vulnerabilities. Developers in particular, need a way to automate the process of identifying and removing vulnerabilities in container images during the build process, and DevSecOps professionals need a way to track and communicate what they’re fixing. Organizations are struggling to keep up with managing CVEs and are drowning in CVE noise. Automatic Container Hardening can solve this problem, by producing precisely hardened, deployment-ready containers without burdening developers with more manual processes.
Transcript
This is texturung TV. Hey everyone. We're back here live after our lunch break.
It's Wednesday of RSA week read quite a crowd here down here. I don't know if you saw yeah, the guy from Eric Idol from Monty Python was signing books. So there was a line out the door here was pretty cool.
But I guess the books have run out everybody's back in sessions. Excuse me. Let me introduce you to John Amaral.
ai, and we're going to hear all about it. Hey, John, welcome to Tech strong TV. Thank you very much for having me.
It's a pleasure. So John. You know, what brings you here today?
How did you tell us about? We're gonna talk about slim but tell us about John. I've been in cyber security and software development for about 25 or 30 years.
I'm not as young as I look and yeah knock on wood and you know this I come to RSA. I don't know 20 years running something like that whenever they've had it I come. Yeah because of the industry.
I'm in. It's always exciting to see all the new stuff that's going on. I use it as an opportunity to get a take on the on the market I get to take on the Technologies the other competitors we have my background has been in as I said building SAS security companies and security companies for a long time prior to doing this job.
I was the I was the head of product for Cisco Cloud security, which is a big business unit there and we had a portfolio of security products SAS security products Etc. They were very popular products at Cisco and there's been a series of these kinds of companies where I've built pretty exciting and really effective security solutions for us now at slim we're focused on some new problem sets that we've encountered as we've built software and helped people, you know, defend themselves. We've really taken a new take on it with us and it's fun.
It's fun to build new companies. Absolutely it is, you know, I haven't done this my whole life, right? I Co-founded three or four Venture companies myself in there's nothing that gets you the juices flowing right, you know and and Beyond the companies I found it.
I I've helped some VCS back in the courage suit days of calm, right and I got a chance to meet a lot of Founders a lot of entrepreneurs and every entrepreneur has a story. Right? Right?
No one no one sort of half-heartedly would subject himself the founding a company unless they were like uber passionate right and thought in some way what they would do when was making the world better. Even if it's in a small way, right? But they're making someone's life better in addition to their own.
What was that for you? Sure, so cybersecurity in general to me is a great Mission. It's you know, protecting Everyday People organizations Enterprises our country from cyber adversaries to me is really good work.
And I've had the Good Fortune to have some really big platforms and some pretty good ideas for how to do that. Yeah, and turn it into products and technology and techniques that have proven to work and I don't you know, I've probably helped my share and that's really a core passion of mine protecting from cyber crime and all that for us for for this company someday. I we really were driven by some some passion that we found through a couple of different sources one is we thought that app Security in general was really hard to do having built a lot of SAS companies and build a lot of big applications.
We always struggled on the developer side of the equation to get our software to be secure a sort of By Design from the beginning. It was a lot of fixing things after the fact really building moats and building, you know firewalls and I've been there protecting things as they're running. We said can we just take a from scratch approach to finding a way to automate security for applications while they're being built that was really part of the part of the drive for this company the second part my co-founder a few co-founders, but my my co-founder that runs the business with me every day Kyle Quest he's and we've been working together 15 out of the last 20 years.
He's been with me at Several of these companies. He had an open source project. We call it some toolkit.
It used to be called Docker slim. It was really successful in the open source space at solving some of the problems. We thought were really core.
He's been working on it for years is kind of a pet project sure and we had a conversation several years ago about what he was doing with that. He explained to me how he thought it could solve some of the key problems. We thought were really Able to solve and let me turn it into a company.
So a coupleing our passion for cybersecurity with this kind of new technology plus a vision of the future. We put it all together and I left a really really awesome job at Cisco which was to do it. But you know, if you feel it you feel it man, right?
That's right. That's exactly what it is. You know.
I was out in Amsterdam last week a cube card nativecon, and I will tell you this whole idea of Of kind of securing the plumbing if I could call it that not necessarily the code that we've been working on the whole shift Left Right secure the code while it's in get and get Ops and all that but securing the plumbing so that we give an environment to developers. Right? Right.
It was a very very hot topic there Ops was back in Focus secops was in focus. Here's another thing though that I've seen John and this is the new compute This Cloud native stack is the new stock. It's the new compute.
Correct. This is the way we're building stuff now and either you got to get with it or you're you're gonna get rolled over right? So it sounds like you know, Darker slim slim I a slim AI was the right way to God.
That's another quick story. So Cloud native now our Cloud site. I went to the first or the second dockercon.
I came back. I said we we need a side around Docker right and I went looking for Doctor domains and I you know, we're gonna get sued so I called it cloud and container Journal, right? Glad I didn't use Docker, right?
But containers don't even begin to you know. Express this whole Cloud native thing so but let's come back to slim. Yeah.
If you go look into this camera, which is where our audience is watching you. How would you describe I mean you kind of talked about the problem? Yeah, and what you solving but how would you describe slim AI to them?
You gave me a perfect intro. So you talked about just intersection of infrastructure and applications, right? And this shift left movement to get the capability to build things well and fast and secure closer to the developer give them the ability to do these things.
You're absolutely right. So in a cloud native sense, the new operating system is kubernetes, right the infrastructure and plumbing or a combination of AWS and containerized workloads. And the unit of software today is the container.
That's what runs you put a container on that system you get that thing so containers by default now right our are the widely accepted unit of software. i acts on those units of software acts on containerized workloads as the container itself. And what we do is we apply some pretty cool technology that we've invented to evaluating analyzing and and interacting with those containers.
They're in your CSD pipeline in the developers areas in in the in the developer zone. So where it's being created and where it's being built. We intercept there and our primary use case folks are using us for right now is to understand evaluate and automatically remediate vulnerabilities in containers.
So we we can look at a container understand everything inside it. Evaluate it give the developers a lot of viewpoint on on the security and compositional integrity of that container after we are able to watch it run through your tests. We can then create a new container that is an optimized version for security and composition and when we optimize it we can usually remove like 60 to 80% of the vulnerabilities remove 50 or 60% of the packages and turn that into something hardened and ready to run securely as a as an optimized workload.
We give a lot of other stuff around that you could classify us as a software supply chain security company because we're really looking after your your your population of containers that are meant for production and minimizing their risk surface and the security risks around software supply chain developers. Love it, you know our open source technology that bread this is been adopted by tens of thousands of developers. We got like a million downloads.
So Legacy of being able to do this is pretty sound but really we're trying to help organizations tack. Problem of am I sure that I have something really secure and minimum going into production when I ship a container. I love it.
You did great. Awesome. You're hired.
Oh, I think you could be a spokesman. Yesly. Yeah, you know, I've been hired for a while, you know, you know the startup will you just said I'd not get fired right exactly.
All right, so we're here. Now RSA, it's back. A lot of people what's news from slim AI here at the show.
Yeah, so what we're out doing is really kind of helping engage and interact with all the security practitioners on a few things one is is this problem of automation for vulnerability remediation you get a vulnerability scanner. Everybody's got one it puts out a laundry list of vulnerabilities. It's a lot of work to triage those and under the current climate of heightened scrutiny on vulnerabilities people really have to do work to get those out of the out of the software.
What we're doing is helping folks see that there's an automated way to do that that doesn't require a lot of engineer and and security Ops work. That's that's kind of the message. We're telling and we're getting folks, you know to kind of kind of engage with us on that.
It's been pretty good for that. The other thing we have slim AI right? Yeah, I part of our name right part of the what's talking about a day.
I know it's I haven't heard I haven't heard of what I've heard a million times not once you know this intersection, I think there's three main themes that we're seeing and it's part of our message. It's it's The heightened awareness of apps and vulnerabilities and just making apps secure a second part is automation. You know, you need to do things that give organizations leverage and this economy.
Every organization is lack of resources. They're lacking time. There's more to do every day with less people less less energy to do it.
They want things that automate away tasks that can be done and and you can keep your developers and your Ops people devops devops people focused on core, you know, the things that they need to have all their attention on so that Automation and security theme around apps is really interesting and good now it intersects with AI right because because with generative Ai and large language models, you can really get some leverage now in these automations to give insight and to really bring a holistically New Perspective to automation. So these are the places I think a really interesting and for us we're bringing some of that into our our work we do we have a lot of proprietary. Rhythms and heuristics, but it's really interesting time for security.
No, there's no doubt about that. No doubt about that. You know, it's so fine feel like I'm back in Amsterdam because we spoke a ton about these things right iCloud native con kubecon as well.
So you've got a chance down to walk around the show a little bit you'd spreading this gospel. What are you hearing back from people? Yeah, the common things I'm hearing back from people are is security and developer teams are burdened with lots of things.
Right? I've heard statistics like, you know, 20 to 25% of development resources are focused on security remediation problems that devsecop team is hard to hire these people it's hard to automate it's hard to get automation done. And so I think what's really resonating is this idea about automation you gotta you have to take shift left is great.
As long as you're not shifting extra difficult work to the left because you know on the left the primary role is build applications Drive the top line of the business, right? These are every company is a software company. So if if you want your business to grow you got to have your developers freed up to do that.
So let's not shift left and create new manual work. Let's shift left and automate jobs. They have to do now that are difficult that are manual that are things.
They really don't want to be doing take that off their plates make it something to just happens automatically and with container security. That's what we're trying to do so that message Really resonates. Well, the automation themes that we're hearing resonate well and and the struggles that we hear from from most teams about like having to to do too much work that's difficult and hard and and and and really Falls outside of the normal task to developers.
These are all themes. I'm getting you know, absolutely I I I'm here the same things man. ai is obviously the website.
People who aren't at the show and watching us John. How did they engage? What's the on-ramp?
dev is is our is our our SAS portal application. You can sign up GitHub gitlab, Google. Now for free you can test everything, you know, we're in we're in a state right now where we let people just do whatever trial they want.
They have access to whole platform super simple and then we engage with folks that want to go deeper and turn it into a commercial relationship, but we believe in letting folks. Try it before they buy it food test drive take it for a test drive. We're super open to feedback and and we're always willing to engage with anyone who wants to talk to us about something they'd like to see or something.
They are interested in we're early stage companies still series a company so engaging with users and and building the best product we can is really our primary Mission. So yeah, go. Try it out.
Call me. Give me an email. I'm happy to do it get a heck of a good job John.
Thanks manitiative. Hey slim Dade ai go check it out. Like John here said we're live.
We're in RSA. We're gonna be back in a minute with our next guest. Thanks everyone.
Thanks everyone.





