Topics: Technology
**Matt Spitz** (0:00)
Securing a company is like securing a house. When people think about security breaches, what they think about are the really sophisticated attacks, like nation state attacks, where the equivalent would be climbing up a tree to go like dive in the third story window, like jump over the laser beam and steal the jewels.
It's a lot easier to break into a house if you walk in the front door that's unlocked.
**SPEAKER_2** (0:20)
When times are tough, engineering leaders need as much help as they can get.
Linear B helps dev teams continuously improve by providing correlated data, context, and automated workflows that help streamline code delivery and improve developer experience. Learn more at linearb.io. And check out our free tool GitStream. GitStream is helping developers everywhere merge their code faster by revolutionizing the pull request review process. Every pull request is different. It's time we start treating them that way. Download GitStream for free and learn more at GitStream.CM.
Now, on to today's episode.
**Dan Lines** (0:57)
Hey, what's up, everyone? Welcome to Dev Interrupted. I'm your host, Dan Lines, and today I'm joined by Matt Spitz, Head of Engineering at Vanta.
**Matt Spitz** (1:06)
Thanks for having me.
**Dan Lines** (1:06)
Now, Matt, you're a security and systems expert.
Vanta, where you serve as Head of Engineering, achieved unicorn status earlier this year with a valuation of 1.6 billion, you know, a tiny amount of money. Congrats on that.
**Matt Spitz** (1:23)
Thank you very much. It's a testament to the value we're delivering to our customers.
**Dan Lines** (1:27)
Yeah, very like awesome milestone to hit.
And, you know, it's probably safe to say that one of the reasons Vanta is doing so well is because you identified something we all kind of know to be true or maybe, you know, have been in this situation before. But it sounds something like startups suck or not so good at security. And we're gonna talk about why that is, what startups can do to change that, and how to build a better company culture, really at any size to embrace some of these great habits. But before we dive into all of that stuff, always like to get to know you a little bit more. How did you get started in engineering?
**Matt Spitz** (2:10)
Yeah, I've always been a tinkerer. I was the one who was responsible for keeping the family PC in working order. I was always the one who was tasked by my family and other families to fix the VCR or move the clocks at daylight savings time or whatever. And the thing that really drew me to software engineering in particular is that save some really awful mistakes that you can make, it's hard to really truly break something.
And so you get as many tries as you want to build whatever you're trying to build in contrast to something where you'd be building it physically and like break it and then have to go back to the hardware store and then buy some more wood and fix it. With software engineering, you really truly can't do anything and that unlocked my imagination of what I could build.
**Dan Lines** (2:59)
That's really cool. That's like one of the most poetic ways I've ever heard anyone talk about software engineering, but it's totally true because you get that rapid iteration, you can do whatever you want over and over again. And that's really cool that you have a passion for it. Now on the security side, did you come build up a career in security or was it more general engineering? How does security play for you?
**Matt Spitz** (3:25)
Yeah, so I would say that I was, before it would be obviously at Vanta, I'm very immersed in security, not only as a head of engineering, who at what I joined was solely responsible or mostly responsible for the security of the company, but also given the product that we build and the product that we deliver to our customers is obviously a security product. Previous to that, I was more of a customer of security. If that makes sense, I would work with security teams. And I think honestly, just sort of given the impression of security in software engineering, it's often positioned as the bad guys who are gonna say no to whatever you're trying to do.
And I had a really eye-opening experience five, six years ago when I was at Dropbox where I was responsible for a team that was building new and adjacent features at Dropbox. So these were things that were not core files they can share, but things you could build on top of it.
Like e-signatures, file transfer, stuff like that. It was not, it was zero to one products in the orbit of what Dropbox was already doing. And what that meant was a lot of experimentation, a lot of just like building really quick and dirty MPPs to get validation and see what our customers wanted.
32 more minutes of transcript below
Thousands of transcripts fetched by people building searchable podcast archives
Try it now — copy, paste, done:
curl -H "x-api-key: pt_demo" \
https://spoken.md/transcripts/1000651996090
Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.
From $0.10 per transcript. No subscription. Credits never expire. Prices exclude VAT, added at checkout for EU customers. Not what you expected? Email us within 14 days with 20 or fewer credits used and we refund the pack in full.
Using your own key:
curl -H "x-api-key: YOUR_KEY" \
https://spoken.md/transcripts/YOUR_EPISODE_ID