Jake Aaron Villarreal: Once an adversary gets into a computer, within 23 seconds, they're breaking out. The average time, when you look at Gartner or Department of Homeland Security reports, is in the hours to days before adversaries are stopped.
I'm Jake Aaron Villarreal, born and raised in Silicon Valley. I'm here to take you behind the scenes to share what it's like to be a startup founder, the journey they're on, the problems they face, the products they build in an effort to make our lives better.
I'm excited to have with us today Curt Aubley, co-founder and CEO of Savvy. Curt, welcome to the show.
Curt Aubley: Hey, good day, Jake, and thanks for having me on.
Jake Aaron Villarreal: Well, excited to have you. I know we spoke a few weeks back and it's been on my mind ever since about what you're doing in technology and AI in particular and how you're helping really provide safeguards for many different organizations, people, and companies. And we'll dive into that, but a little bit more for the audience about Savvy — it's a cybersecurity company with decades of leadership across defense, enterprise, tech giants. Curt has served as CTO for cybersecurity at Lockheed Martin, CTO of Intel's Data Center Group, and held senior executive roles at CrowdStrike and Deloitte. He co-founded Savvy to reimagine security operations for the AI era. The company delivers the world's first level five autonomous defense and remediation platform powered by agentic AI cyber warriors that hunt, investigate, and remediate threats.
I'm excited to learn more about that, Curt. And before we do, give me a little background — where are you joining us from today?
Curt Aubley: Well, today I'm joining from Maryland, and I'm here visiting some of our government and commercial customers in the Washington D.C., Virginia, Maryland area — or what they call the National Capital Region.
Jake Aaron Villarreal: Really cool. Well, you've got a storied career really going back in the early days of cybersecurity and threats and whatnot. Give us a little background of you that kind of shaped you into where you're at today — experiences you've had, the technology experiences as well, and really the startup experience that you've really brought to the table to really start this company recently.
Curt Aubley: Well, great question. But, you know, the hardest thing I think I've ever done, and the most lucky, is I'm a dad of five daughters, and all my daughters surf. So that's always been a lot of fun.
But for me personally, I went from college to become an officer in the Army, and did my combat tours. When I got out of the military, I was fortunate enough to work for a former three-star general I had known in the military and become a CTO. We outsourced all of NASA's IT in these large outsourcing contracts with the government. You learn a lot when you do that, and I also learned that cyber wasn't really where I thought it should be.
So we got some funding — one of my co-founders, Arnie Schimo, and I, and the team, built out a cybersecurity company. We got some venture capital and we sold this to Lockheed Martin, actually, through an acquisition with Leidos Corporation, our primary investor. I was fortunate enough to work for Linda Gooden in the Lockheed Martin division that grew from 500 million to 9 billion, doing a wide range of cybersecurity — from offensive operations and defensive operations, managed security services, all kinds of technologies. That's when I first started learning how well nation-state actors, or adversaries, were attacking the United States or its allies.
Eventually, I decided, hey, I wanted to really always live in Silicon Valley. Fortunately, I got the position over as VP and CTO at Intel's Data Center Group — building foundational technologies and products for AI and data centers and cloud computing, hyperscalers. That was fantastic, but I was lucky enough to run into some old friends that we had done work with in the U.S. government, so I got to join CrowdStrike pre-IPO and post-IPO. Just an amazing team, led by that leadership team — George Kurtz, Mike Carpenter, and the crew.
I got to a point where I wanted to move back to operations, so, fortunately, I went over to Deloitte to lead up their Detect and Respond practice as a GM and CTO there, building out their five security operations centers, IR team, intel team — almost a thousand-person team. It's amazing — as we grew our business there, going from number 86 to number one MSSP.
But one thing was always common: as many great people as we bring onto the team, and great partnerships as we had with companies like CrowdStrike and AWS and Google and NVIDIA, we were never fast enough. Adversaries were still outgunning us. They always had more attacks than we had people, and we had a lot of people. That's why we started Savvy — how do we reimagine how we do security to give cyber defenders the advantage where they didn't have the advantage? And when you add in AI, it is becoming a much more complicated world. In fact, the amount of change we're seeing right now is the most I've ever seen in my entire career.
Jake Aaron Villarreal: Wow. Give us a snapshot for those that aren't in cybersecurity, that don't understand what it's like to have threats — what are you trying to defend? What are you tackling that is so challenging? Because we see so many organizations that are building up cybersecurity services and organizations trying to defend threats against them, but give us a little bit more of the backdrop and the landscape of really what's happening in the world today.
Curt Aubley: You know, in some ways it hasn't really changed too much. Back in the early 2000s, I was fortunate — or unfortunate — to be on the receiving team of nation-based attacks. Projects like — you can look it up on the web — Titan Rain, right? Where they identified a nation-state actor, the Chinese, that had compromised NASA and other government networks and stole intellectual property. There's a reason why certain technologies around the world — whether it's a space station or a space suit or a military airplane — look very similar to those developed in the United States, because that intellectual property was stolen.
Now, if we fast-forward to today's world — when you steal that intellectual property from a company, you can put that company out of business. A company maybe has 5,000 employees in Texas; all of a sudden those 5,000 employees don't have a job anymore. It impacts individuals. Or a water system or a power supply system has been compromised — suddenly the normal day-to-day way you work is being changed through cyberattacks. So we're at a point now where cyberattacks — especially with ransomware — are bringing down healthcare companies, bringing down hospitals. They literally affect everyday people, not just national security, but individual people.
Any chief information security officer, whether it's in the commercial world or government, has to manage risk and protect the assets they have out there — laptops, desktops, servers, cloud computing, our identities, and even more. So they buy a lot of tools, and they're important tools — you need them, like a CrowdStrike or a Cisco Splunk or some other technology. What happens is that creates work for your security teams, and there's never enough security team members.
So the problem we're focused on is — if you look at intelligence reports, once an adversary gets into a computer, within 23 seconds they're breaking out, taking action on some objectives, going lateral, starting ransomware. E-crime actors, 28 minutes. On average, you have around 15 minutes to detect, hunt, reverse-engineer, and stop an adversary. Well, guess what — the average time, when you look at Gartner or Department of Homeland Security reports, is in the hours to days before adversaries are stopped. Think about that — would you want a burglar in your house for hours, and to say, "Hey, I'll come back tomorrow, we'll see how it's going"? Of course not. So the longer they're in, the worse it gets — more work, more risk.
That's why Savvy developed our autonomous defense remediation platform. That creates agentic AI agents — we call them cyber warriors, since most of our company is former combat veterans — and those cyber warriors are able to stop an adversary at machine speed and scale, decoded in a few minutes, without the need for a human in the loop. And that is a very culturally changing way of thinking, because we're very used to keeping humans in the loop in security. So we built governance that puts you — the customers — in control, governance controls of when cyber warriors can be fully autonomous or partially autonomous. That whole thinking, that we need autonomous defense, is very different.
In fact, I'd say a year and a half ago, when we started the company, people were very professional with us when we went to get funding, but most people laughed at us. I'm kind of used to it, because if you think back, I've had the opportunity to work with amazing companies, and sometimes when you're inventing something new, not everybody is going to be on board with it right away.
Jake Aaron Villarreal: Right, yeah, 100%. That's amazing. So there is the technical aspect of it, but you also shared that sometimes it's not just about the technology — it's also about the leadership decisions. What do CEOs and boards still get wrong when it comes to cybersecurity and breaches?
Curt Aubley: Well, I'm not sure "wrong" is the right answer, but not all of them recognize the impact it can have for their business. Now, there's been changes in the dynamics of the security world, and a big one came when the U.S. Congress said, hey, if you're a public company and you have a material compromise — you've been breached — you're going to have to report that to the SEC. And to do that, then people have to bring in third-party incident response teams, third-party auditors, and such. It's a really big deal for a company to report to the SEC.
Suddenly, that, I believe, was one of the biggest wake-up calls we've seen in years. People said, "Wow, this isn't a security problem — this is a business problem. This is a CEO-level, board-level" — and, as a whole team, even if the chief information security officer leads up security, the CIO leads up information, every person is part of the security of your company. So I think those companies that are public and don't recognize that — when something goes wrong, if they haven't done their due diligence and fiduciary responsibility — will be held accountable. And that, in the last few years, has started changing that thinking. But companies that don't recognize that — I'm not sure if they've got it wrong, but they're accepting a lot more risk that could hurt their company.
Jake Aaron Villarreal: Yeah, makes sense. Like you shared, there are a lot of tools and technologies out there today that companies use to protect their organization. One of the questions a lot of times is: if you bring in a new technology or new tools, do I have to rip everything out and start fresh? Does your product overlay into what they already own and have, or how does that integration work?
Curt Aubley: You know, that's a great question, because we've seen over time there's been a change. About 10 years ago, a lot of the people in security leadership positions just didn't have security backgrounds, because, well, security didn't exist that long. So they had what we call the "salesperson of the week" architecture, where a salesperson brings you out to dinner, they buy something, they buy another tool, another tool — and suddenly we had 186 tools in a big customer's environment, right?
But as things have changed over time, you get people with more security experience and architecture experience. Now what we're seeing is people making really thoughtful decisions to maybe own several platforms, but not hundreds of tools — and they made good investments. That creates that tier of the architecture that creates work for the security team. So we didn't want to replace those tools, because they're good tools, they're great partners out there.
So we've created this autonomous, contextual execution and control plane of artificial intelligence that allows us to create that control plane across the tools the customers already invested in. We provide the agentic AI governance, the reasoning, agentic AI agent coordination if we need to, and AI actions. So we're the autonomous execution tier, where our agentic cyber warriors become an extension of a customer's team, and they work for the customer. That's a new concept — that these agentic AI agents are now becoming part of your team, and you get to control what they do for you. So they're not creating work, they're doing the work — think of them as trained expert professionals that you're giving guidance to, and they're doing the work at a speed and scale that's mathematically not possible by humans alone.
Jake Aaron Villarreal: I mean, I think that's amazing. When you think about AI, I know that there's a lot of AI tools that are being developed for threats and to get through systems, but it almost seems like you're developing maybe a better AI that's helping defend against other AI systems. Is that accurate?
Curt Aubley: It is. Now, whether you're "better" or not — that's always interesting, and how do you benchmark? We benchmark by managing risk, but more importantly, the cyber outcome is: can we stop the adversary faster than they can get into your environment and cause havoc? This cyber performance concept, I think, is becoming more emergent, because any good thing can be used for bad things. A car can be used for getting where you need to go, or it could be driven into, unfortunately, a crowd of people, right? That car can be used for good or bad. Well, AI is the same way, and adversaries have a lower risk tolerance — they'll adopt AI faster to create complex attacks, more attacks, lower the bar of entry.
Now, what we've seen is, with Anthropic, which has very public papers on this — they created technologies where you can use this to review your applications you've developed, your operating systems, and look for vulnerabilities faster and more in-depth than ever before. Guess what happens when that happens? You're condensing the time from vulnerability to creating an exploit to launching that. So now, with AI-powered attacks, what you're seeing is a lot more speed to attack, increase in scale, but also brand-new — you can call them zero-days, you can call them a lot of different things — brand-new vulnerabilities, exploits, very quickly. And now that pushes more pressure on teams to actually take a known vulnerability and get a new patch out, or another mitigation in place, before they're compromised by these larger groups.
Jake Aaron Villarreal: Yeah. You know, you said earlier that you're up in, I think, the Washington area with customers and clients, and maybe some meetings there — who is your ideal customer? When you're building, is it for the big enterprise organizations? Is it for really any company that's got products or systems they want to protect? Where's your main focus today?
Curt Aubley: So we designed our platform for scale. So our ideal customer is a large enterprise or a large government entity, because those are some of the most challenging environments to work in. It has to be easy to use, easy to deploy and operate. We typically take an hour to plan and an hour to deploy, and within a week we're operational. We don't want to be shelfware — we want people to really, really use the product. We just want to make that easy, but it has to scale, and consistently provide the cyber outcomes in larger environments.
Like today, our largest environment is around 2.5 million assets under cyber protection as part of the customer's team. Now that we've been able to move to that scale and larger, we can now come down to smaller businesses — but even then, usually it's a customer that has around 1,000 assets to protect, laptops, desktops, maybe identities, cloud computing, because they tend to have the real priority of — we see how important business is, and how important risk management, how important security is. So anywhere from a 1,000-person company up through the largest companies in the world really falls into our ideal customer space. In the future, will we go farther down market so we can help a broader set of people? When we're a larger company, we will be doing that. But for the near future, we're really focused on that enterprise customer.
Jake Aaron Villarreal: Yeah, makes sense. Well, in those organizations, you've got lots of employees and multiple leaders — who inside that company first understands the value you're bringing to the organization and what you're building?
Curt Aubley: You know, everybody — each stakeholder has a different point of view, a different lens they're looking through it with. If you're a chief information security officer, CIO, or a vice president — some senior leadership position — you recognize risk management is important. They're looking at their cyber performance. They're going, "Hey, we know, from a cybersecurity intelligence standpoint, how fast adversaries are moving — how fast can we move today?" Right? Unfortunately, we're seeing a lot of large companies saying, with AI, they're cutting the number of people. Well, if your team is maybe at the same size or has to get a little smaller, how are you handling — according to Gartner — an 87% increase in the number of attacks? I've talked to 120 CISOs in the last five months. No one I know is getting 87% more budget. So they've got the same-size team, maybe a little smaller — how are you going to handle an 87% increase in attacks? That's pretty hard, right?
So that's the first — leadership stakeholders. But we want the people that actually use the technology to really see value. So, to us, the SOC manager, the SOC operator — that SOC operator is the most important part, because they're the defenders for their company or their government group, doing their mission. They see value in our product, they share that with their SOC managers, and then we can quantify that with cyber ROI dashboards for both cyber performance and TCO savings, so that the executive has that visibility, but they're really empowering and supporting their teams.
Jake Aaron Villarreal: Yeah, makes sense. You know, we work with hundreds and hundreds of companies, startups that are building, and a lot of them now are building in AI. And what we're finding, and what we're hearing, is a lot of the organizations' number-one issue today is rising above the noise so that their product can be heard, and companies know what they do and what they solve, and their go-to-market teams — that motion of getting in front of companies, in front of the right prospects, and actually getting traction. For you, talk a little bit about that — what's working for you in terms of go-to-market? Sounds like you've got great enterprise companies. Sometimes it's who you know, because you've been in the industry a long time. Other times it's you've got a really good strategy that's helping get doors opened. What's working for you?
Curt Aubley: So I think, first, it's having a compelling product that very clearly solves a problem and has measurable outcomes. So even if you have contacts in the industry, if you can't cover that basics, it's hard to get traction in the market. We also made a little bit of a different decision, because we're using AI to develop our products — we made that decision very early on. And that allowed us — I have my Savvy shirt on today — we're 100% American made. We design in America, we manufacture in America — manufacture software — and we support in America.
You know, that's interesting, because there are wonderful people around the world, and all kinds of different VCs and groups, but since some of the work we do, we focus on government customers and others, security of their supply chain becomes important. So just fundamentally having a mission that says we're here to help the cyber good defeat cyber evil, and we happen to be an American cybersecurity startup — that actually opens a lot of doors for us. It's quite wonderful.
We started — we are four co-founders: Arnie Schimo, Seeman Hollins, Caleb Cross — Arnie and I probably have a little more silver hair, as my kids would call it, not gray, silver hair, than some of the others. So we do have some friends in the industry, and it was very nice that some of them gave us some opportunities to go in, and because of the fantastic work of my CTO, Steven, and my chief design officer, Caleb, and my CSO, Arnie, we were able to go in and show how easy it was to deploy, and they're getting compelling results. That enabled us to start building these references, and now we can work toward bringing on a direct sales team to help our partners. We're a partner-first organization — we have partnerships on the technology side with CrowdStrike, AWS, NVIDIA, and they were nice enough to put us in the top 35 cyber companies in the world. Just an amazing team — I don't even know how they picked us, there were some super awesome groups in there, right? But that helps with marketing, right — to get that credibility.
Also, we've worked with some very large resellers — some of our partners, like Consortium Networks and Digital Air Group out of Miami. Those groups — because we're a partner-first-led organization from a sales perspective — help us get to those customers that we wouldn't have been able to reach by ourselves. And, of course, a little social media along the way absolutely helps.
Jake Aaron Villarreal: Yeah. Let's talk about people. A company and an idea is great, but it's nothing really without the innovation and the people behind it. You've got four co-founders, yourself included — how big is the team today?
Curt Aubley: So, as the CEO of a startup, typically I answer that question by saying our largest customer has over two and a half million assets under protection. We have multiple investors — our most recent investor was BMW. So we're the right-size company to do cybersecurity products to help our customers, because we are well funded.
But it used to be a really big deal to say how big your customer was, how big your team was. I'll give you an example — at Deloitte, I had almost a thousand people on my team, very lucky, amazing team, by the way, across the United States and Hyderabad, India, for the most part — just amazing teams in both locations. But I think in the world of startups now, your capital efficiency, your human efficiency, becomes more important than ever before, because we're all AI-enabled. So when I look at the full-size team, we're sitting around 30 people on the team. But we don't want to grow too fast, because we have the ability to use technologies that help us code, help us look for vulnerabilities, help us test everything on our own cyber range for offensive and defensive operations. So AI is a very powerful enabler that doesn't really require having a team of, you know, 300 people in the U.S., 700 people in India, 600 people in Romania, and all these other wonderful countries which you love to visit — but you don't need those big teams anymore.
Jake Aaron Villarreal: Yeah. Well, we're seeing that across the board — you're hearing about the one-person billion-dollar company, and the two-person $500 million company, and it's all around AI helping support that. But you have hired a lot of people — talk about what's worked for you. There are a lot of founders out there that are on our show, that listen to our show, and one of the struggles for a first-time founder is: how do I identify the right type of person for my company? How do I go about making sure it's the right person, the choice I make? And how do you filter through the noise when it comes to trying to bring in the right people to help scale your organization?
Curt Aubley: You know, it's always a challenge to find the right person for the right team. Say there's a superstar professional basketball player — if the team they're on, they absolutely are killing it because it's the right team. But you take that superstar and put them on a different NBA team, and the chemistry isn't right, and suddenly they're still an amazing player, but they're not getting those results, because you don't have that culture, that chemistry, in a team.
So for us — we're again very fortunate, we've been in this industry quite a bit. Going with a startup is risky, so you have to have that right appetite for risk and understand you're probably not going to sleep for the next three years. So if you're going to accept that — and there's a reward with stock and equity and things of that nature — we do try to bring team members on and have a number of people interview them and just see if they like them. Is this someone you're going to work with, because you're probably going to spend 40, 50, 60, 70, 80 hours a week with them? Do they have the culture to work with you? Then, of course, do they have the technology skill sets — not just something available today, but in our AI world, you've got to constantly learn, right? And I think this is a differentiator for our company — we're not just product people going, "Yay, we went from one company to a startup and sold it to the next startup to the next startup." We're operators. We're focused on our customers' mission. That's just slightly different, and so we want a culture where they understand — we're obsessed with our customers and their customers' mission, and what we build has to work. It's not an option not to work, because real adversaries are coming in, causing real problems. Selling something that doesn't work just isn't acceptable, right? So you have to have that mission mindset.
So we do recruit a lot straight out of universities. We have a larger engineering team out of North Carolina. We have engineers in California, Texas, Florida, other locations. We also hire a lot of former military — I would say almost 40% of our team have done some type of cyber operations in the military, where they learned their foundation of cybersecurity, whether it's naval special warfare, Army Cyber Command, signal officers, or intelligence, or master chief doing the electronics for electronic warfare. They all have this broader cyber background, and we find having that right mix has been just marvelous. So, always putting a little vote out there — if you haven't tried hiring some veterans that have that experience, give them a try, because they're going to bring a whole new level of skill that you may or may not have been familiar with if you've only worked in the commercial world.
Jake Aaron Villarreal: Yeah. Well, that's great. I had a conversation with the founder of Black Rifle Coffee, and a lot — I wouldn't say all, but a lot — of the employees are veterans, and that's one of the missions behind their organization. Yeah, it's a great product, it's a great company — I think they're public now, and they're doing great. But in terms of challenges — you're in a space that's crowded, but it sounds like you've got something a little bit more unique. What are some of the areas of challenge that you have overcome that you can share with others? You know, everyone goes through ups and downs, but talk about a challenge in the company as you started, and maybe a pivot or something that was a great learning for you.
Curt Aubley: So I think one of our great learnings is not just focusing on the customer, but understanding the threat. The threats are changing so much right now, so fast — learning about the threat, and learning that data, and learning about where the customers are, becomes super important in developing a product. And that was a big learning — that even just two years ago, Arnie and I were working in operations, and it's already changed in two years. So the ability to adapt your product to how the world is moving is absolutely critical.
Now, we're pretty steadfast on our vision to have the ability to help cyber good defeat cyber evil. But when we look at the technologies — one of the big things we added, we started with a layer of AI governance, because we wanted to build trust with the customer. We thought that by showing the risk metrics and showing the speed and scale, we would move everybody to autonomous cyber really quickly. Well, it's taken a while. So the biggest thing, I think, we've overcome now is really making things very, very interactive, making sure the human-in-the-loop interaction is a fantastic experience, and putting additional layers of governance into our product so that people can feel comfortable.
It can be kind of scary — I've had videos sent to me randomly, like from the Terminator, and it's like, "So, what are you guys building?" Well, no, no, we're the good guys. And I think that adding that governance and pivoting with great user experience, as well as the autonomous AI capability — that's probably one of the biggest challenges. We designed it into the platform, but we didn't understand how important it is. But since we designed it in from day one, we're able to add the additional layers that really make people feel more comfortable, because — think about it — we're just sitting here together, right? You see me, I see you, I'm pretty sure you're not a deepfake, I know I'm not a deepfake today. But just imagine, over my shoulder, I have 15 more people working for me right now, watching all the security for my company — in our case, other companies. That's a different world. We've got to use a little imagination with that, right? So how do we make sure these agents, our cyber warriors, aren't going rogue? So we put those governance controls in place, much deeper than I expected to need to in the market.
Jake Aaron Villarreal: Yeah, that makes a lot of sense. Well, I like what you're creating — it's always good to have security around what you're building, and hopefully no one breaks your barriers to get into your data, or whatever it is you're trying to protect. What's on the roadmap as you look forward? We're halfway through 2026 — what are you excited about?
Curt Aubley: Literally, I just — I wake up excited every day. I think that — I got some healthy kids, we can figure anything else out, right? From our company perspective, the first thing that gets me excited is the market traction. The amount of customers that have been reaching out to us has been just beyond my expectations, and we just get so jazzed up from working with customers. We look at every customer as a design partner — we want their feedback, and we're able to adapt with what I refer to as "style, smile, and speed," right? Just because we love doing it.
The technologies we see right now — a lot of it's education, that this is now possible, to bring autonomous execution to the market. And it's just maybe good luck, because we didn't start this, but things like dark AI threats you read about, technologies being used for really good things as well as some evil things along the journey, kind of work right into our space. So our vision is that anything that computes will be protected, by asset and by asset ID. Now, where we are today, we're protecting endpoints — your laptop, desktop, servers. We're protecting identities — those are the areas where we're getting the immediate traction. We've added cloud security. As we go forward, I expect to start protecting more critical assets in the IoT and ICS space. And then, eventually, I could see us in a couple of years even protecting that robot that might be in your house, helping you do whatever you want them to do at the house — yard work, or making lunch, whatever they're going to be doing for you — and making sure they're not going rogue, right, or being compromised by a third party. So that might be more than a few months away, but anything that computes, we see will need protection.
Jake Aaron Villarreal: I like that. Well, as you say that — there is a company CEO that lives about two blocks from me, up the hill here, and he has a company called Luxonis, which does computer vision for a lot of autonomous products, and in-home robots are coming sooner rather than later. And that is absolutely something that I think is probably 24 months away, and that's the reality. So, yeah, to have some security around that, to make sure it doesn't go rogue and doesn't do anything you don't want it to do in the house — I think that could have a real application. Not as maybe interesting as robots, but when you look across the size of the data centers being built across the world right now — especially in the United States, China, Europe, all kinds of places — these places are massive.
Curt Aubley: When I was Intel CTO for DCG, we got to work on supercomputers around the world, which I thought were big at the time — 50,000 nodes, you needed a 20-megawatt nuclear reactor from a submarine to power a data center. Now you need like 10 of them, right? That's another area that we're expanding into, because when you have hundreds of thousands, or millions, of computers to protect, doing it manually is just not possible anymore.
Jake Aaron Villarreal: Yeah, I like where you're headed with this. You know, I always like to leave a little space at the end of the show to talk about the growth of the company and roles that you might want to fill, or functions you want to bring into the company. So go ahead and talk about anything that you feel like you need. I know it's — in this world, in today's market, it's keeping it tight and keeping the employees small while scaling the business — but if there are any roles that are on the horizon you want to talk about, feel free to share that now.
Curt Aubley: Always looking for outstanding folks. I think one of the things — if you ever caught any Jensen Huang keynotes, they're amazing, anybody out there wants to know what's going on in the future, he delivers well, his team does a fantastic job — but one of the things I like is very flat organizations, you just really work as a team. For us, hiring managers really isn't on the horizon — everybody, including myself, is an individual contributor. I'll do anything needed to support the team. Yeah, you probably don't want me cutting code, but I do, once in a while, and my CTO, Steven, just laughs at me, and Alex just laughs at me a little bit. But we need something architected, you need some legal stuff done — whatever's needed, I'm here to support the team.
But, at the same time, we will be expanding our engineering core. And it's not as much computer science or software developers as much as software engineers and product management, because we're defining what we're building, and then AI's helping us build it. Cyber range operators — people that know offense and defense of cyber, as we bring our cyber warriors and train them and test them in real-life scenarios, so that when they do get deployed to customer sites, they're very well engaged. I think the other area, as we've moved into the U.S. government space — as we're deployed in AWS's GovCloud now — is those cyber engineers and software engineers that are very familiar with the government space, we'll be adding additional resources there. And we will be adding direct sales to work with our partners.
So, in a nutshell, those are the main areas: engineering, cyber range operators, direct sales. Those are really the three major areas that we're adding to scale up. But, actually, I've almost forgotten that Chris is going to give me a little trouble after this — Chris Payne, I get to work with him at Deloitte, fantastic special warfare officer, and he leads my VP of Forward Deployed Cyber Engineers. We're growing that, because that agentic control plane and execution plane that goes across the customer's security tools — we're extending that to every technology application the customer uses — and my forward deployed cyber engineers are helping customers with use cases that go beyond the silo of security tools, into systems management, HR, travel, supply chain, and they're really helping tailor our platform to the true context of each customer. So yes, we're hiring forward deployed cyber engineers, and that's actually something I learned back in my Lockheed Martin days — that when we build something, we've got to go to the field sometimes and actually help real operators make sure the new technologies were executing to support the mission. It feels like a blast from the past to bring on a forward deployed engineer, but I guess now it's actually popular to have a forward deployed cyber engineer. So that is the fourth area that we are hiring for as well.
Jake Aaron Villarreal: Yeah, really cool. Yeah, from Palantir all the way through, we're seeing a lot of organizations that are hiring forward deployed engineers. In fact, it's one of the higher-demand roles, and it's really valuable — not just for you having boots on the ground in a company, but also feedback, closing the loop on how you can make your products better and your features better. Overall, it's almost like a design partner insight, where you're getting that intel when building.
Curt Aubley: Like product managers — which are more like hands-on product folks — but there's nothing better than having someone who's working with operations on a day-to-day basis, helping extend the use cases that really add that context. That feedback loop is priceless.
Jake Aaron Villarreal: Yeah. Well, sounds like you're on a really good track, Curt. I'm excited about what you're building. If anybody wants to find you or find Savvy, where do they go?
Curt Aubley: Well, we try to make it easy. We do have a nice website — we're security people, so we're always paranoid that we don't want to share too much from our marketing department. We probably should make it even nicer, but our director of product marketing, Emma, is doing exactly the philosophy of the company — not too much, just enough. I think the easiest way to get a hold of myself and others in the company is just get on LinkedIn — we check it every day. Hit me on a DM and just say hi, what you're looking for — maybe I can point you in the right direction, maybe we can help you. We do get — 99% of those are sales, sometimes we buy through there, it's pretty rare. But if you want to get in contact with us, you can send a note through our website or LinkedIn, just hit us directly in DM. That's really probably the easiest way.
Jake Aaron Villarreal: Really cool. Well, Curt, I'm excited to see what the future holds for Savvy and yourself in the future. It'd be great to have you come back in 6 to 12 months and see the progress you've had. Thanks for coming on and sharing your story today, and thanks to the listeners for listening — means a lot to me that you spent your time with us today. My name is Jake Aaron Villarreal, your host, signing off for now, but can't wait to catch up with you all in the next episode. Until then, Curt, the world — take care.
If you like what we're doing, don't forget to subscribe. Leave a review on Apple Podcasts or wherever you listen, and follow us on YouTube, where we go behind the scenes to learn what it takes to be a startup founder.