# Why Startups Suck at Security w/ Vanta's Head of Engineering, Matt Spitz | Dev Interrupted Powered by LinearB

> Vanta's Head of Engineering Matt Spitz helps us understand why so many startups are bad at security - and how to fix the problem.

[Podcast](https://linearb.io/dev-interrupted/podcasts)

/

Why Startups Suck at Security w/ Vanta's Head of Engineering, Matt Spitz

# Why Startups Suck at Security w/ Vanta's Head of Engineering, Matt Spitz

By Matt Spitz

|

November 15, 2022

![Matt_Spitz_Podcast_Card_3d9f3e691f](https://assets.linearb.io/image/upload/c_limit,w_2560/f_auto/q_auto/v1/Matt_Spitz_Podcast_Card_3d9f3e691f?_a=BAVMn6ID0)

When your startup is struggling to find its product-market fit, security is the last thing on your mind - and according to security expert Matt Spitz, that’s perfectly fine!

Matt is Vanta's Head of Engineering and he joins this week's episode of Dev Interrupted to explain everything you ever wanted to know about startups and security.

Matt debunks the real security risks we face (think S3 buckets, not nation states), how to create a company culture that embraces security and when your startup needs to start caring about all this stuff.

### Episode Highlights Include:

* (2:06) Matt's career journey
* (7:00) Why startups suck at security
* (13:11) Sources of security risks (employees, vendors, S3 buckets)
* (20:54) Nation states aren't the danger
* (25:25) Creating a culture of security
* (28:41) "Blameless culture of reflection"
* (33:20) How to think about investing in security

## Real conversations with top engineering leaders

Find us on

[](https://www.linkedin.com/showcase/dev-interrupted/)
[](https://devinterrupted.substack.com/)

## Your next listen

[![Cover image for Rebuilding CLIs for agents, it’s time to get MCP-certified, and why human code review will never catch up](https://assets.linearb.io/image/upload/c_limit,w_2560/f_auto/q_auto/v1/agentic_cli_tools_mcp_certification_code_review_23be877e85?_a=BAVMn6ID0)](https://linearb.io/dev-interrupted/podcast/linux-foundation-mcp-certification-agentic-loops-pull-request-bottleneck)

Dev Interrupted

[Rebuilding CLIs for agents, it’s time to get MCP-certified, and why human code review will never catch up](https://linearb.io/dev-interrupted/podcast/linux-foundation-mcp-certification-agentic-loops-pull-request-bottleneck)

This week on the Friday Deploy, Ben and Andrew break down the Linux Foundation's new MCP certification and the fundamental mechanics of agentic loops. Discover...

[![Cover image for How to see in the dark factory | LaunchDarkly's Cameron Etezadi](https://assets.linearb.io/image/upload/c_limit,w_2560/f_auto/q_auto/v1/Blog_Comprehensive_DORA_Guide_2400x1256_66_6f6a37357d?_a=BAVMn6ID0)](https://linearb.io/dev-interrupted/podcast/launchdarkly-cameron-etezadi-dark-factory-agent-runtime-frameworks)

Dev Interrupted

[How to see in the dark factory | LaunchDarkly's Cameron Etezadi](https://linearb.io/dev-interrupted/podcast/launchdarkly-cameron-etezadi-dark-factory-agent-runtime-frameworks)

LaunchDarkly CTO Cameron Etezadi joins the show to discuss why the traditional "two-pizza" engineering team is dead. Discover how runtime agent frameworks and...

[![Cover image for How to cultivate expertise with local models, delegating to subagents, and we all really stopped reading, huh?](https://assets.linearb.io/image/upload/c_limit,w_2560/f_auto/q_auto/v1/local_ai_expertise_subagents_delegation_strategies_616640e057?_a=BAVMn6ID0)](https://linearb.io/dev-interrupted/podcast/open-source-glm-models-local-ai-coding-protecting-first-brain)

Dev Interrupted

[How to cultivate expertise with local models, delegating to subagents, and we all really stopped reading, huh?](https://linearb.io/dev-interrupted/podcast/open-source-glm-models-local-ai-coding-protecting-first-brain)

This week on the Friday Deploy, Ben and Andrew break down the rise of highly capable open-source models like GLM 5.2 and the reality of running local AI for...