In the latest episode of Aviatrix "In Progress," Aviatrix CEO Doug Merritt met with our CISO, John Qian, to discuss his unusual path from product engineer to security leader, the lessons he learned building Zoom’s security program during COVID, how AI is changing both offense and defense, and why patching alone won’t protect you if you haven’t thought about containment.
An Accidental Career in Security
John didn’t set out to become a CISO. He studied computer science, earned a master’s degree, and planned to spend his career building better products. When he joined Cisco, that’s exactly what he did, working on a multi-device security management product.
"It was mostly the large Fortune 500 companies using our product,” he explained. “And slowly I progressed from developer to managing the product."
The turning point came when customers started running penetration tests against Cisco’s own tools and finding security issues. As the product lead, John had to understand what they were finding and respond. He made an observation that still holds true: "One thing that might surprise you is a lot of developers who work on security products may actually not know security very well. They kind of know their piece, but exactly how the hacker is getting to the system is something actually pretty novel."
The more he learned, the more he wanted to keep going. He eventually transitioned from developer to full-time product security engineer.
At Cisco, John helped build a security culture across the company’s sprawling product portfolio. They started the Cisco Security Conference with about 100 attendees. By the time John left roughly nine years later, it drew 2,000 to 3,000 participants each year.
Building Zoom’s Security Program During the COVID Pandemic
After 20 years at Cisco, John felt it was time for a change. He was recruited to Zoom by a former colleague. He had no idea what was coming. He joined in June 2020, three months into the pandemic, with Zoom usage growing faster than anyone had planned for.
Zoom’s native client (not a browser app) delivered a better user experience, but that architecture also created a bigger attack surface. "We have all kinds of people evaluating our client, including kids from high school,” he said. “We got some of the best reports from high school kids."
When John arrived, Zoom’s security team was about 10 people. He led to lead the security architecture and later, the infrastructure team. Within two years, they grew the team to 300. One of the first things the company did was pause all development to fix security bugs, similar to what Microsoft did with its “Trustworthy Computing” initiative in the early 2000s.
John described the challenge as "building and flying at the same time", racing ahead of nation-state threat actors and defending Zoom from thousands of attacks per day. His team had to accomplish three things simultaneously: hire domain experts, adopt a maturity framework to assess and prioritize gaps, and turn pockets of success into company-wide operational processes.
Shift Left That Actually Works
Doug pushed John on a question the industry has debated for decades: if developers should own security, why do we still need separate security teams? John offered practical answers drawn from his experience at Cisco, Zoom, and now Aviatrix.
First, collaborate early. "Nobody really wants to get a surprise at the end,” he said. “So very early, the design stage. Make the security team feel like part of engineering." He suggested attending weekly design meetings as an example.
But showing up early only works if you show up prepared. John’s teams run quick risk assessments on all committed features for a release and identify the subset that warrants deeper engagement. For those, security architects join the design meetings from the start.
The second lever is automation and tooling baked into the CI/CD pipeline. John stressed that security tools need careful tuning before deployment, because false positives destroy credibility with development teams.
"Understand the development CI/CD pipeline, and then understand where you can inject into that process so it feels more natural versus something heavy-handed at the end," he said.
Using AI for Design Reviews and Code Scanning
John is using AI for both design reviews and code scanning at Aviatrix. For design reviews, the approach follows what a strong security architect would do manually: feed the AI the system architecture, the product requirements document, and security review guidelines, then let it analyze.
"It’s more comprehensive than a human,” he said. “It will identify a lot of different things across different areas. Even if you have really strong security architects, it’s very hard to think of everything."
He also noted that AI is useful for building proof-of-concept exploits to demonstrate vulnerabilities, which is time-consuming to do by hand.
The Case for Containment Over Patching
The conversation turned to the industry’s default response to vulnerabilities: scan, patch, repeat. John was direct about its limits.
"Traditionally, security teams are thinking about prevention and detection. When the numbers go down, it makes everybody feel good because the numbers are going down,” he said. “It’s less red and more green. But if any security team’s really honest with themselves, even today before AI, if you look in your environment, there’s a lot of vulnerable points,” he said.
With AI now able to discover vulnerability chains and generate exploit code, John argued the pace will only accelerate. Security teams, he said, need to assume breach and focus on limiting the damage. He pointed to supply chain attacks as a concrete example: "It’s not even a remote anonymous attacker trying to get into your cloud environment. It’s through supply chain. You’re deploying this vulnerable workload into your environment yourself."
John framed it as an extension of secure-by-default thinking. "Just like you have secure-by-default type of principles, think about containment by default. If you deploy something new into your cloud environment, what is the containment posture of that?"
Final Thoughts
John named one of the biggest myths in cybersecurity today: “patch all the CVs and you'll be okay.” He and Doug agreed on the growing problem of the vulnerability deficit, which means that patching on its own will never be enough.
Ready to see Aviatrix in action?
Get a personalized live demo walkthrough or explore our latest deep-dive cloud threat research intelligence.
Gartner Strategic Roadmap for Zero Trust Security Programs 2025 Report
Download and gain actionable insights to advance your cloud security strategy.




















