Scale to Zero - No Security Questions Left Unanswered

Scale To Zero
undefined
Apr 8, 2026 • 49min

IAM in 2026: From Anti-Patterns to Autonomous AI Agents | ft. Advait Patel | ScaleToZero Podcast | Ep. 108 | Cloudanix

Cloud infrastructure is moving faster than ever, but is your security keeping up? We sit down with a Senior Site Reliability Engineer to discuss the evolution of Infrastructure Security and Compliance in 2026. Whether you're an SRE, Security Engineer, or DevOps Lead, this episode will challenge how you think about "secure" infrastructure.Transcript: https://www.scaletozero.com/episodes/iam-in-2026-from-anti-patterns-to-autonomous-ai-agents-with-advait-patel/Advait Patel: https://www.linkedin.com/in/advaitpatel93/Powered by: https://cloudanix.comAlso Available on our YouTube Channel: https://youtu.be/1dchqWnt1hAKey Discussion Points are as Follows:00:00 Introduction07:40 Real-world Challenges of Infrastructure Security and Compliance11:20 Automating Security Checks and Avoiding Bottlenecks13:25 Security Impact of IAM Implementation17:28 Architecting an IAM Program in 202619:38 KPIs to Measure the Effectiveness of Security Implementations22:48 Measuring the Decision Quality25:12 Most Common IAM Anti-Patterns29:40 AI Agents for Automated Root Cause Analysis of IAM Failures33:27 Will AI Agents go Fully Autonomous?35:40 Using AI to Bypass IAM Security39:14 Cloud Security Trend From 2012 Should Die42:33 Future of AI Cloud Security44:14 Summary45:24 Learning Recommendations
undefined
Mar 25, 2026 • 45min

AI Security: Hype vs. Reality and the Roadmap to CISO | Ft. Niyati Daftary | Ep. 107 | ScaleToZero Podcast | Powered by Cloudanix

Is the security impact of AI being underrated, or are we worrying about the wrong risks? In this episode, we sit down with a Security Analyst to bridge the gap between high-level security consulting and the deep-trench reality of day-to-day defense.#Cybersecurity #SecurityAnalyst #CISO #AISecurity #SecurityResearch #Infosec #CareerRoadmap #SecurityLeadership #TechPodcast #ScaleToZeroPowered by Cloudanix: https://www.cloudanix.comYouTube: https://www.youtube.com/@cloudanix00:00 Introduction04:55 AI Security Risks Organizations are Worried09:00 Security Impact of AI - Underrated?11:33 Challenges of Security Leaders18:00 Cybersecurity Perspective of a Consultant vs. Analyst22:10 Beliefs vs. Reality in Security Practices23:53 Development of a Security Research Document31:40 Challenges of Leaders Implementing Security Research Notes36:22 Roadmap for Aspiring CISOs and Security Leaders42:22 Learning Recommendations
undefined
Mar 11, 2026 • 48min

Product Security at Scale: Minimizing Friction & Defending AI Integrations | ft. Sana Talwar | Ep.106 | ScaleToZero Podcast

In this episode of ScaleToZero Podcast, we sit down with a Product Security Engineer to discuss the delicate balance between robust security, user experience, and developer velocity.From identifying red flags in security reviews to using AI for point-in-time vulnerability assessments, we cover the tactical moves that early security teams need to make today.The landscape is shifting from "Security vs. Engineering" to "Security + Engineering." If you're an early security team looking to leverage AI to punch above your weight class, this episode is a must-listen.YouTube: https://youtu.be/wv_1NZkv9bsCloudanix: https://www.cloudanix.com00:00 Introduction03:40 Developer-friendly Security in Practice07:22 Minimizing Friction between Security and Engineering09:15 Navigating the Trade-offs between Security and User Experience11:32 Red Flags in Third-Party Security Reviews and Internal Security Reviews19:00 Point-in-Time Vulnerability Assessments using AI21:35 Managing Malicious Updates without Manual Reviews24:55 Communicating Third-Party Security Risks to a Product Manager28:50 Improving Product Security using AI for Early Security Teams33:20 AI Performing Critical Security Job Functions35:27 Patching AI Prompt Injection Attacks41:05 AI Integration and Reshaping Security Landscape46:04 Summary#ProductSecurity #DevSecOps #AppSec #Cybersecurity #AISecurity #ProductManagement #DeveloperVelocity #TechLeadership #ScaleToZero
undefined
Feb 25, 2026 • 49min

eBPF, MCP Servers, and the Kernel-Level Future of AI Security | ft. Ammar Ekbote | Ep. 105 | ScaleToZero Podcast

In this episode, we sit down with a veteran Security and Cloud Infra Leader to deconstruct the architecture of modern workload monitoring and the emerging risks of AI-driven connectivity. We dive deep into eBPF—the technology providing "invisible" observability—and the security implications of MCP (Model Context Protocol) servers in the enterprise.Whether you're an infra lead or a security engineer, this episode provides the technical depth to help you stay ahead of the curve.Also available on YouTube: https://youtu.be/iCfEJlgXFBU00:00 Teaser and Introduction04:12 Architectural differences between Agentless and Agent-based scanning07:50 Losing security signals in case of Agentless scanning09:23 Challenges of Agent-based scanning10:45 Vendor checklist for production release11:45 Noisy neighbour challenge and customer application14:52 Securing large agent-based vendor machines16:40 Use of eBPF for invisible workload monitoring19:17 Securing the eBPF21:00 Does eBPF solve the stability and performance risks?23:25 Security risks when LLMs use MCP servers27:16 Detect and Avoid MCP in an organizational environment32:32 Why use eBPF for security MCP?35:10 Using eBPF to run local servers in a secure way37:00 Can eBPF secure data leaks to AI models?41:19 Justifying stakeholders for using kernel-level security43:25 Evangelizing a security-first mindset44:50 Starting point for developer-led security using eBPF46:30 Learning recommendations47:10 Summary#eBPF #CloudSecurity #AISecurity #MCPServer #DevSecOps #AgentlessScanning #CloudInfrastructure #InfoSec #CybersecurityPodcast #LLMSecurity #KernelSecurity
undefined
Feb 4, 2026 • 1h 9min

The Last9 Story: Scaling Engineering, GTM Strategy, and the Reality of "Overnight Success | Ep.104 | ScaleToZero Podcast | Ft. Nishant Modak | Cloudanix

What does it take to build a company that redefines how we look at engineering reliability? In this episode, we sit down with the Founder of Last9 to peel back the curtain on the journey from a single "Aha!" moment to a scaling enterprise.We move beyond the pitch deck to discuss the raw reality of building a startup, the mental models for engineering leadership, and what Vision 2026 looks like in the age of GenAI.Transcript: https://www.scaletozero.com/episodes/the-last9-story-scaling-engineering-gtm-strategy-and-the-reality-of-overnight-success/Cloudanix: https://cloudanix.com/YouTube: https://youtu.be/a955CYXLRdg00:00 Introduction of Nishant Modak03:00 Birth of Last906:40 The "Aha" moment13:00 How is Last9 different?19:10 Building blocks of Last924:20 The Moments of Overnight Success33:05 Go To Market Strategy41:40 Mental Model to Separate Administration and Engineering46:00 Engineering vs Selling49:40 Hard things of hard things, which gave results over time55:00 Vision 2026 with GenAI58:04 KPIs that helped in scaling01:01:25 Personal learnings and life#StartupStory #FounderJourney #EngineeringLeadership #Last9 #GTMStrategy #Entrepreneurship #SRE #Reliability #GenAI2026 #ScalingStartups #techpodcast
undefined
Jan 14, 2026 • 49min

AWS vs. GCP IAM Architecture & The Future of Security in 2026 | ft. Senior Security Engineer (CISSP) - Sneha Malshetti

This episode is a masterclass in modern cloud architecture and the fast-evolving world of AI security. In episode 103, we sat down with a Senior Security Engineer (CISSP) to break down the architectural nuances of AWS vs. GCP IAM and how security roles are evolving in 2026. From mastering cross-account access to defining data perimeters for AI training models, this episode is a deep dive into the technical and strategic layers of cloud-native security.YouTube: https://youtu.be/Y_OCpI8LJb4Transcript: https://www.scaletozero.com/episodes/aws-vs-gcp-iam-architecture-the-future-of-security-in-2026-with-sneha-malshetti-cissp/Sneha Malshetti: https://www.linkedin.com/in/sneha-malshetti/Fearless Organization: https://www.amazon.in/Fearless-Organization-Psychological-Workplace-Innovation/dp/1119477247TLSHandshake Deep Dive and decryption with Wireshark: https://www.youtube.com/watch?v=25_ftpJ-2MECloudanix: https://cloudanix.com/00:00 Introduction04:30 Architectural differences between AWS and GCP IAM08:40 Best practices to approach IAM in AWS and GCP11:00 Achieving centralized identity federation for a consistent user experience13:45 Manage cross-account access securely in AWS vs GCP14:40 Balancing RBAC for large organizations18:00 Automation and Auditing recommendations for IAM21:42 Managing access for large organizations23:55 Monitoring Privileged Access27:20 Balancing Security and Speed30:19 Data Perimeter boundaries and their importance34:20 How have security functions transformed in the AI world?36:55 Will AI replace Humans?38:15 Managing sensitive data used to train AI models42:42 Security Trends in 202645:48 Summary46:48 Learning Recommendation
undefined
Nov 26, 2025 • 53min

Zero Trust AI & Human Risk | Senior Director of Security | Ft. James Cash | Ep. 102 | ScaleToZero Podcast | Cloudanix

What are the security weaknesses that everyone overlooks, and how is the rise of AI changing the risk calculus? We sat down with a Senior Director of Security and Compliance to discuss strategic defense, from securing human capital to implementing Zero Trust for AI systems.This episode is essential for CISOs, security leaders, and compliance officers navigating the volatile landscape of modern risk.How does AI work: https://blog.hubspot.com/marketing/how-does-ai-workYouTube: https://youtu.be/feudnGhDZ78Transcript:https://www.scaletozero.com/episodes/zero-trust-ai-human-risk-a-guide-to-future-proofing-security-with-james-cash/00:00 Introduction05:08 Significant security weaknesses often overlooked10:25 AI SBOMs and Security14:10 Biggest risks in security from AI systems16:31 Ensuring AI systems are secure and responsible20:55 Zero Trust AI Systems for Internal and Third-Party Teams24:20 Evolution of Risks with Rise in AI27:15 Evaluating between Traditional vs. AI SaaS provider33:50 Keeping Stakeholders' interests in Security39:21 Responding to Insider Threats45:45 KPIs for Human Risk Management49:41 Summary50:51 Learning recommendations
undefined
Nov 12, 2025 • 52min

Beyond Tech: Culture and Mindset of Security Engineering | Ft. Dakota Riley | Ep.101 | Cloudanix

In modern, fast-moving organizations, security is a shared responsibility, not a silo. We sat down with a Staff Security Engineer who operates at the intersection of development speed and security integrity to explore what truly defines a strong security program.This episode offers essential advice for leadership, engineers, and recruiters, covering everything from core culture to the risks of new AI models.Also available on YouTube: https://youtu.be/2ut2GQPWA4I00:00 Introduction05:41 CyberArk Acquisition07:40 Top 3 Elements of Building a Strong Security Culture10:50 Good Engineering is Security Engineering13:20 Why do organizations face challenges in achieving a security culture?16:54 Moving Fast - Startups vs. Large Enterprises19:08 Addressing challenges - Startups vs. Large Scale Companies23:00 KPIs to Show Security Progress26:16 Security Teams as Enablers32:57 Right Mindset for Security Engineering36:36 Hiring the Right Security Talent38:31 Addressing Non-Deterministic Nature of LLMs43:13 Trade-Offs of Implementing Bias in Alert Triaging Systems46:11 Training an Agent for Catching Malicious Attacks48:35 Summary49:35 Learning Recommendations
undefined
11 snips
Oct 29, 2025 • 55min

Kubernetes Security Mastery: Shifting Mindsets for Ephemeral Environments | Ep.100 | Ft. Dinis Cruz

Dinis Cruz, a seasoned security leader and founder of Cyber Boardroom, dives into the transformative world of Kubernetes security. He discusses the essential shift from static data centers to ephemeral environments and emphasizes the need for engineering mindsets in security teams. Dinis highlights the challenges of balancing security with business priorities, effective logging for containers, and managing identity in this dynamic landscape. He also explores the impact of generative AI on security roles and the necessity of anticipating AI-driven attacks. A must-listen for cloud-native practitioners!
undefined
Oct 15, 2025 • 1h 42min

A PSA's Journey - Bridge Between Business and Technology at AWS | Ft. Lalit Khatter | ScaleToZero Business

Have you ever wondered what it takes to drive successful partnerships in the AWS ecosystem? In this episode, we sit down with Lalit Khatter, a Senior AWS Partner Solution Architect, who gives us a deep dive into his dynamic role and the strategies that help AWS Partners thrive.Lalit shares his journey from Software Engineer to PSA and reveals the essential traits of a successful AWS Partner.Whether you're an aspiring PSA, a business leader at an AWS Partner, or simply curious about the engine that drives cloud adoption, this podcast offers unparalleled insights!00:00 Teaser and Introduction03:57 Role of a Partner Solution Architect and their day-to-day08:15 Why Partner Solution Architect as a job role?19:52 Transition from software engineer to AWS PSA23:22 How would a SI company work with Lalit for partnering with AWS?31:04 Trait of a successful partner38:40 AWS programs that help partners get visibility to prospective customers41:58 Aha moment after getting started with the AWS partner environment48:08 Scaling with AWS Marketplace01:03:05 Amazon Pace and Ambassador Program: Hand-in-Hand01:06:23 AWS Ambassador Program and how to invest in it01:10:20 Business Outcome Accelerator (AWS BOX)01:22:53 Weekends of Lalit Khatter01:28:40 Next 5 years of AWS Partner programs01:33:01 Stuff about Lalit

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app