Matthew Marji, Security and Compliance at WorkOS
By Matthew Marji, Head of Security and Compliance at WorkOS
“Atliant has made a huge impact on the time to solution. We typically only need to review 2–3 vendors to make a decision, knowing that they’re already a good technical fit for the problem we’re trying to solve.”
Key Takeaways
- AI as a Security Game-Changer in 2026
- What's Missing in AI Security Conversations
- From Painful Searches to Targeted Matches on Atliant
- Bringing Socket Across Organizations
- ZeroPath's AI-First SAST Approach
Where are you based and what is your current role?
I'm based in Toronto, Canada. I'm currently at WorkOS, where I lead security and compliance. So that's both the security of our product end-to-end, as well as a lot of our customer trust.
We're about a month into 2026. What is most pressing for you and your team?
We had some ideas for what our initiatives were, but as we rolled into 2026, AI quickly became a game-changer. We are thinking about how AI is used within the organization, how AI is being used as an advantage for us to build out security tooling.
Is there something that you feel the industry is not talking about enough?
AI is quickly being integrated into all parts of an organization, even in our personal lives, and I don't hear enough of the industry talking about what are the security and compliance ramifications of this?
So if I'm a vendor, what should I do? Are there opportunities there?
Without a doubt. I think a large part that I ask vendors about is not only their AI strategy, but I ask about the guardrails around their AI. I really appreciate when vendors have a transparent view into their usage of AI.
Before Atliant, what was your process for finding and evaluating vendors?
Oof, yeah. If you followed Gartner, that's kind of the collection of vendors that I worked with. It was either vendors that I had heard acquaintances use, or ones that make it to these lists. And it was a really painful process.
“I found a lot of the times that I was doing these either word-of-mouth or just broad reviews of vendors. And it was a really painful process.”
You've been on Atliant for a while now, and you've been at different companies while you've been on Atliant.
Yes. It has allowed me to continue to use vendors that I found on Atliant that have been high-impact for me. It has made a huge impact on the time to solution. We're typically doing maybe two to three vendors that we review at a time.
“Atliant has made a huge impact on the time to solution. We typically only need to review 2-3 vendors to make a decision.”
Tell us about Socket.
Socket solves a really important problem. Everybody who's writing source code will pull in libraries of some sort. The problem is, when there is a security vulnerability in their code, how do we know? I've continued my relationship with Feross and the Socket team from that call all the way through to now.
Tell us about ZeroPath.
ZeroPath has absolutely blown my mind in terms of their AI-first way of thinking about SAST. They are chained and linked and connected, providing so much more value than a typical SAST.
“ZeroPath has absolutely blown my mind in terms of their AI-first way of thinking about SAST.”
If there is somebody in your shoes a few years ago, what advice would you give them?
Take the first step for learning. And that's really where I started. I feel pretty confident, from there, you'll quickly realize how integral the platform becomes to how you think about finding vendors and solving problems.
Keep reading
View allIt's Time to Rethink How Cybersecurity Solutions Are Discovered
Join the platform where security leaders and innovative vendors connect to shape the future of cybersecurity.