Home

AI · Application Security · Platform

Transforming Application Security Testing into AI-Driven Security Management

Reframing a mature AST platform around AI as a horizontal capability - connecting triage, remediation, developer workflows, and executive reporting.

Product strategyAI / LLMMCPEnterprise SaaS

Context & problem

From Application Security Testing to Application Security Management

The Application Security Testing market is shifting toward Application Security Management — covering not only detection of vulnerabilities, but also faster remediation, deeper integration with developer workflows, and stronger executive visibility.

At the same time, AI is rapidly becoming a core capability across enterprise software. The opportunity wasn't to add an isolated AI feature, but to use AI as a horizontal capability that addresses several long-standing problems in AST at once.

Talking to security and engineering teams, the same friction kept surfacing in different forms — four chronic gaps with one underlying shape:

  • Slow, expert-only triage. Hours per finding, bottlenecked on senior security engineers.

  • Delayed remediation cycles. Validation loops between security and dev that drag for weeks.

  • Limited developer integration. "Shift left" was promised, but rarely delivered inside the IDE.

  • Time-consuming executive reporting. Manual rollups for every stakeholder, every quarter.

Discovery & validation

Where the four gaps actually came from

The problem framing wasn't a top-down hypothesis — it was synthesized from recurring signals across customer-facing channels, then pressure-tested before any roadmap commitment.

  • Signal sources. Customer RFEs and backlog items were the primary input — clustered into the four chronic gaps above.

  • Discovery channels. Technical Advisors, Sales, Customer Success, design-partner conversations, and live customer conferences I led directly.

  • Validation. Stress-tested the framing with TAs, Sales, and CS before committing the roadmap.

  • De-risking. POCs with design partners validated the "AI as horizontal layer" bet before scaling investment.

Solution

AI as a platform capability, not a feature

We introduced AI as a layer that crosses the entire product — combining a context-aware chatbot embedded in the UI with an MCP-based ecosystem connecting the IDE, Jira, GitHub, and beyond. Instead of a chat box bolted onto the dashboard, AI became the connective tissue between detection, triage, remediation, and reporting.

ASoC findings (DAST + SAST) combine with code and developer tools as context for an IDE-embedded AI agent that proposes and applies fixes.

Three concrete use cases anchored the work:

  • Executive risk posture. Automated, organization-wide summaries tailored to each stakeholder.

  • Triage & prioritization. Faster vulnerability analysis, with context surfaced inline.

  • IDE remediation. Findings connect directly to code — fixes happen where the work lives.

Impact

Feature impact — and a new product narrative

80%
Reduction in triage time
via AI-assisted analysis
Days to Minutes
Remediation cycle
fixes drafted in the IDE
POC to Deal
Enterprise conversion
AI capabilities closed deals
4
Surfaces unified
Platform · AI · IDE · MCP
  • Converted POCs into enterprise deals.

  • Reduced triage time by up to 80% via AI-assisted analysis.

  • Cut remediation cycles significantly — fixes drafted in the IDE.

  • Unlocked new capabilities like cross-scan comparison and natural-language querying.

  • Strengthened AI-forward positioning with enterprise buyers and analysts.

How I led it

Owned the strategy, the metrics, and the narrative

What I owned

  • Product strategy & roadmap for the AI layer across all 4 surfaces.

  • Weekly re-prioritization as dev capabilities, legal, and federal requirements shifted underneath the work.

  • KPI definition and the metric / instrumentation spec — including the backend data structure for tracking — which is what made impact provable later.

  • Detailed design partnership — flows, data shape, and edge cases.

  • GTM narrative and execution. Co-led marketing blogs, videos, and conference talks that surfaced the AI capabilities to the market and reframed the product from "AST tool" to "AI security management system."

What I influenced

  • Technical architecture and model selection (with Engineering).

  • Licensing and token-cost models (with Licensing + Legal).

  • Federal compliance posture (with Federal PMs + Legal).

  • Cross-functional partners on this work: Engineering, Design, Security research, Legal, Licensing, Federal PMs, Technical Advisors, Sales, and Customer Success.

key decision

Every early decision balanced AI's potential against the operational constraints of an enterprise security platform. The principle: assistive, not autonomous — by design.

  • Retrieval over action. Keep enterprise trust intact by surfacing context, not taking destructive actions.

  • No autonomous ops in v1. Avoid running scans or modifying production state automatically.

  • Contextual intelligence over autonomy. Embed AI inside existing workflows rather than replacing them.

challenges

  • A weekly agile cadence — by necessity. Requirements re-adjusted every week because the LLM landscape, dev capabilities, legal posture, and federal requirements were all moving simultaneously.

  • Strategy and details, in parallel. Stayed deep in design reviews, backend data structures, and metric instrumentation while holding the cross-surface roadmap.

  • A Legal + Licensing + Federal track, in parallel with shipping. Orchestrating three regulated stakeholder groups around an AI product while it was actively being built.

What I learned as a PM

Lessons from leading an AI product through a moving substrate

  • Weekly re-prioritization is a muscle, not a fallback — when LLMs, legal, and dev tooling are all moving, the PM cadence has to match.

  • Owning the data layer early (metrics and schema) is what made the impact provable later.

  • Cross-surface products demand cross-functional choreography — the hardest work was aligning teams that don't usually plan together.

  • Narrative is a product deliverable — the "AST → AI security management" reframe unlocked deals as much as the features did.