This Week’s Pick by David B. Cross (CISO, Atlassian)
Why this episode matters
|
Copy paste takeaways for your team
|
Standout ideas discussed
- Title is not the goal – the challenge is. David took the Oracle CISO role not for the label but because it was a hard, interesting problem that matched his skills.
- CISOs must align deeply with the business. Understanding products, infrastructure and how the company makes money is non negotiable if you want your program to matter.
- AI will not replace tier one SOC – it will augment it. The real win is better triage, fewer false positives and faster reporting rather than full auto remediation on day one.
- Human in the loop is here to stay. David compares AI operations to modern aircraft: a lot can be automated but humans still authorize actions that carry serious risk.
- The worst advice: let AI write and ship all your code without human review. In David’s view the future is AI generated code with humans doing the hard validation and QA.
- The best advice: do not judge security from a distance. Get hands on with tools, code and systems before calling something secure or insecure.
- Portfolios beat buzzwords for new entrants. Blogs, GitHub projects and public writeups make it much easier for hiring managers to understand how someone thinks and works.
- Veterans bring battle tested habits into cyber. Integrity, attention to detail and comfort with playbooks under pressure translate directly into reliable security operations.
Try this in the next 7 days
- Security operations map: Draw a simple diagram of how security operations work in your company today. Mark who owns monitoring, detection, response, patching, vulnerability management and identity. Note any gaps or overlaps.
- AI in the SOC experiment: Pick one narrow use case – for example summarizing incidents or clustering alerts – and run a small AI assisted pilot with a human firmly in the approval loop.
- Leadership technical health check: Ask each manager in your security org to list one AI or automation topic they will learn in the next quarter and how it ties back to your roadmap.
- Portfolio challenge for juniors: Encourage early career team members and interns to publish one small project or blog post that they would be proud to show in a future interview.
- Veteran talent review: If your company hires in regions with strong military communities, talk to HR about making sure veteran candidates are considered for SOC, IR or operations roles.
About David B. Cross
David B. Cross is Chief Information Security Officer at Atlassian. Before Atlassian he held senior security leadership roles at Microsoft, Google and Oracle and began his career in US Navy aviation and electronic warfare. His work focuses on building engineering centric security programs, scaling security operations and helping the next generation of practitioners build meaningful careers.
Want your pick featured next?We are building a rotating slate of member recommendations from USA, Middle East and India. If you are a CISO or security leader, submit a link and 3 bullets on why it matters for other security teams. |
How we choose
|
Share this with your team

Comments