# Why Startups Suck at Security w/ Vanta's Head of Engineering, Matt Spitz | Dev Interrupted Powered by LinearB

> Vanta's Head of Engineering Matt Spitz helps us understand why so many startups are bad at security - and how to fix the problem.

_This is a markdown rendering of a live HTML page on linearb.io, generated for AI/LLM consumption — it is not a markdown-only site. To get the full HTML page instead, request this URL with an explicit `Accept: text/html` header (no wildcard, no markdown preference)._


```json
{
  "@context": "https://schema.org",
  "@type": "PodcastEpisode",
  "name": "Why Startups Suck at Security w/ Vanta's Head of Engineering, Matt Spitz",
  "description": "Vanta's Head of Engineering Matt Spitz helps us understand why so many startups are bad at security - and how to fix the problem.",
  "url": "https://linearb.io/dev-interrupted/podcast/why-startups-suck-at-security",
  "datePublished": "2022-11-15T00:55:26.000Z",
  "partOfSeries": {
    "@type": "PodcastSeries",
    "name": "Dev Interrupted",
    "url": "https://linearb.io/dev-interrupted/podcasts"
  },
  "actor": {
    "@type": "Person",
    "name": "Matt Spitz",
    "jobTitle": "Head of Engineering",
    "worksFor": {
      "@type": "Organization",
      "name": "Vanta"
    }
  }
}
```

```json
{
  "@context": "https://schema.org",
  "@type": "BreadcrumbList",
  "itemListElement": [
    {
      "@type": "ListItem",
      "position": 1,
      "name": "Home",
      "item": "https://linearb.io/"
    },
    {
      "@type": "ListItem",
      "position": 2,
      "name": "Dev Interrupted - Podcasts",
      "item": "https://linearb.io/dev-interrupted/podcasts"
    },
    {
      "@type": "ListItem",
      "position": 3,
      "name": "Why Startups Suck at Security w/ Vanta's Head of Engineering, Matt Spitz",
      "item": "https://linearb.io/dev-interrupted/podcast/why-startups-suck-at-security"
    }
  ]
}
```

[Home](https://linearb.io/)

/

[Podcast](https://linearb.io/dev-interrupted/podcasts)

/

Why Startups Suck at Security w/ Vanta's Head of Engineering, Matt Spitz

# Why Startups Suck at Security w/ Vanta's Head of Engineering, Matt Spitz

By Matt Spitz

|

November 15, 2022

![Matt_Spitz_Podcast_Card_3d9f3e691f](https://assets.linearb.io/image/upload/c_limit,w_2560/f_auto/q_auto/v1/Matt_Spitz_Podcast_Card_3d9f3e691f?_a=BAVMn6ID0)

When your startup is struggling to find its product-market fit, security is the last thing on your mind - and according to security expert Matt Spitz, that’s perfectly fine!

Matt is Vanta's Head of Engineering and he joins this week's episode of Dev Interrupted to explain everything you ever wanted to know about startups and security.

Matt debunks the real security risks we face (think S3 buckets, not nation states), how to create a company culture that embraces security and when your startup needs to start caring about all this stuff.

### Episode Highlights Include:

* (2:06) Matt's career journey
* (7:00) Why startups suck at security
* (13:11) Sources of security risks (employees, vendors, S3 buckets)
* (20:54) Nation states aren't the danger
* (25:25) Creating a culture of security
* (28:41) "Blameless culture of reflection"
* (33:20) How to think about investing in security

## Real conversations with top engineering leaders

Find us on

[](https://www.linkedin.com/showcase/dev-interrupted/)
[](https://devinterrupted.substack.com/)

## Your next listen

[![Cover image for Why AI gains are unevenly distributed in your engineering team | Asana’s Arnab Bose](https://assets.linearb.io/image/upload/c_limit,w_2560/f_auto/q_auto/v1/Blog_Comprehensive_DORA_Guide_2400x1256_72_a71bae404c?_a=BAVMn6ID0)](https://linearb.io/dev-interrupted/podcast/asana-arnab-bose-ai-productivity-agentic-work-management)

Dev Interrupted

[Why AI gains are unevenly distributed in your engineering team | Asana’s Arnab Bose](https://linearb.io/dev-interrupted/podcast/asana-arnab-bose-ai-productivity-agentic-work-management)

Asana Chief Product Officer Arnab Bose explains why enterprise AI gains remain unevenly distributed across engineering teams. Discover how moving from isolated...

[![Cover image for The rise of software factories, the fall of first drafts, and the hidden tax holding back your agents](https://assets.linearb.io/image/upload/c_limit,w_2560/f_auto/q_auto/v1/software_factories_ai_agents_hidden_tax_544434bf00?_a=BAVMn6ID0)](https://linearb.io/dev-interrupted/podcast/dark-software-factories-orchestrators-tax-agentic-compute)

Dev Interrupted

[The rise of software factories, the fall of first drafts, and the hidden tax holding back your agents](https://linearb.io/dev-interrupted/podcast/dark-software-factories-orchestrators-tax-agentic-compute)

This week on the Friday Deploy, Ben and Andrew debate whether dark software factories create engineering efficiency or unmaintainable code rot. Discover why...

[![Cover image for Why the traditional pull request has a target on its back | CircleCI’s Rob Zuber](https://assets.linearb.io/image/upload/c_limit,w_2560/f_auto/q_auto/v1/Blog_Comprehensive_DORA_Guide_2400x1256_70_8130b5ade1?_a=BAVMn6ID0)](https://linearb.io/dev-interrupted/podcast/circleci-rob-zuber-pull-request-ai-agent-cicd)

Dev Interrupted

[Why the traditional pull request has a target on its back | CircleCI’s Rob Zuber](https://linearb.io/dev-interrupted/podcast/circleci-rob-zuber-pull-request-ai-agent-cicd)

CircleCI CTO Rob Zuber joins the show to discuss why the traditional pull request is struggling under the sheer volume of autonomous AI agents. As AI adoption...

## Structured data

_Machine-readable metadata (JSON-LD) embedded in the page for search/AI context — not content rendered on the page itself._

```json
{
  "@context": "https://schema.org",
  "@type": "Organization",
  "name": "LinearB",
  "url": "https://linearb.io/",
  "logo": "https://assets.linearb.io/image/upload/v1715628027/logo-mark-lg.svg",
  "description": "LinearB is the engineering productivity platform that helps engineering leaders prove AI is improving throughput without sacrificing delivery confidence, flow efficiency, or developer experience.",
  "sameAs": [
    "https://www.linkedin.com/company/linearb"
  ],
  "award": [
    {
      "@type": "Award",
      "name": "LinearB is a Leader in the 2026 Gartner® Magic Quadrant™ for Developer Productivity Insight Platforms",
      "dateAwarded": "2026",
      "awardedBy": {
        "@type": "Organization",
        "name": "Gartner®"
      }
    },
    {
      "@type": "Award",
      "name": "Great Place to Work Certification",
      "dateAwarded": "2025-2027",
      "awardedBy": {
        "@type": "Organization",
        "name": "Great Place to Work"
      }
    },
    {
      "@type": "Award",
      "name": "America's Best Startup Employers 2025",
      "dateAwarded": "2025",
      "awardedBy": {
        "@type": "Organization",
        "name": "Forbes Magazine"
      }
    }
  ],
  "hasCertification": [
    {
      "@type": "Certification",
      "name": "SOC 1 Type 2"
    },
    {
      "@type": "Certification",
      "name": "SOC 2 Type 2"
    },
    {
      "@type": "Certification",
      "name": "GDPR Compliance certification"
    },
    {
      "@type": "Certification",
      "name": "ISO 27001"
    }
  ]
}
```

## More on linearb.io

### Top navigation

- [Book a Demo](https://linearb.io/book-a-demo)
- [AI Code Reviews — Catch security risks, bugs, and spec mismatches](https://linearb.io/platform/ai-code-reviews)
- [AI & Productivity Insights — See how AI tools affect cycle time and delivery speed](https://linearb.io/platform/ai-developer-productivity-insights)
- [Measure AI Impact — Track AI adoption and tie it to delivery outcomes](https://linearb.io/use-case/measure-ai-impact)
- [MCP Server — Chat with your data to spot patterns and boost output](https://linearb.io/platform/mcp-server)
- [Resource Allocation — Cost initiatives and shape your investment strategy](https://linearb.io/platform/resource-allocation)
- [Cost Capitalization — Capitalize engineering costs with audit-ready reports](https://linearb.io/platform/cost-capitalization)
- [Dev Team Management — Set targets and tie throughput to business outcomes](https://linearb.io/platform/goals-and-reporting)
- [DevOps Workflow Automation — Policy-based PR routing, approvals, and tests](https://linearb.io/platform/ai-workflow-governance)
- [AI Powered Support — Unify AI and human code delivery in one clear view](https://linearb.io/use-case/ai-powered-support)
- [Optimization — Surface friction with feedback and MCP insights](https://linearb.io/platform/developer-experience)
- [Reporting — Spot what's working and what needs attention](https://linearb.io/use-case/measuring-developer-experience)
- [Surveys — Turn developer feedback into actionable signals](https://linearb.io/platform/developer-surveys)
- [Platform overview](https://linearb.io/platform/overview)
- [Watch now](https://linearb.io/resources/engineering-productivity-gap)
- [Customers](https://linearb.io/customers)
- [Pricing](https://linearb.io/pricing)
- [Why choose LinearB — Explore your data. Measure performance. Act to improve it.](https://linearb.io/why-linearb)
- [APEX framework — The operating model for AI-era engineering teams](https://linearb.io/resources/apex-framework)
- [Anti-FAQ — The questions other vendors won't answer](https://linearb.io/why-linearb/anti-faq)
- [Security — Enterprise-grade compliance and zero code access](https://linearb.io/security)
- [Build vs. buy — The hidden cost of building it yourself](https://linearb.io/resources/build-vs-buy)
- [Dev Interrupted Podcast — Conversations with engineering leaders](https://linearb.io/dev-interrupted/podcasts)
- [Reports & Guides — Deep dives on productivity and delivery](https://linearb.io/resources)
- [Webinars — Expert sessions on productivity and AI](https://linearb.io/resources?category=workshops)
- [Metrics Benchmarks — See how your engineering org stacks up](https://linearb.io/resources/software-engineering-benchmarks-report)
- [Blog — Product updates and practical insights](https://linearb.io/blog)
- [Help Center — Documentation, setup, and support](https://linearb.helpdocs.io)
- [API Docs](https://docs.linearb.io/api-overview)
- [Status](https://www.linearbstatus.com/)
- [Integrations](https://linearb.io/integrations)
- [LinearB Library](https://linearb.io/library)
- [Engineering metrics](https://linearb.io/library/engineering-metrics)
- [Platform engineering](https://linearb.io/library/platform-engineering)
- [Engineering glossary](https://linearb.io/library/engineering-glossary)
- [Developer productivity](https://linearb.io/library/developer-productivity)
- [AI in software development](https://linearb.io/library/ai-in-software-development)
- [Engineering management](https://linearb.io/library/engineering-management)
- [Developer experience](https://linearb.io/library/developer-experience)
- [DevOps](https://linearb.io/library/devops)
- [Engineering operations and the context layer](https://linearb.io/library/engineering-operations)
- [Engineering efficiency](https://linearb.io/library/engineering-efficiency)
- [Software delivery](https://linearb.io/library/software-delivery)
- [Research and data](https://linearb.io/library/engineering-benchmarks-and-research)
- [LinearB is a Leader in the 2026 Gartner® Magic Quadrant™ for Developer Productivity Insight Platforms](https://linearb.io/resources/gartner-magic-quadrant-dpi-platforms-2026)
- [Sign in](https://app.linearb.io/login)
- [Enterprise](https://linearb.io/solutions/enterprise)
- [Contact](https://linearb.io/contact-us)
- [About us](https://linearb.io/about-us)
- [Careers](https://linearb.io/careers)
- [Service agreement](https://linearb.io/services-agreement)
- [Privacy policy](https://linearb.io/privacy-policy)
- [DPA](https://linearb.io/data-processing-agreement)
- [Security FAQ](https://linearb.io/security-faq)
- [Substack](https://devinterrupted.substack.com/)

### Footer

_Additional links from the site footer, not repeated from the top navigation above._

- [GitHub](https://github.com/linear-b)
- [LinkedIn](https://www.linkedin.com/company/linearb)
- [Twitter](https://twitter.com/LinearB_Inc)