Are you ready to transform security from a roadblock to a strategic advantage? In this podcast hosted by Cassio Sampaio, Rippling Chief Information Security Officer Duncan Godfrey will be speaking on building secure products in the B2B SaaS world. Duncan shares insider insights on building security into product development, managing vulnerabilities, and creating a collaborative partnership between product and security teams that accelerates innovation without compromising protection.
Subscribe to the Product Talk podcast on Spotify and Apple Podcasts and catch every conversation with leading product executives.

Show Notes
- Security is a business enabler, not just a cost center
- Embed security engineers directly into product teams for deeper collaboration
- “Shift left” by considering security risks early in the development process
- Threat modeling is crucial for identifying potential security vulnerabilities
- Bug bounty programs provide an essential external security testing mechanism
- Not all vulnerabilities can be reduced to zero – prioritization is key
- Establish clear SLAs for addressing different severity levels of security issues
- Compliance should be addressed early, not as an afterthought
- Automated compliance tools are making regulatory requirements more manageable
- AI presents both opportunities and challenges for cybersecurity
- Security teams should be partners, not gatekeepers, to product development
- Critical (P0) vulnerabilities must be addressed immediately
- Technical product managers can and should challenge security assessments
- Building security into product culture is as important as technical controls
- Cloud migration and AI are transforming how security is approached
- Contractual data agreements are crucial when using AI tools
- Security credentials (like SOC 2) can be a competitive advantage
- Product managers should expect clear, consistent security policies
- Collaboration between security and product teams requires mutual respect
- The next generation of workforce will need to embrace AI-augmented tools
About the speaker
About the host
I am a product person with 20+ years of experience most recently with DigitalOcean, Apple, Auth0 and now running Customer Identity at Okta. I love technical products and my sweet spot is B2B SaaS / IaaS. I have done a bit of everything including running engineering teams, corporate development and marketing and lived and worked in Canada, US and Brazil.