How Product Management Shaped a Security Career
Sondhi started as a product manager at EMC Corporation in 2005, building hardware and software products. When EMC needed to define its product security story, she raised her hand. The product manager’s habit of asking “what value does this give my customer?” stayed with her. She carried it into security at EMC, then Autodesk (where she became CSO), then Twilio as Chief Digital Officer. Taking a board seat at Rapid7 added the perspective of a director who receives security briefings rather than delivers them.
28 Million Developers and 90 Minutes of Coding a Day
70,000+ SaaS companies exist today. 28 million software developers write the code running inside them, 50% more than 20 years ago. By 2030 that number reaches 45 million. The OWASP Top 10 from 2021 still shows broken access control, broken authentication, and session management issues, mostly unchanged from 2006. Microservices and APIs added complexity but not fixes. Meanwhile, the average developer spends under 90 minutes a day writing code, squeezed by alerts, triage, performance, and resiliency demands. Application security teams have a shrinking window to reach a very busy customer.
Using a Breach to Move Faster Than a Normal IT Project
Two years ago, Twilio’s attackers ran a smishing campaign against employees. The company had a second factor of authentication, but it was smishable. Sondhi moved all 8,000 employees to FIDO-compliant WebAuthn in days. A normal IT project that size takes months of change management. The breach created permission to move fast. Her lesson: treat a security incident as a capital budget for change. The security enablement team that handled customer calls post-breach often left those conversations after customers said they wanted to replicate the program themselves.
Security That Closes Deals
Sondhi sorts companies into two types: those that build trust proactively, and those that care only after a breach. For the first group, security professionals should position as revenue contributors. At Twilio, BISOs sit matrixed to R&D teams, representing security to engineering and bringing engineering’s needs back to the security org. A separate security enablement team joins sales calls and does objection handling, earning the most internal recognition from sales and product. Her team also mapped Twilio’s security non-negotiables to the top 10 questions in customer RFIs, giving engineers customer-facing justification for every requirement.
AI in Security: Real Value Without the Firehose
Sondhi wears two hats on AI: security and IT. From the security side, she’s nervous. Attackers use AI too, and false positives are already a problem. Adding AI without a human in the loop makes that worse. From the IT side, she’s enthusiastic. Twilio’s IT helpdesk runs conversational AI that routes common questions and frees staff for more complex work. She initially doubted it and was wrong. OWASP’s LLM Top 10, with prompt injection at number one, supports keeping humans in the loop. Her position: real transformation is coming, but the system is not ready to run unsupervised.
Secure by Default: Closing the Usability Gap
Sondhi frames security and usability as two kids: most days you pick between them, some days you get both. Zero trust network access at Twilio replaced VPNs accumulated from acquisitions. Engineers who toggled between VPNs now use one access path. Her measure of progress: her mother, in her 70s, has MFA enabled on multiple apps. On secure design: build it in by default, don’t bolt it on and wait for customers to opt in. Find, with data, which customers aren’t using existing security controls and run a targeted campaign before the next breach forces the conversation.
Notable Quotes
there are like 70,000 plus SAS companies Reeny Sondhi · ▶ Watch (11:20)
take full advantage of a crisis of a breach Reeny Sondhi · ▶ Watch (18:02)
the AI problem is also a data problem Reeny Sondhi · ▶ Watch (43:41)
Key Takeaways
- The average developer writes code under 90 minutes per day, making the AppSec access window narrow.
- A breach creates organizational permission to move faster than any normal IT change project allows.
- Security that closes enterprise deals earns more internal credibility than security that blocks deployments.
About the Speaker(s)
Reeny Sondhi is Chief Digital Officer at Twilio, responsible for the Information and Corporate Security organizations as well as Information Technology. Before joining Twilio, she was Chief Security Officer at Autodesk, where she drove the company’s security program.