Today's episode is with Shrivu Shankar, VP of AI Strategy at Abnormal AI - a $5B cybersecurity company. What makes this one unique is that Shrivu joined as an intern in 2021 and got promoted every single year until he reached VP, so he's basically watched AI go from a niche engineering tool to something that's reshaping entire companies from the inside.
We get into how AI is catching cyberattacks so sophisticated that even humans can't tell they're fake, how engineers at a $5B company have basically stopped writing code themselves, and what that means for everyone else on the team.
We also go deep on why context engineering is replacing prompt engineering as the real moat, how they used GPT-3 with zero safety guardrails to generate fake phishing attacks as training data, and what it actually takes to become an AI native company at 1,500 people.
One of the most technical and eye-opening conversations I've had. You don't wanna miss this one.
Chapters:
00:00 Intro
00:58 Who is Shrivu and what is Abnormal AI
01:39 Why cybersecurity and machine learning
03:13 Intern to VP in 4 years — how it actually happened
05:44 What Abnormal AI does and how it started
09:10 The vendor fraud attack so convincing the victim didn't believe it was real
10:45 What GPT-3 changed for cybersecurity
13:01 Using synthetic data to train models — and how they measured it
16:49 How a 1,500 person company actually adopts AI internally
19:50 How engineering, PM, and platform roles are changing right now
23:17 The biggest AI misconception Shrivu keeps hearing
27:35 What Shrivu's day actually looks like as VP of AI Strategy
28:53 Engineers stopped writing code. Here's what they do instead.
32:28 Why product teams are getting much smaller
34:31 Why context engineering beats prompt engineering
36:31 Spec-driven development and how Nora Tech Plan works
39:14 How to scale context engineering across an entire eng org
40:30 What the manager role looks like in the agent era
42:17 What skills actually matter for managers now
43:29 AI is making orgs flatter. Is that a good thing?
45:08 How the C-suite is getting closer to the work
46:41 What agents actually are and how tool calling works
48:05 How agents improved Abnormal's detection pipeline
50:56 The AI phishing coach — how it works and why it matters
53:30 The internal AI data analyst agent
56:13 Dozens of internal agents — the ones Shrivu is most proud of
57:15 Where agents fail (it's usually not the model)
58:52 What Shrivu would tell a CEO just starting with agents
01:00:19 Sending sensitive security data to LLMs — how they handle it
01:01:47 What becoming AI native actually means in practice
01:03:37 What most people still get wrong about AI in the enterprise
01:04:31 How to write documents with AI without it sounding like AI
01:06:40 Claude Code vs Codex — which one and why
01:09:27 How Shrivu stays ahead and his take on MCPs
01:11:33 How the team uses Claude Code skills
01:12:47 Using hooks for shift-left validation in large codebases
01:13:42 How to manage context in a massive monorepo
01:14:56 Building tool-agnostic rules across Claude, Cursor, and Code Rabbit
01:16:55 Why infra teams are becoming agent harness teams
01:17:57 Wrap up