✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Assume Containment, Not Breach
Nick Reva's path to becoming Global Director of Engineering Security at DoorDash started with a high schooler's curiosity about getting around network restrictions to reach Napster — a rabbit hole that turned into a career spanning Wrigley, PwC, SpaceX, and Snapchat. Along the way, he went from analyst to becoming Snapchat's 32nd security hire, eventually turning what he learned into a Udacity course on cloud-native security and an upcoming book. In this episode, Nick and Doug dig into why "assume breach" might be the wrong mindset for the cloud era, what it actually takes to build guardrails developers will use without a fight, and how Elon Musk's first-principles thinking reshaped the way Nick leads security teams. It's a conversation about engineering discipline, practical risk management, and why a cracked-open window in your cloud environment might matter more than the breach itself.
Stay in the Loop
Get exclusive access to the latest conversations with cloud leaders, industry pioneers, and technology changemakers.
Subscribe and stay ahead of what's next.
Zero spam. Unsubscribe at any time.
The Speaker
Doug Merritt is Chairman, Chief Executive Officer, and President of Aviatrix. Most recently, Doug served as Splunk President and CEO from 2015 to 2021. During his tenure as CEO, Doug led the transformation of Splunk from an on premise, perpetual license software company with the equivalent of $220 million in Annual Recurring Revenue (ARR), to a cloud-based SaaS company with ARR of $3.12 billion. In his first year at Splunk, Doug served as the Senior Vice President of Splunk’s go-to-market functions including sales, marketing, support, business development, partners, and other customer facing functions.
The Guest
Nick is a security leader with 19 years of experience exclusively in Security Engineering, including 12 years at engineering-first companies including DoorDash, Snap and SpaceX, where technical rigor, velocity, and innovation are culture. He has built and led high-performing teams and delivered security outcomes that enabled the business.
What sets Nick apart is a blend of deep technical expertise, high EQ, and a business-first mindset. He brings clarity, empathy, and strong executive presence to every conversation, and he thrives in environments where security is viewed as a strategic technical differentiator—not a compliance checkbox.
Key Summary
- Why Nick argues the industry should shift from "assume breach" to "assume containment" — and what that changes about incident response
- The guardrails-not-gates philosophy that lets developers move fast without becoming security experts
- How Nick's team found a workable path through an "impossible" secure-SDLC mandate on SpaceX's Falcon codebase
- Applying Elon Musk's first-principles reasoning to break security problems down to their core "whys"
- Why Nick sees cloud security footholds as a societal and economic risk, not just a technical one
Never Miss
an Episode
Join thousands of cloud professionals following the stories, strategies, and hard-earned lessons from the architects driving enterprise transformation. Be the first to know when new episodes go live.
Zero spam. Unsubscribe at any time.
Join cloud engineers and modern architects already tuned in.
Keep exploring
Related Episodes

Chris Hughes: Not Prevention, But Resiliency
Doug Merritt · Chief Executive Officer
- CVEs are exploding — over 40,000 in 2025, with 2026 projections near 60,000 (some estimates up to 100,000) — while AI makes vulnerabilities easier to find and exploit. - Patching capacity has long lagged below 10% of the backlog; broken production risk and competing business priorities keep it there. - Security should shift from trying to prevent every incident to containing and recovering from the ones that happen. - "Human in the loop" doesn't scale against AI-driven attack volume — defenders need to fight AI with AI. - Security teams that act as collaborators, not blockers, avoid the shadow-IT workarounds that punitive policies create.

