Detection at Scale

1Password's Jacob DePriest on Balancing Human Intuition and AI in Cybersecurity


Listen Later

In this episode of Detection at Scale, Jack speaks with Jacob DePriest, VP of Security/CISO at 1Password, who shares insights from his 15-year journey from the NSA to leading security at GitHub through his current role. Jacob discusses his framework for assessing security programs with fresh eyes, emphasizing business objectives first, then addressing risks, and finally implementing the right security measures. 

He also explores how generative AI can enhance security operations while maintaining that human expertise remains essential for understanding threat intent. As 1Password transforms from a password manager to a multi-product security platform, Jacob outlines his approach to scaling security through engineering partnerships and automation, while offering practical leadership advice on building relationships, maintaining work-life balance, and aligning security initiatives with business goals.

Topics discussed:

  • Transitioning from engineering to security leadership and how that technical background provides empathy when implementing security controls.
  • Approaching security program assessment by first understanding business objectives, then identifying risks, and finally implementing appropriate measures.
  • Exploring 1Password's evolution from a password management product to a multi-product security company with extended access management.
  • Balancing generative AI's capabilities with human expertise in security operations, recognizing AI's limitations in understanding intent.
  • Leveraging AI to enhance incident response through automated summaries and context gathering to speed up triage processes.
  • Implementing AI applications in GRC functions like vendor reviews and third-party questionnaires to increase efficiency and reduce tedium.
  • Building sustainable security operations by ensuring security tools have proper access to data through education and partnership.
  • Addressing the varying security postures across the vendor landscape through a risk-based approach focusing on access and visibility.
  • Scaling security teams by clearly connecting their work to business objectives and ensuring team members understand why their tasks matter.
  • Three pillars of security leadership: building a trusted network, establishing sustainable work-life balance, and connecting security to business goals.
  • Listen to more episodes: 

    Apple 

    Spotify 

    YouTube

    Website

    ...more
    View all episodesView all episodes
    Download on the App Store

    Detection at ScaleBy Panther Labs

    • 5
    • 5
    • 5
    • 5
    • 5

    5

    11 ratings


    More shows like Detection at Scale

    View all
    Security Now (Audio) by TWiT

    Security Now (Audio)

    1,966 Listeners

    Risky Business by Patrick Gray

    Risky Business

    360 Listeners

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

    628 Listeners

    Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

    Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

    367 Listeners

    CyberWire Daily by N2K Networks

    CyberWire Daily

    1,014 Listeners

    Smashing Security by Graham Cluley & Carole Theriault

    Smashing Security

    314 Listeners

    Click Here by Recorded Future News

    Click Here

    392 Listeners

    Hacking Humans by N2K Networks

    Hacking Humans

    313 Listeners

    Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

    Defense in Depth

    78 Listeners

    Dwarkesh Podcast by Dwarkesh Patel

    Dwarkesh Podcast

    352 Listeners

    Cyber Security Headlines by CISO Series

    Cyber Security Headlines

    118 Listeners

    The Ezra Klein Show by New York Times Opinion

    The Ezra Klein Show

    15,037 Listeners

    Cloud Security Podcast by Google by Anton Chuvakin

    Cloud Security Podcast by Google

    40 Listeners

    Risky Bulletin by risky.biz

    Risky Bulletin

    33 Listeners

    No Priors: Artificial Intelligence | Technology | Startups by Conviction

    No Priors: Artificial Intelligence | Technology | Startups

    129 Listeners