Joe Sullivan — Former CSO of Meta, Uber, and Cloudflare — Joins StackHawk Board as Security Teams Struggle to Keep Pace With AI Coding Velocity That Has Made Traditional AppSec Approaches Obsolete
With 87% of organisations already using AI coding assistants and code velocity rising up to 10x, static analysis tools flooding teams with untriageable alerts and legacy DAST too slow for modern CI/CD pipelines have left security professionals with more exploitable vulnerabilities reaching production than ever — Sullivan's conviction that dynamic, runtime testing in CI/CD is the only approach that makes sense in 2026 directly validates StackHawk's platform thesis.
4 min read
StackHawk, the company re-imagining application security for the AI era, has announced the addition of Joe Sullivan to its board of directors. Sullivan — who served as Chief Security Officer at Meta, Uber, and Cloudflare during critical periods of growth and regulatory scrutiny — is one of the most recognised security leaders in the technology industry. The appointment comes as StackHawk accelerates its go-to-market expansion, driven by customer demand for security testing that can match the velocity at which AI coding tools are generating applications — a velocity that has fundamentally outpaced the capabilities of traditional application security approaches.
The AI Coding Velocity Problem — Why Traditional AppSec Has Been Left Behind
The scale of AI adoption in software development is no longer a forward-looking prediction — it is the current reality. A recent StackHawk survey found that 87% of organisations have already adopted AI coding assistants such as GitHub Copilot, Cursor, and Claude Code, with code velocity increasing by up to 10x as a result. The security implications of this shift are compounding at the same speed. More code, generated faster, means more surface area for vulnerabilities — and the traditional security tools that were designed for a world of slower, human-paced development cannot operate at the speed, scale, or accuracy required to keep up.
Static application security testing (SAST) tools analyse source code for potential vulnerabilities, but at AI development velocity they produce an overwhelming volume of alerts — many of which are false positives — that security teams cannot triage fast enough to act on. The result is alert fatigue that causes genuine vulnerabilities to be missed. Legacy Dynamic Application Security Testing (DAST) tools, which test running applications from the outside as an attacker would, are effective in theory but in practice too slow and too rigid to integrate into the rapid CI/CD pipelines that AI-assisted development environments depend on. Together, these limitations leave a growing population of exploitable vulnerabilities and business logic flaws making their way into production environments, where they become the attack surface that adversaries exploit — often before security teams have finished processing the alert backlog from the week before.
"AI coding tools have created a complete paradigm shift in application security. They're generating applications faster than traditional security approaches were designed to handle, and simultaneously getting better at catching bugs in code itself. That means the job for security professionals shifts entirely to what happens when code runs. StackHawk is the only company I've seen that tests applications the way attackers exploit them: dynamically, in CI/CD, before production. That's the approach that makes sense in 2026."
— Joe Sullivan, Board Member, StackHawk
Why Runtime Testing in CI/CD Is the Only Approach That Works at AI Scale
Sullivan's framing of the strategic shift is precise and consequential: because AI coding assistants are already getting better at catching bugs in source code, the differentiated security work that humans and security platforms must focus on shifts to what happens when code actually runs. Static analysis is becoming increasingly commoditised as AI improves at the code-review task; dynamic, runtime testing — which tests applications in the way that real attackers exploit them, by interacting with running systems and discovering exploitable vulnerabilities through actual execution — is the category where the security gap is widening fastest and where the tools have historically been weakest in CI/CD integration.
StackHawk's AppSec Intelligence Platform combines shift-left runtime testing with complete attack surface discovery from source code, integrating directly into development workflows and providing context-aware remediations to developers — so that exploitable vulnerabilities are identified and fixed before they reach production, rather than discovered after deployment when the cost and risk of remediation are highest. The platform is already in use at organisations including British Airways, ITV, and Norstella. Sullivan joins as StackHawk also launches its Alliance & Reseller Program, bringing runtime testing to more security teams navigating AI-driven development across a broader partner ecosystem.
"Joe works with just a select few companies at a time, only joining when he clearly sees where the industry should head. His conviction in runtime testing validates what customers are telling us: they can't afford to wait until production to find exploitable vulnerabilities, and they can't triage the noise from traditional tools at AI development speed."
— Joni Klippert, CEO and Co-Founder, StackHawk
Sullivan's Career — Building Security at Meta, Uber, and Cloudflare During Their Most Critical Growth Periods
Sullivan brings more than two decades of security leadership to the board role. At Meta, he built the security programme during the company's rapid expansion from startup to global platform — a period when scale and attack surface were growing simultaneously at a pace that required building security infrastructure that could operate at internet scale. At Uber, he led security through intense regulatory scrutiny and organisational transformation, navigating one of the most demanding public security environments in recent technology industry history. At Cloudflare, he helped scale security for internet infrastructure protecting millions of websites worldwide, contributing to a platform that has become foundational to global internet security. His advisory portfolio includes Lakera, Pangea, SGNL, and Seraphic — all of which have had strong recent exits — further demonstrating the commercial judgement that underpins his sector reputation.
The combination of his background — building security at scale in three companies that faced fundamentally different threat profiles — and his selective approach to board involvement (described as working with only a select few companies at a time, joining only when he has clear conviction about the industry direction) makes the appointment a meaningful strategic signal for StackHawk's position in the evolving AppSec market. More information about the StackHawk AppSec Intelligence Platform is available at stackhawk.com.
Key Takeaways
- Joe Sullivan — former CSO of Meta, Uber, and Cloudflare, and one of the most respected security leaders in the technology industry — has joined StackHawk's board of directors as the AppSec platform accelerates go-to-market expansion driven by customer demand for security testing that can match AI coding velocity
- A recent StackHawk survey found 87% of organisations have already adopted AI coding assistants such as GitHub Copilot, Cursor, and Claude Code, pushing code velocity up to 10x — creating a compounding security gap as static analysis tools flood teams with untriageable alerts and legacy DAST solutions prove too slow and rigid for modern CI/CD pipelines, leaving more exploitable vulnerabilities reaching production environments
- Sullivan's core strategic insight — that AI's improving ability to catch code-level bugs means the security function must shift entirely to what happens at runtime, testing applications dynamically the way attackers actually exploit them — directly validates StackHawk's platform thesis and positions runtime testing in CI/CD as the only scalable approach that makes sense at AI development velocity in 2026
- StackHawk's AppSec Intelligence Platform combines shift-left runtime testing with attack surface discovery from source code, integrating into development workflows with context-aware remediations for developers — currently deployed by British Airways, ITV, and Norstella — with the Alliance & Reseller Program also launching to extend runtime testing reach across a broader partner ecosystem
- Sullivan's advisory track record — including Lakera, Pangea, SGNL, and Seraphic, all of which have had strong recent exits — and his reputation for engaging only selectively and only when he has clear industry conviction make his board appointment a commercially meaningful signal about where application security must go as AI development transforms the software delivery lifecycle
