The Agentic SDLC: Why Most of Software Security Has to Change, with Jet Anderson (GEICO)
Jet Anderson · Distinguished Engineer at GEICO
Jet Anderson is a Distinguished Engineer at GEICO and leads the transformation of their product security function. He joins us to discuss the agentic SDLC and why most of what security teams do has to change while the first principles should stay the same.
We get into why static analysis and human triage no longer keep pace when models write the code, why we need new AI infrastructure, and why the Hugging Face sandbox escape was a decade-old Kubernetes misconfiguration found at machine speed.
Jet tells us the story of when he asked his own agent to "wrap this up" and it merged the PR and did an unauthorized production deploy. He walks through the pre-commit hooks and branch protections he built to prevent this from happening again so that deploys still get an approval gate and an audit trail.
He also explains why teams that skip ideation, design, and specification to go straight to code end up with less secure software the more they iterate, and why the unglamorous answer is doubling down on least privilege, egress control, and build containment.
Listen on