Episode 390 ·

Matt Spitz, Head of Engineering at Vanta - Continuous Security Monitoring

Today we’re talking to Matt Spitz, the Head of Engineering at Vanta. And we discuss the benefits of having continuous security monitoring. Why it’s important to think about security before you have to get compliance, and why trying to make a product perfect is often worse than releasing and iterating. 

All of this, right here, right now, on the Modern CTO Podcast!

To learn more about Vanta, check them out at https://www.vanta.com

About Matt Spitz:

Matt is an engineering leader with experience at small and large companies. Over the years, he has had the opportunity to manage diverse teams of engineers through times of significant growth, cultural shifts, and changing priorities. Prior to that, Matt has been a technical leader in both product and infrastructure engineering.

Matt is at his best when he's working on something high-impact with talented, direct, and kind people.

About Vanta:

Our mission at Vanta is to be a layer of trust on top of cloud services, to secure the internet, increase trust in software companies, and keep consumer data safe. Think of us as your automated security and compliance expert.

Transcript

(Joel Beasley at 00:00:03) Hello, my friends. Today we're talking to Matt, the Head of Engineering at Vanta, and we discuss the benefits of having continuous security monitoring, why it's important to think about security before you have to get compliance, and why trying to make a product perfect is often worse than releasing and iterating. All of this right here, right now on the Modern CTO Podcast.

(Joel Beasley at 00:00:31) Here we go. This is the Modern CTO Podcast.

(Matt at 00:00:43) Yeah, so I grew up in San Francisco, and in the late nineties was sort of surrounded by tech. I think I didn't really gravitate towards writing code until maybe late high school and college, but I was always a tinkerer. I was the one who had to fix the VCR for my parents. I still hold that responsibility. But yeah, I mean, the nice thing about software is that unlike many crafts, it is non-destructive and you can't really break it, which gives you a lot of opportunities to be creative and try new things and explore.

(Matt at 00:01:25) And I've just always liked that element of software and just generally optimizing for exploration and learning. And that's sort of what drew me to it in the first place. And, you know, I've been very fortunate that that's a booming industry and a going concern for our world. So it's been a lot of fun. I've learned a lot.

(Joel Beasley at 00:01:45) Yeah. So you were in San Francisco in the nineties. Were you still there early 2000s when the bubble popped?

(Matt at 00:01:53) I was in the early 2000s. And when I went to college and wanted to study computer science, my class at college was the lowest enrollment point at the end of the dot-com, but before the resurgence in the late early 2000s.

(Joel Beasley at 00:02:09) Yeah, that's pretty crazy, man. That's like—it just kind of reminds me of my personal college experience where I went through the first couple years and I went to—I was in school for marketing. And so I was in a lot of business classes, and all the professors kept saying, "You guys are so lucky. This is the best job market we've seen in years."

(Joel Beasley at 00:02:30) And my last semester of college was when the pandemic hit and everyone graduated into that, which is just really crazy how the floor can kind of drop out like that, whether it's the bubble burst or something insane like a worldwide pandemic. But so what was your first job going into that economy after school in tech?

(Matt at 00:02:53) Yeah. Well, the economy that I was going into was the 2008 recession, which was fun. But no, it's fine. And when you say the bottom fell out of the market, it was sort of a lot of job applications that I put in all of a sudden were—those jobs were no longer available.

(Joel Beasley at 00:03:12) Yeah.

(Matt at 00:03:12) Because companies were tightening their belts. But I was very fortunate. I ended up joining a company called Meebo. And because I grew up in San Francisco and because I went to college in the Bay Area, I sort of decided that if I wasn't going to leave then, I never would, and I spent the next ten years in New York. And Meebo was the first company that I worked at that was sort of opening a—being the first engineer in a distributed presence. So I was the first engineer in New York for Meebo and learned a lot with that experience, kind of took that to another couple startups from there.

(Joel Beasley at 00:03:49) That's cool. So I think we actually probably have a common connection because I saw your last job before your current company was like a—Dropbox. You were like an engineering leader there. We actually had a little while ago—I think his name is Bharat. He goes by Bart, the CTO.

(Joel Beasley at 00:04:06) Yeah. Yeah. He was a really cool guy on—

(Matt at 00:04:10) He was my last boss before I left Dropbox.

(Joel Beasley at 00:04:12) Oh, crazy. That's cool, man. So, well, speaking of leaving Dropbox, how did you come to start Vanta?

(Matt at 00:04:22) Yeah. So I didn't actually co-found Vanta. I joined, oh God, about a year and a half ago. When I was in New York, I overlapped with our CEO, Christina Cacioppo.

(Matt at 00:04:30) We did a startup together and worked on a bunch of different things. Nothing really worked out, obviously, but we learned a lot through the process and, importantly, learned that we liked working together. And when we split ways, I ended up going to Dropbox to found and eventually be the site lead for the New York City office for five years.

(Joel Beasley at 00:04:50) Oh, cool.

(Matt at 00:04:52) Which is an amazing experience. I think I kind of had two jobs there. One was engineering leader, and in a growing space, that kind of meant whatever needed happening or whatever needed doing. So I was like a technical lead. I was an engineering manager.

(Matt at 00:05:08) I worked on product engineering. I worked on infrastructure engineering. As that office grew, I just kind of filled whatever holes were needed on the engineering side. And as a site lead, that was very much a kind of zero-to-one startup experience for me. And so I had the opportunity to kind of lay the groundwork for what culture looked like and how the teams operated together.

(Matt at 00:05:30) And it wasn't just specifically engineering. We had sales in there too. We had some other functions represented. And that was my first opportunity really laying the groundwork for a culture and for a team in a way I'd participated in that before at fast-growing companies, but I'd never been responsible for it. And when I moved back to San Francisco in 2019, I didn't have that part of my job at Dropbox anymore.

(Matt at 00:05:55) I was just an engineering leader, which was an interesting job, to be clear. But I really missed that sort of zero-to-one component. And so I searched specifically for opportunities where I could be a major contributor in kind of laying the groundwork for a culture and for a team. And Christina, at the time, was looking for a Head of Engineering. And, you know, I think that Vanta's mission really spoke to me in terms of the good that we're doing for the world and the positive impact we're having on our customers and the value that we're providing for them.

(Matt at 00:06:32) And it sort of also matched what I was looking for at the time too, which was a chance to kind of take all the learnings that I had in building a culture and building a team and apply them to a smaller setting again.

(Joel Beasley at 00:06:45) That's really cool. I mean, Dropbox is such a huge company. I wouldn't have thought of that as a place to get startup experience. But—

(Matt at 00:06:55) Well, in the New York City office, we were zero when we started.

(Joel Beasley at 00:06:57) Yeah.

(Matt at 00:06:58) And I think I joined Dropbox at about 500 people, which, you know, in some ways it's a relatively large company. But given how quickly Dropbox was growing, especially at that time, there were a lot of things that the company needed to figure out. And I actually got an opportunity to experience a lot of the things—a lot of the sort of groundwork around compliance and security and things like that. I had the opportunity to observe some of that at Dropbox, which has been a really interesting experience for me as well.

(Joel Beasley at 00:07:25) That's really cool. So can you tell me what Vanta does?

(Matt at 00:07:30) Yeah. So Vanta's mission is to secure the Internet and to protect consumer data. And what that looks like in practice is that we empower companies to practice better security such that they do it and they keep their customers' data safe. The origin story for the company kind of came out of the 2016 election tampering and all the data breaches and the continued data breaches that we've seen since. The fundamental realization there is that the incentives are such that companies don't necessarily practice as good security as they could or they should. And as a result of that, they end up being irresponsible with customer data.

(Matt at 00:08:09) And you see misconfigured IT servers. You see PII in publicly accessible S3 buckets. You see people, ex-employees, still having access to company resources, all these different vectors of potential data breach. And a part of the root cause of that is that security is a scary thing. I'm the Head of Engineering at a small, very fast-growing company, and there are many, many, many different ways—and the surface area is very large for us—the risk surface area is very large.

(Matt at 00:08:42) And any one of those things could result in a security breach. And this is changing, but the culture of security previously has very much been: security is scary. I therefore can't know everything, and therefore I shouldn't even try. I should hire a consultant or I should hire a Head of Security to handle that for me so I don't have to worry about it. I think the reality is that security is much more accessible than it's made out to be.

(Matt at 00:09:10) And this is changing, right? I think there's better tooling. There's better dissemination of best practices such that people like me who are leading engineering, again, at small companies, can better engage with security and understand what my risk looks like and keep my—again, keep my customers' data secure and keep my company's data secure.

(Joel Beasley at 00:09:32) So what kind of products do you actually offer? Are you like the consultancy that someone might go to to be like, "Hey, can you handle this for me?" Or are you creating the tooling to make it a more frictionless experience for people to run their own? Are you doing both?

(Matt at 00:09:48) It's more the latter. I mean, I think there's kind of two—there's two value adds Vanta provides. So we offer a continuous security monitoring solution that plugs into our customers' tooling. So we plug into your identity provider. We plug into your code review tool.

(Matt at 00:10:05) We plug into your infrastructure provider. And we scan the configuration of those tools and notify you of potential threats in real time. And so many companies think that they're practicing good security, and, you know, everybody has two-factor authentication turned on. Everybody's laptop is encrypted. Servers are patched and up to date.

(Matt at 00:10:23) But until you have someone monitoring that continuously, you don't know for sure. And so many companies plug in Vanta, and they realize, "Oh my goodness, this person that left the company three years ago still has access to our GitHub repository." And so we offer a tool that helps our companies scan their surface area for potential threats and identify them in real time. And in addition to that, we sort of outlined this list of 150 to 200 best practices in security, things that maybe a company wouldn't think to do, but are generally good for security.

(Matt at 00:11:00) Like, make sure that your S3 buckets aren't public. Make sure that you have two-factor authentication turned on. These are sorts of things that, you know, I say that to you and you say, "Of course, that's better security." But for many companies, especially companies that are growing quickly and trying to find product-market fit, that's not necessarily top of mind for them. And so we help them understand what those best security practices are, and then we automate monitoring those in real time to detect potential threats.

(Joel Beasley at 00:11:27) Got it. So you just kind of connected for me the meaning behind continuous security monitoring because I had seen that phrase on your website, and I wasn't entirely sure what that meant in practice, but it makes a lot of sense that while you can initially take all the right steps of, like you said, two-factor, encrypting the laptops, doing that—if you're not checking up on that constantly and making sure it's staying that way, you can run into some issues.

(Matt at 00:12:01) Well, that's part of the problem with the industry today as well in that a lot of companies, their first experience with practicing security is in service of compliance. So the language approving security today largely is in this alphabet soup of compliance standards like SOC 2 or HIPAA or ISO 27001. And typically, the experience for someone like me who's leading engineering at a small company is that the CEO comes to them and says, "Hey, we really need to sell to this big company, but they're not even gonna look at us until we have a SOC 2. So get a SOC 2."

(Matt at 00:12:34) And the practice there, you know, these standards define some ways that are generally good practice, like hiring trustworthy people, making sure the data is safe in transit and at rest and things like that. And codifying them and actually practicing them is often a company's first experience with security. And, you know, that's better than nothing. However, these standards are inherently lossy in terms of how they're validated and how they're proven. They're validated by humans.

(Matt at 00:13:07) Humans can't look at everything all the time. Humans look at a sample of your population to understand whether you have two-factor authentication turned on or whether you've offboarded people appropriately. You have an audit period, typically, for SOC 2, and then you get a certificate, and that certificate is good for a year. And unfortunately, because of the way those incentives work, what a lot of companies do is that they will go do all the work that's necessary, send over all the screenshots, put them in the spreadsheet for the auditors. They'll get their certificate, and then they're gonna turn their attention to something else.

(Matt at 00:13:41) And the reality is that, you know, maybe I had everybody—everybody had two-factor authentication turned on at the time of the audit, but the next day, someone could have it turned off and they could get phished, and then someone could have access to my company's email. And so what Vanta offers is both help with that compliance journey. We kind of help our customers understand what the security best practices are. We hook them up with an auditor who knows how to use Vanta, which is inherently a better dataset than what they'd be using previously. It's a better way to gather evidence from the context of an audit.

(Matt at 00:14:16) But now we've also offered them continuous security monitoring to keep them secure even when there's not an auditor looking.

(Joel Beasley at 00:14:24) That's cool. So you're saying that a lot of companies' first kind of foray into taking security seriously is when they have to get compliance. Is that when you are having your first touch point with a lot of these companies?

(Matt at 00:14:37) That's true today just because of how, you know, the incentives in security work. However, what we're seeing is that companies are starting to invest in their security early because the reality is that a lot of these best practices, whether or not you want to get a compliance standard or not, a lot of these best practices enable you to better manage your company in the future. So things like centralizing your—using SSO to centralize access to different services—it makes it easier to onboard and offboard people. It makes it easier to understand who has access to what and why.

(Matt at 00:15:12) Having any kind of process around onboarding, offboarding, around reviewing access to different services, around vendor management, around asset management—these are all important things to practice. Even if you don't do them well, it's important to practice early. And Vanta is a tool that you can use to help you both understand what sorts of best practices you might think about practicing and then also enable you to do that at an early stage for a company.

(Joel Beasley at 00:15:43) So does Vanta use Vanta?

(Matt at 00:15:48) Of course. I cannot imagine managing our security program without Vanta. Again, there's just so many things. The analogy that I like to use is that securing a company is like securing a house, except instead of having one front door that you have to make sure is closed and locked and maybe a couple of windows on the ground floor, there's like 150 of those windows and doors. And any one of those, if left open, is a potential threat. And Vanta is a tool that kind of gives me the peace of mind that there aren't open doors and open windows in my house.

(Joel Beasley at 00:16:25) That makes sense. So what are some of the best first steps that a startup can take towards security?

(Matt at 00:16:34) Yeah. So there's a couple things. One thing I mentioned earlier is to just start practicing this even if you don't do it well. Right? So keep track of your vendors.

(Matt at 00:16:45) You don't need a fancy tool for that, and you may want to build some more process around it, but just dump them in a spreadsheet to start and look at that spreadsheet every now and again. You don't need to have fancy onboarding and offboarding tools, but you can start with a spreadsheet. As I mentioned earlier, investing in single sign-on, investing in mobile device management—these are sort of things that you won't do them well to start. But if you start doing it, you'll get better at it over time. And as your company grows and as the complexity grows, you'll always have something to start with.

(Matt at 00:17:16) There's a lot of companies that don't think about this at all and then all of a sudden need to think about it, and they start being bad at it sort of late, if that makes sense. Another thing I would say is that codifying as much as you can, literally in code, enables you to have a better understanding of the potential threat surface area of your company. So there's a lot of tools for this these days for infrastructure as code. But something like Terraform allows you to encode your Amazon configuration, and so you don't have to go to the portal and click around to see what's happening. You can look in code and see exactly what the status is.

(Matt at 00:17:52) Investing in things like centralized logging and centralizing monitoring early enables you to understand what is happening in your system. And then there's eventual—there's development best practices too that not only accelerate your team's development but also are more secure. Things like investing in continuous integration, continuous deployment, investing in things like enforcing code review, locking your deployment branch. These are generally good practices. They also happen to be best practices for security as well.

(Joel Beasley at 00:18:24) That makes sense. Yeah. I hadn't necessarily thought of continuous deployment as a security best practice, but it totally makes sense to constantly be pushing out security patches when you can.

(Matt at 00:18:36) It also makes it clear who's pushing the button to release code. And if you have everybody on their laptop who could run the "push this to production" script, you don't necessarily know what's out there. You don't necessarily know who's been pushing it. But if it's all coming through one pipeline in one place, you can be more confident that you have—you can be more confident about what's actually running in production and you can have more of a paper trail as to how it got to be that way, such that if there are issues or if there are incidents, you can have a better way to diagnose that. And you can restrict who actually has the right to push things to production.

(Joel Beasley at 00:19:12) That makes sense. So have you heard of a company called Axio?

(Matt at 00:19:16) I have, but I'm not super familiar with it.

(Joel Beasley at 00:19:19) Okay. So I'm just asking because I actually recently interviewed their founder, and he was a really cool guy. He didn't really start his career in security, but just out of interest, he ended up falling into writing a lot of our modern best practices. He spent some time at MITRE and stuff.

(Matt at 00:19:41) What—

(Joel Beasley at 00:19:41) What his company does is they analyze a company and help you make decisions on where to allocate investments to hedge your cyber risk, whether that's beefing up security in a specific area or getting cyber insurance. And so it's a little bit more on the financial side of it. And I'm curious as a provider of continuous security monitoring, how do you talk about the financial side of cyber risk management with your customers and talk ROI with them and whatnot.

(Matt at 00:20:20) Yeah. So, fundamentally, security is risk management. And if you really want to be secure, you shouldn't run any code in production. You should never hire anybody. You should never do anything as a business that might expose you to any sort of risk.

(Matt at 00:20:33) Right? That's the only way to be 100% secure. That's not realistic. Right? Similarly, you should never leave your house. You should never cross the street. You should never get into a car if you really want to be 100% safe. And so, fundamentally, security is about assessing your risk and understanding what risk there is to what your employees are doing, what risk there is to the code you're running in production, what risk there is to other forms of data breach or whatever, and then mitigating that risk enough to be comfortable with whatever risk is left. Right? And I think Vanta is sort of a guide in many ways. We offer opportunities to guide people through a risk assessment. We outline some of these best practices that can mitigate risk. We are a tool that helps companies mitigate that risk. There are other forms, as you mentioned, of risk that maybe we're not focused on as much today in terms of financial risk, but it's all kind of covered in the same thing.

(Joel Beasley at 00:21:30) Right. You mentioned financial risk is maybe a separate thing, but I think it's all a part of your cyber risk management. Because you can always calculate the dollar cost of any given breach if you have the right person to do that and the right data in front of you. You know?

(Matt at 00:21:50) Right. I mean, I think that's a better way to put it. I think when we talk about financial risk, that's really the outcome of what might happen with these different data breaches. And maybe that's ransomware. Maybe that is someone steals my company data and asks me to pay millions of dollars to get it back. Some of it is reputation risk. If my company gets breached, that damages customer trust, and that may make it more difficult to close deals in the future, et cetera.

(Joel Beasley at 00:22:14) That makes sense. So what is it about Vanta that makes it unique from other security companies that are doing something similar?

(Matt at 00:22:26) There are a bunch of different tools and companies out there that are helping companies practice better security. So one is on the sort of more niche elements of helping companies with security. There are whole companies that are based on helping companies detect vulnerabilities in their software and code that they're running in production. There are whole companies that are based on helping companies identify when there are potential intrusions in their infrastructure. In terms of helping companies manage their security program, there's kind of two flavors of that.

(Matt at 00:22:57) One is sort of a project management approach. And this is what consultants would do when they come in and help you with your security program or your compliance program. They do a risk assessment, they kind of map out all the potential sources of risk, and then they help project manage your resolving that risk. You have to do all the work, but they kind of help guide you through that process of doing it.

(Joel Beasley at 00:23:21) Interesting. Absolutely. And then—

(Matt at 00:23:23) There are tools like Vanta, which do that part of it but are more focused on actually helping you mitigate the risk rather than just identifying and telling you what to do. So Vanta not only outlines a set of best practices and helps you do a risk assessment, we also provide the tools and the tests to help you understand in real time whether you're actually meeting the goals of your security program. And, fundamentally, we believe that this automation and continuous security monitoring is so much stronger and so much more powerful than better project management and the point-in-time verification that we see with compliance today.

(Joel Beasley at 00:23:59) That's really interesting. It sounds like you're definitely taking the more proactive approach of avoiding a breach rather than, hey, we have a problem, we have to take these steps to solve the problem. It's better to just not have a problem.

(Matt at 00:24:13) That's always true. I mean, I think, you know, security is all about risk management, and it's impossible to eliminate all sources of risk. But you can take preventative measures and be proactive to mitigate that risk as best as you can or mitigate it to what is an acceptable risk for you and your company. And that's sort of a choice that every company has to make. Right? Again, you can be 100% secure by not running any software and not hiring anybody. But the people that you hire and how you manage that, how you manage the software that you are running in production, that all presents a certain level of risk. And if you're comfortable with that risk, then there you go.

(Joel Beasley at 00:24:55) So what are some big trends you're seeing in the security space today?

(Matt at 00:25:00) I think the big thing, and I'm really happy to see this, is that more and more teams and companies are relying on automation. And we're seeing this high-level trend in the security industry from what is previously a consulting model. So whether that's internally within a company or having a consultant come in and tell you, "Okay, this is what you should be doing. Here's your list of things you should do. Go off and do them, and you will be more secure than you were when you before you paid me hundreds of dollars an hour." And what that's moving to is more of using tools to actually validate these things and be proactive about it. And a lot of bigger companies are using—have full teams that are deployed against building tools for things like access management or things like vulnerability detection and stuff like that, or using third-party services and software. Fundamentally, security by automation is so much stronger than security by consulting. And sort of as a consequence of that, security becomes much more accessible too.

(Matt at 00:26:03) And the tools that you write, that's just code. Right? And engineers can read code, and we can understand what we're monitoring, what we're not monitoring. And it just becomes so much more tangible and easier to understand.

(Joel Beasley at 00:26:13) Yeah. Absolutely, man. And I love that you mentioned security by automation going forward because that just allows for such larger scale of scaling up your security systems. We actually just recently had on the CTO of Avast Antivirus. And so, obviously, this guy is deep in the security space, but he in addition to that role, he's a professor of AI, and he does a lot of AI research. I believe when he introduced himself, he said, "I am a big AI scientist guy." I think that was his phrasing. But, anyway, one thing that he was talking about that I thought was really interesting is how he's been studying bad actors' use of what he calls adversarial AI—and how they're able to scale up their attacks with the help of automation on that side too. And the only way to scale up your security to be able to fight that is by also embracing automation on the security side.

(Joel Beasley at 00:27:23) So I think I just thought it was really cool hearing you just bring that up as the answer to such a broad question as what trends you're seeing because that just sounds really promising and makes me feel personally safer that that's something that a lot of people are thinking about.

(Matt at 00:27:44) There's another thing here too, which your comment about scaling up made me think about. Another big trend that we're seeing is that smaller companies are able to do so much more. So smaller companies that are starting today don't need to hire a data center team. They can use AWS. Smaller companies today can delay hiring an HR team to analyze benefits, et cetera, et cetera, because they can use a company, a tool like Gusto, that incorporates it all in one.

(Matt at 00:28:15) More and more companies are using SaaS instead of headcount to get things done and move faster. And throughout this, security doesn't scale down. So the sorts of things that you would do to secure a 2,000-person company actually aren't that different from the things that you would do to secure a 200-person company or a 20-person company. And as a result of that, smaller and smaller companies are doing more and more, but maybe aren't at the point where they would hire a big security team. If you look at a 2,000-person company, maybe they have a 50-person security team. A 20-person company likely doesn't have a security team. A 200-person company, maybe a couple people. And so there's this gap in that there are smaller and smaller companies doing more and more valuable things, but don't necessarily have the security posture that they would need because security doesn't scale down.

(Joel Beasley at 00:29:08) You can complain about it from a consumer perspective that everything's a subscription now, but I think it is a really cool trend in the startup space because it makes it so much easier for anyone to just spin up a business. And lots more ideas can become businesses. And I think you take that one step further, now the level of creativity and competition for making cool stuff just has to rise to compete with each other since there's so much more accessibility to—you don't have to have a huge budget for an HR department when you can just use Gusto. You don't have to have a huge budget for security when you got cool tools like Vanta that can help you early on and various other SaaS tools that can just help you run all those non-core parts of your business. And, yeah, I mean, it seems like what you're doing at Vanta is just further enabling that to make these security practices available where they previously weren't because of budgetary constraints, and that they couldn't hire that person or that team to take care of it.

(Matt at 00:30:26) I think it's also just, you know, again, speaking as a head of engineering for a small company, there's a lot of things that these people have to worry about. And security—no one's going to say security is not important. Right? But on the priority list, security often—because it's not urgent, and if it's urgent, it's too late—security often doesn't end up at the top of the priority list.

(Matt at 00:30:51) And what a tool like Vanta does is empowers people to engage with security and gives them the tools to make it easier to reduce the cost of actually thinking about it and investing it. And for many companies, that's the difference between thinking about security at all and not. And I think at the end of the day, Vanta's mission is to secure the internet and to protect consumer data. And the more companies that are investing in their security, the more companies that are feeling empowered to practice better security, and the more companies that have the tools to enable them to do that and be confident in their posture because a tool like Vanta is monitoring it hourly instead of annually, the more companies actually practice security and the more that consumer data is kept safe and the fewer data breaches that we have in the world.

(Joel Beasley at 00:31:39) Yeah, dude. I remember you said your mission statement early on in the interview. I didn't get to comment on it, but that just sounds cool. So before we wrap up here, I actually want to talk a little bit about your leadership approach and just leadership in general at your company. Is that cool?

(Matt at 00:32:00) Yeah. Absolutely.

(Joel Beasley at 00:32:01) Cool. So I saw that you have a lot of really large companies in your work history. And today you're head of engineering at a smaller, very fast-growing company. What's a lesson that you learned working at those larger companies that has served you really well in your role today?

(Matt at 00:32:22) I think that one common thread throughout the companies that I've worked at, and this is true for smaller companies and larger companies, a common thread is how quickly everything changes. And whether that is company priority shifting, whether that is your team grew by 50 in the last three months, whether that is you end up working with new people or focusing on new things, everything is constantly in flux. And I think that in those, especially in those environments, but just generally, perfection is the enemy of the good. And when it comes to, hey—

(Matt at 00:33:05) Let's figure out the right way to do this new process or the right way to work together or the right way to approach this product or exactly the perfect thing to ship to our customers. There's risk of writing a PhD thesis and doing a bunch of research about what the best approach is and trying to tackle that best approach. And in my experience, there are certainly things for which the investment and upfront research is worth it. But for many, many, many things and many, many decisions, it's better to try something and iterate. Because whether that is shipping a product and then putting it in front of customers and understanding how they're using it and using that to inform future product decisions, whether that is rolling out a new process on a team or whether that is an approach to a product roadmap or goal planning, it's often better to put something out there and iterate on it than it is to come up with the perfect thing before you ship anything at all.

(Joel Beasley at 00:34:05) Yeah. I think that you kind of said that earlier when you were talking about how a lot of the times it's really good to try to start your security approach very early, because you're going to be bad at it at first. And you'd rather be bad at it early and get good fast, rather than start late and be bad late when it's critical. And so I just had to bring that up because I really like that phrasing. I think it's very, very pointed.

(Joel Beasley at 00:34:34) But—

(Matt at 00:34:34) Yeah. Exactly.

(Joel Beasley at 00:34:35) So how would you describe the culture at Vanta?

(Matt at 00:34:39) I think there's a couple ways to think about culture. One is the sort of how people treat one another, and another is how people work. And often, we talk about the former. And Vanta has a lot of the good things that I've experienced at other tech companies, things like over-communication, an emphasis on collaboration, an assumption of good intent. These are the sorts of things that enable a company that's growing as quickly as it can to have somewhat of a safety net.

(Matt at 00:35:09) Culture is a safety net against high growth. When things break all the time because you've doubled the team every six months, the fundamental trust within a company is an effective counterweight against fast growth in which many things are breaking all the time just due to how quickly the company is changing. The other element of culture is sort of how people work, and I believe strongly in hiring absolutely best people and empowering them to do their jobs. And what that looks like is identifying clear owners for things and identifying people who are responsible and accountable for getting things done and then giving them the resources to do it and getting out of the way. What I found is that people will always impress you.

(Matt at 00:35:56) They'll always do more. They'll ramp up faster than you would expect. They'll come up with ideas that are much greater and better than anything you would have come up with yourselves. And the more that you can create an environment and a culture in which people are empowered and have the ownership and opportunity to go and deliver great things, the more you'll be impressed and the more good will come from that.

(Joel Beasley at 00:36:21) So how do you foster those cultural tenets, like assuming positive intent and that level of trust between coworkers? How do you do that in practice? Do you hold, like, off-site events that people can participate in and get to know each other as people? Or I don't know. Just because I feel like a lot of that is about building the relationships between coworkers. Right?

(Matt at 00:36:48) So I don't think that culture is set top down. There's certainly an element of demonstrating the behaviors that I would like my coworkers to practice as well. I think, ultimately, as a leader, my role in culture is in curation rather than dictating it. And what that means is, when I see things that are good, I reward them and I celebrate them. When I see things that I don't like, I tamp it down or stop it.

(Matt at 00:37:16) And things like, from an engineering perspective, one thing that's really important to me is this notion of blameless postmortems. Bad things are going to happen, and most of the time, that's due to the processes and tools that we were using rather than individual bad actors. And the more that we talk about the processes and tools that are broken rather than disciplining someone for accidentally taking down a part of our infrastructure or something like that, the more you sort of create the culture that we're all trying to make Vanta better rather than disciplining individuals for doing bad things.

(Joel Beasley at 00:37:55) That's huge of having the blameless postmortems because if a postmortem is a really bad experience for the engineer that made a mistake, they're not likely to bring up either a mistake or something they're not confident in and ask for help. And that kind of thinking just drags a company down. So mentioning blameless postmortems, absolutely. That's a really cool thing that you do, and everyone should.

(Matt at 00:38:30) I think it's another really important part of creating an engineering culture and company culture, which is creating an inclusive environment where anyone feels empowered to express their ideas. And that's absolutely something that a leader can help curate at the company. And this can look as small as in a meeting where someone looks like they want to say something, but they haven't yet, explicitly calling that person out and saying like, hey, would you like to add something to this conversation?

(Matt at 00:39:02) This looks like ensuring that everybody has the right venues to speak and feel empowered and comfortable to do that. And especially if someone in a leadership position where you're often the person running these meetings or in a position that people look to to demonstrate the behavior and how to operate, leaders have a disproportionate opportunity to create that inclusive environment and enable those best ideas to surface.

(Joel Beasley at 00:39:26) At the end of the day, people just think differently and come up and express their ideas differently. And maybe it's not such a great idea to say, hey, we're having this meeting to come up with an idea to solve this problem. And we have to decide on what we're going to do by the end of the meeting because maybe there's people in the room that do a really good job of just kind of brainstorming and saying things on the spot, and there's also people in the room that will do a really great job when they go home and keep thinking about it all day. And then something comes to them, and they can come in the next day and say, hey, I thought of this really great idea. It's better than what we said in the meeting. Let's do this. And I guess where I'm going because I just talked to someone about this yesterday. And, yeah, I just think you're totally right. Making room for all those different types of cognition to be able to bring their ideas forward is so important when you're in a highly competitive landscape and you have to be going with the best ideas that you can and getting the most out of your team.

(Matt at 00:40:34) Absolutely. That's absolutely right. I would also say that good management enables good culture.

(Joel Beasley at 00:40:39) Mhmm.

(Matt at 00:40:40) If you can structure your meetings in a way that you have clear agendas and a clear understanding of what you want to get out of them, if you can structure your projects such that you don't have to make urgent decisions in the moment, you can create opportunities to bring more ideas forward, and you can create lower stress opportunities to share and collaborate.

(Joel Beasley at 00:41:01) Yes. Yes. Absolutely, man. Alright. So we are coming up on time. Before we wrap up, is there anything that we didn't get to touch on today that you want to make sure we get out to the world? You mentioned it a couple times. You're fast growing. You're hiring. Any plugs you want to make?

(Matt at 00:41:20) Yeah. Absolutely. We are growing our team very quickly. We have a lot of job openings at vanta.com/jobs. In particular, I'm hiring engineers quickly. And if Vanta's mission to secure the Internet and protect consumer data is exciting to you, please reach out. We'd love to have you join us.

(Joel Beasley at 00:41:45) Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you'd like to hear discussed on the podcast, either add me on LinkedIn or send me an email [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.