Developer tools
10 CISOs in developer tools
These chief information security officers lead or have led security at companies that build products for software developers, including Docker, GitHub, GitLab, Snyk and Semgrep. A reader can learn from them how to build a security program when the customers are themselves software developers.
Professionals to explore
01—10Aaron Kiemele
LinkedInExperience: Chief Information Security Officer · Perforce Software
Chief Information Security Officer at Perforce Software since September 2024; the profile describes Perforce as providing enterprise-scale development tools, including version control, application lifecycle management and agile planning. Former Chief Information Security Officer (CISO) at Jamf (2018–2024), Director of Information Security and Compliance at KrolLDiscovery (2016–2018) and Deputy CISO at Ontrack (2012–2016).
Alexis Wales
LinkedInExperience: Chief Information Security Officer · GitHub
Chief Information Security Officer at GitHub since August 2024; the profile describes GitHub as an AI-powered developer platform that builds and ships software on a single, collaborative platform. Former Deputy Chief Security Officer (2024), Vice President, Security Ops (2022–2024) and Senior Director, CSIRT (2022) at GitHub, and Associate Director, Threat Hunting at the Cybersecurity and Infrastructure Security Agency (2021–2022).
Brian Campbell, MS, MBA, JD
LinkedInExperience: Chief Information Security Officer · Snyk
Chief Information Security Officer at Snyk since August 2024; the profile describes Snyk as a developer-first platform for securing code, dependencies, containers, IaC and cloud deployments, and lists AI security, cloud security and application security. Former VP, Cyber Security Architect at Veeam Software (2020–2024) and Chief Information Security Officer at Magellan Health (2018–2020); also Adjunct Professor at The Ohio State University since 2021.
James Kirk
LinkedInExperience: Chief Information Security Officer · Jellyfish
Chief Information Security Officer at Jellyfish since December 2025, following Head Of Security and Privacy there (2022–2025); the profile describes Jellyfish as a software engineering intelligence platform that helps engineers build AI-integrated engineering teams. Former Senior Director, Information Security (2020–2022) and Director Information Security (2017–2020) at Datadog; Advisory Board Member at QuilrAI since 2025.
Jonathan Werrett
LinkedInExperience: CISO · Semgrep
CISO at Semgrep since April 2026, following Head Of Security (2022–2026) and Advisor (2020–2022) there; the profile describes Semgrep as an extensible, developer-friendly application security platform that scans source code with AI-assisted SAST, SCA and Secrets Detection. Former Head of Security (Fitbit) at Google (2021–2022) and Head of Information Security at Fitbit (2018–2021).
Josh Lemos
LinkedInExperience: CISO · GitLab
Former CISO at GitLab (2023–2026); the profile describes GitLab as a comprehensive AI-powered DevSecOps platform that helps automate software delivery. Board Member at HiddenLayer and at GitLab Federal (2023–2026), and former Chief Information Security Officer (CISO) at Square (2020–2023). Chief Information Security Officer at lululemon since April 2026.
Mark Dorsi
LinkedInExperience: CISO · Netlify
CISO at Netlify since February 2022; the profile describes Netlify as a platform that allows users to create with AI or code and deploy instantly on production infrastructure. Former Head of Security at HelloSign a Dropbox Company (2019–2021) and at HelloSign (2018–2019), Head of Security and Technology at Cloud Lending Solutions (2017–2018) and Director Infrastructure and Security at Qualys (2011–2017).
Mark Lechner
LinkedInExperience: Chief Information Security Officer · Docker, Inc
Chief Information Security Officer at Docker, Inc since October 2025; the profile describes Docker as a platform designed to help developers build, share and run container applications. Former Chief Information Security Officer at Otera (2025), Chief Information Officer (2024–2025) and VP TechOps, CISO (2021–2024) at Bitpanda, and Head of Cyber Security at Solaris SE (2020–2021).
Quincy Castro
LinkedInExperience: Chief Information Security Officer · Chainguard
Chief Information Security Officer at Chainguard since July 2025; the profile describes Chainguard as providing trusted open source artifacts for every layer of the modern software stack, including containers, language libraries and VM images. Former Chief Information Security Officer at Redis (2021–2025); Advisor at KindWorks.AI since 2022 and Investor at SVCI - Silicon Valley CISO Investments (2023–2026).
Riaz Lakhani
LinkedInExperience: Chief Information Security Officer · Redis
Chief Information Security Officer at Redis since September 2025; the profile describes Redis as a real-time data platform that offers a range of products and services for developers. Former Chief Information Security Officer at Barracuda (2022–2025); Advisor at Veza since 2021, Investor at Mercury since 2021 and Member of the Information Security Leadership Foundation since 2021.
Choose the right perspective
Match the person's company to the kind of product you build, since securing a code hosting platform differs from securing an application security scanner or a container platform. For supply chain and open source questions, favor someone at a company whose product centers on code, dependencies or containers; for enterprise trust and compliance questions, favor someone with a long security leadership path.
Questions to take into the conversation
- 01How do you secure the build and release pipeline for a product that developers install and run in their own environments?
- 02How do you handle vulnerability disclosure and the risk from open source dependencies in a developer product?
- 03What do enterprise customers ask about most in security reviews of developer tools, and how did you prepare for it?
Reaching CISOs in developer tools
How can I contact one of these CISOs in developer tools?
Pick one of the 10 people on this page and choose "Book a paid call", or describe your project to find others. You offer a fee for a 15-minute call or a written answer, Instant Expert finds the person's work email and sends the invitation, and they decide whether to accept. The list covers 10 companies, including Perforce Software, GitHub and Snyk, based on profile data retrieved on October 3, 2026. Being listed here doesn't mean someone has agreed to take calls.
How much does it cost to reach CISOs in developer tools?
You choose the offer, starting at $5 per person. It includes Instant Expert's 20% fee, so an offer that pays the person $100 costs you $125. You're charged only when the person books the call or sends the answer.
What if they don't reply?
You pay nothing. Instant Expert sends follow-up reminders, and if the person hasn't booked or answered within 7 days, the request expires and any hold on your card is released. You can invite several of the 10 people on this list at once and cap your total spend, so you pay only for the ones who accept.
About this directory
This is a professional research starting point based on business profile data retrieved on . Titles and companies reflect that source snapshot and may describe past or present roles. Check the linked profiles for current details. Inclusion does not imply Instant Expert membership or availability.
Request a correction or removal