He's an L8 Principal Engineer at Netflix — the kind of technical leader the company puts on the problems that decide whether it wins or loses. And he just watched AI out-hack him.
Scott Behrens is an L8 Principal Security Engineer at Netflix, where over 11 years he's watched the security team grow from a handful of people to over a hundred. Today he's the technical lead for Netflix's Live product security, its Attack Emulation Red Team, and its DDoS research. He joins Aaron for one of the most honest, forward-looking conversations we've had about what AI actually does to security work, and to the people who do it.
Scott doesn't sugarcoat it: he sat down with the latest models and quickly concluded they're better at finding and exploiting vulnerabilities than he is. But instead of doom, he lays out why that's an opportunity and where humans still hold the irreplaceable edge.
We get into why the model matters less than the "harness" you build around it, the idea that human intention and hard-won wisdom are the most valuable resources in the AI race, and what actually happens when your discovery tools start surfacing thousands of real vulnerabilities you now have to fix. Plus: how AI is quietly making security the easiest story he's ever had to tell, the one-line trick that cuts vulnerabilities in AI-written code, and why the best security engineers are becoming systems thinkers, not bug-finders.
Guest: Scott Behrens, L8 Principal Security Engineer at Netflix.
Find him on LinkedIn and read his newsletter, The Engineer Setlist, on Substack.
⏱️ CHAPTERS
00:00 Intro
01:57 Excited, worried, and humbled all at once
04:16 Don't just do the old things faster
07:30 Should security teams fix the bugs, not just find them?
09:30 Human intention is the most valuable resource in the AI race
10:16 The "wisdom" AI doesn't have
12:22 Systems thinking as the human edge
18:14 Why the harness matters more than the model
20:25 Codifying 20 years of expertise into a harness
23:41 You built the harness — now what do you do with the findings?
25:32 What small and mid-size businesses should actually do
27:35 The one-line trick that cuts vulnerabilities in AI code
30:41 Rethinking the front end, WAFs, and detection
32:45 The "isadmin=false" honeypot trick
51:50 The era of YOLO security
53:09 Security as an enablement function
55:04 "The easiest story I've ever had to tell"
56:34 Where to find Scott
#cybersecurity #infosec #AI #Netflix #appsec