$ whoami
matthew marji // "marji" — toronto, canada
$ ./init --role security --mode collaborative
[ok] secure-by-default ...... enabled
[ok] blocking-gate .......... disabled
Principal · Modulo Security · Toronto

Founding Leader in
Security, Compliance
& AI.

I build security that's collaborative, AI-native and secure by default — an enabler for engineering teams, never a gate.

Matthew Marji
// subject: marji
[01]

about

Human or agent — thanks for stopping by. You can call me Marji.

I build and lead security and compliance programs — usually as the first security hire, then growing them into teams and owning the strategy as the company scales. Most recently I led Security & Compliance at WorkOS, taking the function from just me to a team of 8. Before that, security engineering at Narvar and three years on product security at Auth0.

I studied as a software engineer, and I run security teams as collaborative — a natural, non-blocking part of how software gets built, never a checkpoint. I'm also AI-pilled: I automate the tedious parts so the secure path stays the fast path. On the side I run Modulo Security and advise a handful of companies.

[02]

how i think about security

// 01

Security Is Collaborative

Built with engineering, not imposed on it. The strongest controls come from the teams shipping the code — deeply integrated, not bolted on.

// 02

An Enabler, Not a Gate

Make the secure path the default path — powering secure-by-default features. Never a checkpoint, never a police officer between teams and shipping.

// 03

AI-Native by Default

Automation and AI so security scales with the organization — catching real risk early instead of becoming a bottleneck.

[03]

security, automated

 marji@sec — ~/automations

A secure SDLC works when the tedious parts are automated. I've built a growing set of AI-driven automations that do real security work end to end — reviewing, validating, and fixing — so the secure path stays the fast path.

ProdSec AI

An autonomous white-box pentester. It reads the code, reasons about attack paths, and runs live testing against the running application.

Vuln Triage

Reviews and validates incoming findings, determines true severity, and rewrites the report into clear guidance. Then it opens a PR with the fix and tests.

Bug Bounty Triage

Handles ingestion of every responsible-disclosure report and runs tier-1 triage. Only real vulnerabilities reach a security engineer.

Dependency Upgrades

Autonomously ships patch and minor version upgrades, checking for breaking changes and verifying each one with Playwright tests. A human only steps in for majors and breaking changes.

Cloud Security Triage

When Wiz or other cloud tools surface a possible threat, a tier-1 agent validates it live against the environment. Security engineers only see what survives that check.

Compliance Bot

Keeps a continuously updated answer base and handles 80%+ of inbound customer security questions. Sales and support engineers get answers without waiting on security or compliance.

[04]

the path

first security hire → built the function → grew the team → owned the strategy. hands on the whole way through.

Most Recently
Engineering Manager, Security & Compliance · WorkOS first hire → team of 8

Joined as the first security hire at the identity platform behind OpenAI and Plaid, and grew the function to a team of 8. Built a paved-roads program with enforced patterns and automated lint checks, plus autonomous vulnerability triage handling 50+ findings a week. Owned exception-free SOC 2 Type 2, PCI SAQ-D, HIPAA and GDPR — and built the customer trust portal from scratch.

Jan 2019 – Present
Principal · Modulo Security independent

My independent security consulting practice. I help companies build and mature security programs, run penetration tests, and get through compliance.

High-Growth
Security Engineering Lead · Narvar

Led security engineering at a fast-scaling post-purchase platform. Built and matured the security development lifecycle across engineering.

Three years
Product Security · Auth0 (acquired by Okta)

Spent three years building the fundamentals of product security at Auth0. Integrated SDLC practices across engineering teams working on identity at massive scale. Okta acquired the company during my tenure.

[05]

what i focus on

the practices that make security a strength, not a speed bump.

Secure SDLC

Embedding security into how teams design, build and ship — without slowing them down.

IAM & Identity

Identity and access systems that scale with the business and hold up under real attack.

SOC 2 & Compliance

Audits and frameworks turned into real, durable security — not a checkbox exercise.

AI-Augmented SecOps

AI that makes security operations faster and sharper as systems become autonomous.

Fractional CISO

Senior security leadership for teams that need the strategy without a full-time hire.

Pen Testing & Tooling

Finding what's actually exploitable and guiding pragmatic remediation decisions.

[06]

blog

distilled thoughts, talks and podcasts — short nuggets from practice on secure development, identity, and building security programs that hold up.

let's chat

Building something and want security to be a strength, not a scramble later? I'd love to hear what you're working on.