I build security that's collaborative, AI-native and secure by default — an enabler for engineering teams, never a gate.
Human or agent — thanks for stopping by. You can call me Marji.
I build and lead security and compliance programs — usually as the first security hire, then growing them into teams and owning the strategy as the company scales. Most recently I led Security & Compliance at WorkOS, taking the function from just me to a team of 8. Before that, security engineering at Narvar and three years on product security at Auth0.
I studied as a software engineer, and I run security teams as collaborative — a natural, non-blocking part of how software gets built, never a checkpoint. I'm also AI-pilled: I automate the tedious parts so the secure path stays the fast path. On the side I run Modulo Security and advise a handful of companies.
Built with engineering, not imposed on it. The strongest controls come from the teams shipping the code — deeply integrated, not bolted on.
Make the secure path the default path — powering secure-by-default features. Never a checkpoint, never a police officer between teams and shipping.
Automation and AI so security scales with the organization — catching real risk early instead of becoming a bottleneck.
A secure SDLC works when the tedious parts are automated. I've built a growing set of AI-driven automations that do real security work end to end — reviewing, validating, and fixing — so the secure path stays the fast path.
An autonomous white-box pentester. It reads the code, reasons about attack paths, and runs live testing against the running application.
Reviews and validates incoming findings, determines true severity, and rewrites the report into clear guidance. Then it opens a PR with the fix and tests.
Handles ingestion of every responsible-disclosure report and runs tier-1 triage. Only real vulnerabilities reach a security engineer.
Autonomously ships patch and minor version upgrades, checking for breaking changes and verifying each one with Playwright tests. A human only steps in for majors and breaking changes.
When Wiz or other cloud tools surface a possible threat, a tier-1 agent validates it live against the environment. Security engineers only see what survives that check.
Keeps a continuously updated answer base and handles 80%+ of inbound customer security questions. Sales and support engineers get answers without waiting on security or compliance.
first security hire → built the function → grew the team → owned the strategy. hands on the whole way through.
Joined as the first security hire at the identity platform behind OpenAI and Plaid, and grew the function to a team of 8. Built a paved-roads program with enforced patterns and automated lint checks, plus autonomous vulnerability triage handling 50+ findings a week. Owned exception-free SOC 2 Type 2, PCI SAQ-D, HIPAA and GDPR — and built the customer trust portal from scratch.
My independent security consulting practice. I help companies build and mature security programs, run penetration tests, and get through compliance.

Led security engineering at a fast-scaling post-purchase platform. Built and matured the security development lifecycle across engineering.

Spent three years building the fundamentals of product security at Auth0. Integrated SDLC practices across engineering teams working on identity at massive scale. Okta acquired the company during my tenure.
the practices that make security a strength, not a speed bump.
Embedding security into how teams design, build and ship — without slowing them down.
Identity and access systems that scale with the business and hold up under real attack.
Audits and frameworks turned into real, durable security — not a checkbox exercise.
AI that makes security operations faster and sharper as systems become autonomous.
Senior security leadership for teams that need the strategy without a full-time hire.
Finding what's actually exploitable and guiding pragmatic remediation decisions.
distilled thoughts, talks and podcasts — short nuggets from practice on secure development, identity, and building security programs that hold up.
How to embed security into engineering without becoming the team that says no.
read Sep 10, 2026 · distilled thoughtTurning a compliance deadline into security you'd actually keep after the audit.
read Jun 26, 2024 · podcast · scale to zeroHiring security engineers, assessing business risk, and why alignment decides whether a program succeeds.
read Jan 2026 · perspective · sagetapAI and automation run on non-human identities; weak IAM fundamentals widen the gaps.
read Mar 2025 · video · sage spotlightBuilding security and compliance at WorkOS, and where AI fits in a modern program.
read Oct 2019 · talk · bsides torontoA year researching subdomain takeovers — and automating both the attacks and the defences.
read Jan 2023 · talk · fuckup nightsBadly fumbling a talk at a large security conference, and what it taught me.
read Feb 2022 · talk · itwc maplesecWhy customer identity is consistently harder than teams expect.
read