CIO Influence
Automation CIO Influence Interviews IT and DevOps Machine Learning Networking Security

CIO Influence Interview with Aravind Venkataraman, VP of Technology at UltraViolet Cyber

CIO Influence Interview with Aravind Venkataraman, VP of Technology at UltraViolet Cyber

Aravind Venkataraman, VP of Technology at UltraViolet Cyber talks about the impact of AI on application security and what security teams needs to focus on as protocols are reshaped due to latest advances:

_________

Hi Aravind! Take us through your journey in tech?

I’ve spent my entire career in cybersecurity. My Master’s was in network security; I came into the industry in 2007, and by 2009 I had pivoted into application security. I’ve stayed in AppSec ever since — joining Cigital in 2009, which became part of Synopsys, then was carved out as Black Duck, and now UltraViolet Cyber. Through the mergers, carve-outs, and rebrands, the work has remained the same throughline: helping serious security programs find, understand, and remediate the vulnerabilities in their applications that actually matter.

I started as a hands-on practitioner doing pentests and threat models, then moved into running projects and territories, and eventually leading technology practices and engineering initiatives. Today, as VP of Technology & Practices at UltraViolet Cyber, I oversee our technology, service offerings, and automation-and-AI strategy across the offensive security portfolio.

What’s kept me in this space for nearly two decades is the asymmetry. Defenders have to be right everywhere; attackers only have to be right once. And the people inside an organization who own that problem rarely have the headcount, the institutional memory, or the tools to keep up. That gap is where the work happens. The work is harder now than it was when I started — and it is also more interesting.

What about application security testing needs to be fixed in the ecosystem?

Application security testing is stuck between two models that don’t work in isolation. First-wave autonomous AI scanners fire requests without context — they generate volume but not fidelity, and any experienced practitioner recognizes the output as noise within minutes. Manual-only testing remains the gold standard for depth, but it is rate-limited by human hours. Growing application portfolios, tighter delivery windows, and a constrained pool of senior practitioner talent mean coverage gaps are inevitable.

What needs fixing is the framing itself. The choice is not between human expertise and AI. It is between testing programs that combine both into a single, integrated architecture — and testing programs that don’t.

The architecture that works is human-led and AI-augmented. AI handles the cognitive scaffolding — attack surface mapping, threat modeling, test plan generation, parallel execution across vulnerability classes. The practitioner focuses on what no automated system can do alone — judging business logic flaws, navigating trust boundaries, chaining evidence into defensible findings. Every dismissal teaches the system; every confirmed finding compounds the institutional memory. The whole thing gets sharper with use. Most of the market today is selling tools that don’t.

Also Read: CIO Influence Interview with John Elliott, Cybersecurity Author Fellow at Pluralsight

Tell us about Solstice and its core features?

Solstice is UltraViolet Cyber’s AI-augmented offensive security platform — the umbrella under which our entire penetration testing portfolio now operates. It is not a product we sell off the shelf. It is how UltraViolet now delivers. Solstice was built by UltraViolet practitioners for UltraViolet practitioners, and it embeds years of our engagement memory, our methodology, and our triage rules directly into every test.

Four capabilities operate underneath it. First, pre-test intelligence: from the moment our practitioner begins interacting with the target application, the AI ingests the traffic and application context, automatically constructing the attack surface map, the threat model, and a structured test plan — ready for review and refinement before the first briefing call ends.

Second, parallel agentic execution: specialist agents run concurrently across vulnerability classes — injection, authorization, authentication, and more — while the practitioner focuses on the judgment-heavy work AI alone cannot do. Third, real-time guidance: the AI observes the engagement as it unfolds and surfaces coverage gaps and next-step recommendations the practitioner can act on before the testing window closes. Fourth, an engagement brain: a listener agent captures all activity into a connected knowledge graph that is queryable in plain language, and a narrator agent reads that graph at the end of the engagement to draft the report — findings, evidence, attack narrative, and remediation guidance.

What makes Solstice different is not the underlying technology — large language models and agentic frameworks are accessible to every firm in this market. The difference is what we have put inside it. Years of UltraViolet engagement memory, our practitioners’ own testing IP, our triage rules, and our methodology. That foundation cannot be replicated overnight, and it compounds with every engagement we run. The Solstice instance that tests an application this year is materially sharper than the one that tested it last year. That is the design intent.

Why is AI a gamechanger in application security? As teams deploy AI powered tools to support security tests, what should they be careful of?

AI is a gamechanger because it directly attacks the constraint that has held application security back for the better part of a decade — practitioner hours don’t scale. Every engagement has historically started from zero. Every report walked out the door. And the institutional knowledge that should compound across engagements just didn’t — it stayed in individual practitioner heads. AI changes that math. The cognitive scaffolding — mapping the attack surface, drafting the threat model, generating the test plan, executing specialist tests in parallel — becomes work that machines can do faster and more consistently. The practitioner spends their time on judgment. And the knowledge from this engagement is available to sharpen the next one.

What teams should be careful of is the marketing. The first wave of AI testing tools was sold as autonomous — the AI does it all, you read the report. Anyone who has tried to run a serious security program on that output knows how it goes. High volumes of low-fidelity findings. Context-blind attack patterns. Business logic missed entirely. And a triage burden that erases the speed advantage. Autonomy is not the goal. Augmentation is. The right question to ask of any AI testing tool isn’t “is it autonomous?” — it is “how do humans and AI work together in this system, and what does the human actually decide?”

The second thing to watch is the new attack surface you are creating by deploying these tools. Every AI you stand up — for testing, for development, for any function — is part of your environment now, and it needs the same scrutiny as any other production system. Many programs are racing to adopt AI tooling without a clear plan for how to govern, secure, and audit those tools. That gap is going to bite people.

Five thoughts about the future of AppSec you’d like to share in this Q&A?

1. The architecture wins. Human-led, AI-augmented will outperform both fully autonomous AI testing and manual-only testing — not in theory, in practice. The next two years will separate the firms that have figured this out from the firms that haven’t.

2. Testing gets rebuilt, not retrofitted. The future is not vendors bolting “AI” features onto the same SAST and DAST products. It is security testing redesigned around AI from the ground up — custom AI-powered workflows and agents integrated directly into CI/CD pipelines and IDEs, replacing the standalone-scanner model.

3. Shift-left becomes shift-everywhere. Developers will use AI to build and secure their applications from day one. Security teams stop being gates and start being partners — providing the guardrails, the patterns, and the judgment that AI-built code cannot extract from training data alone.

4. Institutional memory becomes the differentiator. Anyone can buy a large language model. What separates a useful AI testing partner from a useless one is what has been encoded inside it — engagement history, application context, triage rules, false-positive patterns. The teams that figure out how to compound knowledge across engagements will outpace the teams that don’t.

5. The AI itself is the new attack surface. Every model, agent, and retrieval pipeline an organization ships becomes part of its threat model. The programs that treat “how do we secure all the AI we’re shipping?” as a board-level question — and stand up the governance, controls, and testing for it — will be the ones still standing when the first wave of AI breaches makes the news.

A few thoughts you’d leave fellow CISOs and CIOs with before we wrap up?

Three things. First, don’t treat AI as a checkbox. The question that matters at the board level isn’t “are we using AI?” It is “how are we securing the AI we are actually shipping?” Make that a first-class question this year, not next.

Second, staff and budget for human expertise plus AI tooling — not one or the other. The teams that try to substitute AI for talent will end up with neither. The AI without expert oversight degrades; the expertise without AI leverage burns out. The combination is what wins.

Third, the right question to ask of any security vendor — including your own teams — is not “is the AI autonomous?” It is “how do humans and AI work together in this system, and what does the human actually decide?” That single question separates the programs that will compound from the programs that will produce noise.

Catch more CIO Insights: How Are CIOs Aligning Technology with Workforce Agility?

[To share your insights with us, please write to psen@itechseries.com ]

UltraViolet Cyber is a security operations partner that unifies red, blue, and purple team capabilities into one integrated team — finding what’s vulnerable, stopping active threats, and validating that your defenses hold under real pressure. Purpose-built to test, validate, and govern the AI systems organizations are deploying today, UltraViolet brings the same offensive and defensive rigor to AI that it applies across the enterprise.

Aravind Venkataraman is VP of Technology at UltraViolet Cyber

Related posts

Automation Tools Can Increase Deal Close Rate by +25%

CIO Influence News Desk

Conversant Group Hires Tod Grantham as VP of Professional Services

PR Newswire

NICE AI and Robotics Technology Reduces Complexities for Key UK Government Agency

CIO Influence News Desk