Nate Lee: Building a GenAI Security App for Fun (and No Profit)

Nate Lee: Building a GenAI Security App for Fun (and No Profit)

Source: YouTube · SANS Cloud Security · published Dec 11, 2023 · 50:30

Cloud Security
No ratings yet Log in to rate
Transcript Available
Description

[BLUF] Nate Lee, CISO at Trade Shift, shares his journey from a non-tech background to leading cloud security, emphasizing the critical role of business acumen, strategic compliance negotiation, and practical AI integration in building effective security programs 0:30.

Key Takeaways:

  • Lee’s career highlights that business logic and operational skills are as vital as technical expertise for security leaders, allowing them to avoid ineffective, auditor-driven controls 0:50.
  • At Trade Shift, Lee evolved the security program alongside a shift from monolithic to microservices architecture, leveraging managed AWS services to focus on business differentiators rather than infrastructure management 1:30.
  • He advises tuning tools like SAST and CSPM to prevent alert fatigue, using bug bounties to make risks tangible for developers, and negotiating contracts by addressing underlying risks rather than blindly accepting legacy controls 1:45.
  • Lee built a Slack-based RAG bot to automate security questionnaire responses, demonstrating that CISOs must understand LLM architecture to assess data privacy and prompt injection risks effectively 2:30.

Closing Statement

This episode illustrates the CISO’s evolution into a strategic business partner who balances security rigor with developer productivity, leveraging emerging technologies like AI to enhance operational efficiency and trust.

Sources:

  • 0:30 Introduction of Nate Lee, CISO at Trade Shift.
  • 0:50 Lee's non-tech background and early interest in computing.
  • 1:30 Building security for mic

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cloud Security. Commonly maps to: Security Architecture and Engineering, Communication and Network Security. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

This is the Cloud Ace podcast, [music] bringing you the latest in cloud security through captivating chats with fascinating cyber security experts [music] who are leaving their mark on the industry. Cloud Ace is brought to you by the SANS Institute and hosted [music] by SANS fellow Frank Kim. And now, prepare for departure. We're cleared for takeoff. Here's your captain, Frank Kim. Hello and welcome to the SANS Cloud Ace podcast. I'm very excited to have on the show today Nate Lee who is the CISO at Trade Shift. Nate, thanks so much for joining us. >> Hey, thanks Frank. Glad to be here. >> All right. Well, hey, as we like to do, let's go ahead and start the show here with a little bit of personal history. So, Nate, can you tell us a little bit about your family, where you grew up, things l…