In the latest episode of Aviatrix’s “In Progress” podcast, Aviatrix CEO Doug Merritt and DoorDash Global Director of Engineering Security Nick Reva met to talk about:
Nick’s career journey from discovering egress filtering in high school to managing security engineers at SpaceX and DoorDash
The reality behind the “assume breach” mindset
What it means to be a security leader
What it will take to reach the essential default-deny enforcement that modern cloud security requires
Nick Reva’s Journey: From Burning CDs to Leading Security Engineers
Nick described his journey to becoming the Global Director of Engineering Security at DoorDash, starting with his explorations of the internet in high school. Exploring ways to access Napster to download music on the school computers led him to a fascination with networking and his first job as a network security technician.
Doug and Nick discussed how, despite revolutionary changes in the industry, certain realities about cyber have remained consistent. “From the day I learned what the OSI model is to today, the OSI model still stands,” Nick said. “We have the same seven layers.”
Nick described his journey from security analyst at Wrigley to consulting at PwC and becoming Head of Engineering at SpaceX. He described tackling significant challenges with a secure-by-design, shift-left approach. “I’m the classic blue team person and I really care a lot about hardening,” he said.
Nick identified threat modeling and practicality as his solutions to find ways to meet the government’s stringent compliance requirements. Doug highlighted the importance of that kind of practicality when facing security challenges – something many organizations do not understand when they demand that CISOs reduce vulnerabilities to a certain number before they can receive their yearly bonuses.
Nick described how he moved from SpaceX to become the 32nd security engineer at Snapchat. Eventually, he put his insights into a class on Udacity on Cloud Native Security Architecture and cowrote a book that will be released later this year, Securing Cloud-Native Apps.
Chokepoint Security vs. True Threat Containment
Nick described two of the major things he’s found useful in cloud security:
Guardrails - “You have to focus hard on guardrails, not gates, that are secure by default, in larger companies that enable developers to do their work without having to be security experts. And you need to design this into the security ecosystem by engineering it in.”
Incident response, detection engineering, and containment – "We have for many years as an industry said that we should assume breach. I think this should change. I think this should assume containment. Because containment comes after the breach. Without our ability to contain, we will not be able to stop the exfiltration.”
Doug and Nick compared the “assume breach” scenario to a home break-in: “Which one of your windows was cracked open?” Nick said. “You have to close that window back down.”
Doug and Nick discussed the real problem of how to think about containment in cloud and how larger organizations can implement some of these security practices – including organizations that may be slower-moving, decentralized, and reluctant to adopt new patterns. Nick discussed the importance of giving people “paved paths” that allow them to "do the right thing consistently.”
"This is why I strongly believe security is an engineering discipline,” he said. “Yes, it’s risk management, and we use our risk management lens . . . but the security teams who are strongest in our industry are those that have an engineering-first mentality.”
First Principles Reasoning: Breaking Problems into the Core “Whys”
Doug and Nick discussed how Nick has brought that engineering-focused discipline and change to the departments and teams he’s led. Nick shared that he was inspired by Elon Musk’s first principles reasoning, which breaks problems into core “whys.”
“What does it take to create something if you remove all the other facts of how humans have tried to do this before?” Nick asked. He gave the example of “why can’t cars be electric,” which breaks down to the cell battery packs and the necessary solution of smaller-formed cells.
The next step is teaching teams to think this way: what do we need to do to prevent bad things from getting into our infrastructure, and then catch the things we missed? “Every company can naturally be this way if they have an engineering-first mentality,” Nick said.
Detection, Remediation, and Containment: Advice for Fellow Security Leaders
Doug and Nick discussed practical places for CISOs and other security leaders to start, including:
Taking inventory and understanding your infrastructure from a network and resource perspective
Gaining observability over network traffic and logs from your topology so you can send those to a data integration source and establish a baseline for what is normal
From there, determining containment and constraining of traffic
Doug recommended asking one core question: “do I understand and have concrete proof of every egress?”
“It’s very simple,” Nick said. “If they don’t have control, they haven’t won. If they have control, they’ve won. We have to figure out how to not allow them to have control.”
Nick also clarified that this problem of cloud security is “not just tech people creating fanfare, “but a societal, existential risk problem.”
"These footholds and these egresses can shut down banks, water systems,” he said. “Just a couple of those affected for half a day is going to have dramatic effects on our economy.”
Ready to see Aviatrix in action?
Get a personalized live demo walkthrough or explore our latest deep-dive cloud threat research intelligence.
Gartner Strategic Roadmap for Zero Trust Security Programs 2025 Report
Download and gain actionable insights to advance your cloud security strategy.


















