Skip to content

Director of Security, GRC and IT · Decagon

Transforming emerging AI companies into credible enterprise vendors.

I'm Ben. I build the security, compliance and IT function that lets a fast-moving company sell to the world's most careful buyers. Twelve years of engineering underneath four of leadership, which means I can read the code and the contract, and I have opinions about both.

  • AI security
  • GRC & audit
  • Enterprise readiness
  • Security engineering
  • Angel · advisor
Professional headshot of Ben Draffin

01For example

A major prospect gave us thirty days.

Decagon was moving up-market fast, selling into some of the world's largest regulated enterprises. A major prospect gave us a month to prove a young AI company could meet enterprise expectations — and rescue a launch after an incumbent vendor stumbled.

I wrote the technical roadmap, persuaded leadership to stand up an eight-person engineering team, and started an AI red-teaming program. I coached the customer on how to threat-model AI, ran product pentesting, negotiated the DPAs and enterprise contracts, shaped legal strategy, prepped GTM leaders, and led the external audit.

We won the account. It opened a regulated market that's since become a major part of the business. I slept, eventually.

30
Days
8
Engineers hired
1
Red team program
1
External audit

02Track record

Twelve years of shipping security, four of leading it.

2025 —

Decagon

Director of Security

Started and built the Security, GRC, IT and Internal Tools teams — twenty-plus staff and contractors. Supported 100+ enterprise deals through security review, compliance, customer calls and MSA/DPA negotiation. The job was executive persuasion and technical execution in the same week.

  • AI security
  • GRC
  • IT
  • Enterprise readiness

2023 – 2025

Verkada

Senior Staff Security Engineer

Led security and security engineering for the Cameras line, plus Alarms, Business Systems, IT and GRC. When the company faced an FTC consent order across five architecturally distinct product lines, I volunteered — which in hindsight was either brave or badly calibrated — and ran the response: 270 projects, 60 engineers, one very successful audit.

  • FTC consent order
  • 150+ engineers

2020 – 2021

Magic

Security Lead

Ran the whole security program for an auth and wallet platform serving 200K developers. Led GDPR, CCPA and security audits, and built fraud prevention with the infra and platform teams.

  • GDPR
  • CCPA
  • Fraud

2017 – 2020

Box

Senior Software Engineer

Founding engineer on Box Shield, lead engineer for authentication and abuse, architect of a real-time security rules engine. Co-invented a patented approach to anomaly detection of suspicious logins.

  • Box Shield
  • US patent

2014 – 2017

Zense

Co-founder, Director of Products

Built smartphone authentication that used human behavior as the password. The underlying research came out of Carnegie Mellon and now sits in the top 1% of most-cited papers in its field.

  • Behavioral auth
  • ML

03Advising & angel

I invest in and advise security, GRC, AI and infrastructure startups.

Pre-seed through Series A. Most useful on enterprise readiness, security product strategy, and standing up a security and compliance program from nothing. Reach out anytime — I answer.

04The rest of it

I write, I chair a non-profit, and I ask far too many questions.

Security leader, engineer, writer, compliance expert, governance builder. One enterprise deal needed all five.

How those thirty days actually got done
CISSP · CISA
Certifications
US 11,140,158
Patent — anomaly detection
KeySens
Top 1% most-cited authentication research
CMU · Vanderbilt
M.S. Information Security · B.Eng.