Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

In conversation with GitLab’s CISO, Chaim Mazal: “I think to be successful in this role, you have to be a complete and total optimist.”

From hacking to becoming a CISO, and studying to become a Rabbi, Chaim Mazal’s seen it all and has some solid advice for fellow defenders.

Mon, 07 Sep 2026
In conversation with GitLab’s CISO, Chaim Mazal: “I think to be successful in this role, you have to be a complete and total optimist.”

Cyber Daily: Chaim, thanks for taking the time with us today. From just a cursory glance at your career, you’ve put in a lot of work to get where you are, so that seems a good place to start – what’s driven you throughout that career, and how did you move from hacking on the one hand to where you are as a CISO today?

Chaim Mazal: So, you know, after having gone through executive coaching and training a myriad of times at different organisations, the unifying theme is that… Achievement is my number one driver. I don't know what underlying foundational things happened through my childhood that pushed that one to the top.

But I was always curious about how things worked, and then also how to go ahead and have a non-standard, non-traditional view of that working capacity, and was curious about how to make things work in their non-intended purpose, and that curiosity, mixed with that drive, for solving problems.

 
 

So, just to give a linear view, my first job was doing technical support for Microsoft on their initial cloud offerings, which was called Business Productivity Online Suite, and I was obsessed with computers as a child and through adolescence.

And I was like, oh, this is not the thing that I love about technology. It was obviously a great, great organisation, but the purview that I had was extremely limited. I had very focused tasks, repeating the same cycles throughout the day. Extremely technical.

I dealt with Fortune 500 customers, but became disenchanted with the whole thing. Take the thing that's my passion, and can… is it really a career, right?

So I took a little bit of pause in between, and kind of tried to reanalyse and reshape things, and I got this amazing opportunity to work for a boutique cyber security firm, and they asked if I was interested in helping them lead their security research function.

Well, that's what we call it now. I guess it was pen testing, and so, I did that, and I was immediately re-enamoured: this is the thing that I love, trying to view things in an objective way and create material results that weren't aligned, with the traditional way of thinking.

Basically, a large, large, large, large puzzles.

And so I did that for a while. And then I was presented with an opportunity to work at a big data analytics company that was started by the co-founder of Groupon. I came on super early as employee 100 or something like that, and they hired me to be a penetration tester, but as things continued to scale, and they were serving Fortune 100 industrial companies, Caterpillar, Electromagnetic Diesel, Berkshire Hathaway Energy, all these things, and so they said, hey, you have a penetration testing background, but you also have an engineering background. We need someone to help secure our software development lifecycle, and we think that you have the skill set to do that, and we'd like to empower you to build a team out around you.

And, that was my first transition, and big opportunity, into leadership, and I was still very early on in my career, and so that same trajectory continued to follow me throughout my career.

I never asked for it. It was kind of like…

Cyber Daily: Right place, right time?

Chaim Mazal: Yeah, I guess no good deed goes unpunished, right?

So I led the application security team there, and I was very fortunate that, because of the space in tech, and they aggregated and assembled the best practitioners from all over the globe. It was a Chicago-based company, but I'd say that 90 per cent of the company wasn't actually Chicago-based.

They were all relocated to Chicago for this initiative and effort, and so I got to work with some really, really tremendous people, and I was able to model myself after some of the best people I've had the experience to work with professionally, which really helped me have a vision of what good looks like going forward in all my other adventures.

After that, I went and I led security architecture at a fintech company, and I was really focused in my group with how we tokenise credit card information, and be able to have a myriad of different product lines that all interacted, but we didn't have that transfer of data sets. It was in one secure location, and we were able to reference it through tokens.

And I think, at the time, there was only a very small handful of companies that had figured this out, and so you really had to figure everything out on the fly. There was some information that was available, but really, it was like almost recreating the wheel.

So a lot of this, experience, with that, and most of my activities, again, were embedded deeply in the engineering org, to solve and resolve these problems.

And then after that, I got the opportunity to join ActiveCampaign's sales and marketing automation platform and be the first security hire who was tasked to be the CISO and build out the security function.

I had the opportunity to work with Tony Newcomb, who was the SVP of Engineering at Salesforce, where he led teams of 500, 600 engineers, and got to work alongside him for three and a half years, and really got to model, again, around somebody who was tremendous, and I built out one of the things that I'm still, to this day, the most proud of; I built out a world-class, engineering-first-led security team, and at the time, this was all still very nascent.

I had dedicated engineering teams that built security features into our platform and product, and who actually built core services into the platform as well. And so, a tremendous first step of what I envisioned, security, to be as a go-forward, perspective.

And then, after that, I used a product, internally that was called Kanji, which was mobile device management for Macs. And I started having some conversations with them, and pushing their product roadmap in a certain direction, and had some very strong opinions and ideas, because it's been something that my teams were dependent on historically.

And they were like, we love you. How do you feel about coming and joining our organisation?

I took a risk and took a bet, and ultimately they brought me in as CISO, and then within six months, they asked me to lead the entirety of the engineering work. So, yeah, SVP of technology/CISO, but for all intents and purposes, I was the CTO there, they just hadn't had that title yet.

Post that, I got asked to join Gigamon; and Gigamon has 87 of the Fortune 100 as customers, and the US federal government's the largest customer; ten different nation states depend on it for their their national security, and so I was posed with the challenge to help secure the world's largest, most complex, most scrutinised networks in the world.

The mission statement was so big, that it was hard for me to pass it up. And so, I got there, and immediately, after being the CISO there for three or four months, I was actually asked to take over all of technology, yet again. And so, basically, all of data, all of back-end, front-end business applications, as well as, IT, network, and all of infrastructure as well.

The only thing I wasn't responsible for was the actual product development deliverables, but I still worked very closely with product and CTO to help define requirements going forward.

And, then, ultimately, I was having a few conversations, and GitLab came across my desk, and I was like, this is my dream role.

So, just for some more historical context, when I was a CISO at ActiveCampaign I started working very heavily with security product companies, or security-adjacent product companies in an advisory capacity, with the goal of having as much influence on the tools that me and my peer groups use in our day-to-day, so we could be successful in our role and mission statements, and so I started working with companies like Cloudflare, GitLab, Lacework, Cyber Reason, and then all of these cutting-edge security VCs in an advisory capacity.

When I got the call from GitLab, I had already been a customer for eight years, and had been an advisor for five.

The biggest portion of my career was spent in, essentially doing what we now call DevOps transformations, really putting my stamp on what DevSecOps means for security organisations. And one of the parts that I kind of left out is that at a young age, I was very much involved in, I guess, the hacker community as a teacher, and which is how my passion was reignited in the security research/penetration testing role, which eventually turned into the career that it is today.

Cyber Daily: It seems like a very natural progression to be looking for the next big puzzle to solve, so going from starting at age 12, being captivated by the hacker community to where you are now, it seems like a perfectly linear progression.

Chaim Mazal: Yeah

Cyber Daily: So, you talked a lot about seeing what good looks like with the people you've worked with and for. How important is mentorship in this industry, especially in your role as a CISO today?

Chaim Mazal: Oh, I think it's, like, 90 per cent of the equation, and I also am a firm believer that you have active mentorship and passive mentorship, and that mentorship could be in the positive and the negative, right? Every single instance is an opportunity, and so as we, collectively, go through our journey in career, being able to understand what you appreciated and what you didn't appreciate, and what worked well versus what didn't work well, and making internal commitments to yourself that when I'm in that role, when I'm in that position, I will do this, I will behave like this, and I will shy away and not do the opposite, is very, very important.

One of the things that I feel very strongly and passionate about in every team that I build and have the opportunity to work with, is creating exposure, because I think people don't put enough emphasis on it.

When we were building out the security org at Uptake, after I was there for about three months, they brought in a CISO, and this CISO was the SVP of Spider Labs, which was the offensive division of Rapid 7 at the time, which in the pen testing community, everyone was like…This is it, this is the standard.

His name was Nick Bercoco, and he's the one who assembled all this tremendous security talent, and I reported directly to him. And whether I knew it at the time, or whether he knows it or not, from a go-forward perspective, all of the security programs that I built were built under that frame of reference, that I had an opportunity to be in the right place at the right time, as you alluded to, a very special moment in time.

And going forward, this is the baseline. Obviously, I've evolved things quite considerably since then, but the entire premise and the worldview that was approached by Nick, I adopted and made my own.

I've never said that out loud before; that's wild.

Cyber Daily: We're looking at quite a considerable career here. You've probably seen a lot of changes, and because of that background of yours in the hacking community, you've probably seen what's changed in the industry, so…

Do you think your average young person who's looking at their career and might be thinking, I like solving puzzles, wow, this whole hacking community's great, do you think they're being motivated by similar things that motivated you to get into that?

Chaim Mazal: I hope so. I think curiosity, I believe, is one of the number on, traits to being successful in this, because if you don't love what you do, it could be a very rough go. So, questioning everything, being very much aligned to solving challenges, I promise you, even though we have this continued evolution of our industry… New look, same great taste, right? We go in cycles.

The only difference is the speed at which some of this innovation is coming now, which has been a unique facet of AI.

But really, ultimately, the same problems that I solved at 12 years old, from an alternative perspective, are the same problems that I'm solving now at this stage in my career. It's just the ability to abstract and obscure whatever the technology is, and think about things holistically.

It’s understanding what the blockers are, where we need to go, and at what value, intrinsically, we can provide outside of the core problem we're trying to solve. And that's another thing I think that's been instrumental. A lot of times, people tend to focus on the unique challenge at hand, and how we go ahead and resolve that challenge and move forward, but thinking about how to change a challenge into a benefit proposition, outside of just removal of the obstacle, is something that, I found, has been quite beneficial.

So, thinking about primary, secondary value streams of the work and effort and energy you're doing, and how you can repurpose it and contribute it back to the organisation that you're at, and things like that, are super important.

But I think that now is probably a more exciting time than ever to join this career field, because you have so much more opportunity and flexibility within AI, because it's the Wild West all over again. So, we have the same core fundamental principles, but they're presenting themselves in wild new ways that I think we haven't seen thus far, so…

Cyber Daily: I think that's a great segue into the fact that it seems every other day now, I'm waking up and I'm seeing another AI has broken containment and accidentally hacked something. We had, just here in Australia, one guy asking his Claude agent: can you book me into a gym session?

And his agent said: “Well, I could, but I can't, because it's busy. I better get rid of that guy, and I'll bump you to number one”. And that's just one person accidentally hacking the booking system of his local gym.

What are your thoughts on this whole rogue AI phenomenon we're seeing at the moment?

Chaim Mazal: It's so interesting, because in the industry, like, we really talked in a hype cycle about zero trust for years, right? Zero trust seemed to be the buzzword of the moment. And a lot of that promise didn't materialise.

But I think that this is actually, for the first time, we have, like, a real driver where this is on us, where we actively have to go ahead and follow this format and segment things off. And it's kind of interesting, because we're actually… It is cyclical.

We went from network assets, identity, and now, the last 0 years, we've primarily been focusing on assets and identity, and now we just threw the whole thing into a tailspin, and we're saying, yes, collectively, all of those things have to be done, and they all have to be done really well, right?

Cyber Daily: I guess it's like when you have a huge workforce, right? Most of your employees, your human employees, will probably get an intimation that they shouldn't be doing this thing, this is probably bad. And I think what we're seeing with AI agents is they're not having that thought process…

They're going, oh, I can do this thing, I'm allowed to do this thing, because no one's told me I can't do this thing. And I think that's a huge mind shift that a lot of people who are in the industry, both on your side and throughout the C-suite, are really going to need to get their head around that

That these AI agents might be artificially intelligent, but they're also artificially stupid.

Chaim Mazal: Yeah, absolutely, and so I think that's why we, as an industry, I think the natural progression of what we're gonna see happen is effectively building training wheels. And what I mean by that is having a security harness that focuses on a couple of key areas is going to be key to ensuring that the wheels don't fall off.

And so, identity and access management, being able to have auditable, attributable guardrails from an identity perspective that we can plug into all of our other tools that we have for consumption, and be able to actively track and monitor…

And then we have the second portion, which is the runtime prevention analytics for anomalous activity. And then the third one – which I think is now becoming top of mind for people – we're going to actively have to start depending on AI gateways that are looking at internal and external workflows as far as egress to be able to make sure that agents stay contained within sandbox environments, and that there aren't these breakout scenarios which ultimately lead to negative outcomes.

And the other thing, I'm just gonna say it, I don't know if I should say it, but I feel like a lot of these frontier models, although they are doing tremendous work, and they are incredible at the rate of innovation, they purposely built guardrails into these models, and we've only watched these events take place when they intentionally disengaged those guardrails.

So… is this reality, or is this marketing/negligence? Or a little bit of both?

Cyber Daily: Yeah, yeah, I've heard that from a few people as well. This is a great advertisement for the ability of your agent: oh no, it's so powerful, it broke out!

Chaim Mazal: Yeah, that's right. Look at us, look at us, we can do it too, right?

Cyber Daily: Yeah, yeah.

Chaim Mazal: But the other portion is, with the adoption of open-weight models and the configurability that exists going forward, anyone can do anything, and it could be simply, purely through oversight.

So the thing that we're watching happen now, which could be seen as a marketing ploy about how powerful these models are, is going to become a definitive reality just based on people using open-weight models and having highly configurable, customisable models where they can say: hey, for these intents and purposes, we don't want to have these guardrails, because for this specific outcome they'll be prohibitive.

And then, once you take those guardrails off, all bets are off

So I think it’s having that clear, defined security path that prevents any of these negative scenarios from happening, and it's going to be from a multitude of perspectives. Again, we talked about zero trust policy, segmentation, observability, ingress, egress… Looking at identity and access management, looking at the runtime perspective. Those are all going to have to be a unified harness in organisations for them to have a level of confidence that they can deploy these agents and have them create outcomes for their organisations without creating negative impact.

Cyber Daily: I have one last question, then I'll let you go. You strike me as someone who takes everything they've learned in their past and applies it to their present, both in a career and a problem-solving manner.

So where does your training as a rabbi, your study as a rabbi, fit in? How does that inform your day-to-day? Because I imagine there's probably quite a bit of learning that can cross over.

Chaim Mazal: Yeah, 100 per cent. So I think, the biggest thing is…

Cyber Daily: If you don't mind me bringing that into it.

Chaim Mazal: No, absolutely, 100 per cent.

I spent, from a practical standpoint, 16 hours a day studying legal books, right? And so from that perspective, which required, obviously, the ability to have intense focus, I think, is something that I probably didn't have before that.

And then, I think to be successful in this role, you have to be a complete and total optimist. You have to believe that everything has a silver lining, that there's positivity baked in, and you really have to be committed to the mission statement, which is ultimately making the world a safer, better place for people that depend on the things that you're building and shipping every day, and I think that perspective has been instrumental.

I think on the management side, the humanistic perspective… A little bit of goodness and kindness goes a long way, and it really makes a difference, not only in your life, but in people's lives around you. So if you can have a positive impact, and you can put yourself in their seat, and have care and empathy, I think you'll be a much more successful leader.

Cyber Daily: I think that is an outstandingly positive note to end on. Thank you so much for your time, Chaim.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.