PODCAST · technology
SecOps Confidential
by Exaforce
Behind every security program are the unseen stories of chaos, resilience, and reinvention. SecOps Confidential brings those stories to light through candid conversations with security leaders, CTOs, and practitioners who have built, scaled, and rebuilt their SOCs from the ground up.
-
4
Building security operations from scratch and when MDR makes sense with Raghuraman Sethuraman
Most security conversations happen on the security side of the org chart. Raghuraman Sethuraman, VP of Engineering at Automation Anywhere, has been in the room from the engineering side, and the view is different.In this episode, Raghu joins host James Berthoty to talk about how one of the world's leading AI automation platforms thinks about security from the inside: how product security, infrastructure security, and IT InfoSec operate as separate functions but stay tightly coordinated; why AI-generated code from coding assistants is creating threat vectors traditional security processes weren't built to catch; and how to break AI security into three distinct areas, coding assistant security, prompt injection and system prompt security, and runtime monitoring.They also get into what the explosion of internal agents actually means for security teams: every department will have its own agents, each needing access to specific data, each requiring identity controls and secure communication protocols. And why the organizations that aren't thinking about agentic security frameworks today will be the ones caught scrambling when adoption hits.Raghu's advice for security leaders: governance cannot be an afterthought, and one to 100 happens very fast.
-
3
Building security-first crypto infra and the CTO-CISO partnership with Srijan Shetty
In this episode of SecOps Confidential, host James Berthoty talks with Srijan Shetty, co-founder and CTO at Fuse, about building security into crypto and fintech infrastructure. Srijan explains why Zero Trust and least privilege access are easier to scale than bolting security onto legacy systems later. They dig into how AI tools speed up both development and security ops, why comprehensive test suites let teams ship fast while meeting regulatory requirements, and what it actually looks like to run 99% unit test coverage on a million-line codebase. Srijan shares what's working with AI SOC platforms, DAST scanning, and LLM-assisted development, and explains how security becomes an advantage when you tie it to developer experience and deployment speed.In this episodeThe shift from security as a blocker to security as a business enabler in CTO-CISO partnershipsWhy building on Zero Trust and least privilege from day one beats retrofitting security laterHow progressive regulators like the UAE's VARA can enable rather than block security innovationThe strategic use of AI across infrastructure, CI/CD pipeline, and developer experience layersWhy AI SOC platforms reduce alert fatigue and improve investigation speed for lean security teamsBalancing developer velocity with security through comprehensive testing infrastructureHow 99% unit test coverage and end-to-end regression suites enable confident, frequent deploymentsLinksFuzeExaforce
-
2
Building security operations from scratch and when MDR makes sense with Patrick McKinney
In the inaugural episode of SecOps Confidential, host James Berthoty sits down with Patrick McKinney (VP of Security, Invisible) to break down how to build and scale a security operations program. They cover when companies should move beyond “CTO-owned security,” how to approach tooling organically without overbuying, and how MDR and emerging AI SOC platforms can reduce operational burden while improving investigation speed and access to data. Patrick shares practical guidance on tying security spend to revenue retention, sales enablement, and risk, plus how to think about open-source vs. SaaS, vendor transparency, and the evolving SOC tool landscape as AI accelerates change.In this episode:The practical triggers for standing up a formal SecOps programHow to sequence tooling decisions without “$500K worth of tools” on day oneHow to justify security budget with revenue retention, sales cycle impact, and risk framingOpen-source vs. SaaS tradeoffs (including the often-ignored operational overhead)When (and whether) to off-board MDR as internal maturity growsWhy AI SOC value is often analysis quality and investigation speed, not just headcount reductionWhat vendors can do to earn trust: transparency, proof, realistic promises, and fast time-to-valueLearn moreInvisibleExaforce
-
1
Introducing SecOps Confidential
Welcome to SecOps Confidential - a cybersecurity podcast about the SOC programs that survived contact with reality. Hosted by James Berthoty, founder of Latio, each episode features security leaders, CTOs, and practitioners sharing what actually happened when they built their security operations centers.The 2 AM pages. The budget battles. The moments where perfect met reality. The automation wins. The complete rebuilds. Whether you're running a lean SOC, scaling to enterprise, or trying to figure out what actually works in modern security operations, this show is for you. You'll hear real stories from people who've been in the trenches. How SOCs are built, scaled, and automated. The people, processes, and technologies driving the next era of SecOps. New episodes drop monthly. Subscribe now on YouTube, Spotify, Apple Podcasts, or wherever you listen.
No matches for "" in this podcast's transcripts.
No topics indexed yet for this podcast.
Loading reviews...
ABOUT THIS SHOW
Behind every security program are the unseen stories of chaos, resilience, and reinvention. SecOps Confidential brings those stories to light through candid conversations with security leaders, CTOs, and practitioners who have built, scaled, and rebuilt their SOCs from the ground up.
HOSTED BY
Exaforce
CATEGORIES
Loading similar podcasts...