The BreakLine Arena · 47 min
Key moments - from our scoring
Substance score
50 / 100
Five dimensions, 20 points each
Sam Jones, co-founder and CEO of Method Security, discusses building a dual-use cybersecurity platform designed to achieve cyber resilience at scale for the most critical U.S. institutions. Method takes a contrarian approach by targeting Fortune 500 companies and government agencies - including the Department of Defense and Department of War - from day one rather than following the traditional startup playbook of starting with commercial customers. The company has raised $26 million from Andreessen Horowitz, General Catalyst, and Blackstone. Jones reflects on his career arc from Air Force Cyber (AFT Cyber) through Palantir and Shield AI, where he gained expertise in mission-critical software, autonomy, and hardware-AI integration. Method's technical approach centers on continuous security challenge and testing - automating what historically required expensive red teams and penetration testers through AI-powered offense and defense capabilities. A recent partnership with OpenAI operationalizes frontier language models into trustworthy autonomous security tools. The platform shifts enterprise security from reactive alert-based models to proactive mission objectives and rules of engagement, enabling organizations to stress-test their entire infrastructure continuously rather than quarterly. This episode is essential for defense tech investors, government CISOs, security leaders at critical infrastructure firms, and founders building in the defense-AI space seeking insights on dual-use strategy, program-of-record customer acquisition, and embedding government DNA into startup architecture from inception.
Jones contends that government deserves the best commercial technology, and this is only achievable if software is commercially competed every day. If software is not continuously tested against real commercial competition, it becomes 'de facto dead on arrival' when delivered to government customers because it cannot withstand actual competitive pressure.
Method Security focuses on cyber resilience for the United States by building platforms that enable organizations to continuously challenge and test their own defenses through autonomous offensive and defensive capabilities, rather than relying on expensive, infrequent red team engagements. This shifts security from reactive alert-based responses to proactive mission objectives and rules of engagement.
Jones learned from Palantir that serving complex government customers from inception embeds the necessary DNA into company culture, delivery practices, and technical architecture - including deployability, compliance, and program-of-record revenue capture - in ways that cannot be retrofitted if commercial customers are served first.
OpenAI builds frontier language models while Method operationalizes them into trustworthy, enterprise-grade autonomous security tools with proper guardrails and rules of engagement. Together, they can deliver tailored solutions to U.S. Cyber Command and other DoD organizations that cannot be solved by ChatGPT or traditional software alone.
Method prioritized deployability and AI guardrails over flashy demos - avoiding certain commercial technologies and building systems that can run on constrained environments like a Mac Studio, ensuring the platform can be integrated into full weapon system constructs and avoiding tech debt that would limit their ceiling with top-tier customers.
Our reviewer’s read on each dimension, with quotes from the episode.
There are a handful of genuinely non-obvious practitioner points - the dual-use software competition argument, the AI-offense economics framing, and the force-redesign analogy to coding productivity - but they are spread across extensive career narrative, company origin storytelling, and promotional framing that dilutes the payload significantly.
AI is essentially taking cyber offense to infinity and the cost to zero at the limit
Who might charge you $50,000 for a penetration test that's like a PDF that like goes into the trash bin. Those times are done
The dual-use commercial-validates-government-software argument and the 'AI offense to infinity, cost to zero' framing are reasonably fresh articulations, but the broader thesis - continuously test your defenses with AI-assisted red teaming - is a widely circulating idea in security circles, and the Palantir/Anduril comparisons are standard defense-tech founder discourse.
you don't get it unless you're dual use, period
Security is funny that there's not a lot of like totally new ideas or like recycled and expanded and deployed
Sam Jones is a genuine practitioner: early pre-Foundry Palantir employee, early Shield AI operator, VP of Product at Stellar Cyber, and now a funded founder with real deployment credibility in both commercial and government security markets - not a career podcast guest or pure thought leader.
This was pre commercial products. Everything that they have. Foundry did not exist when I was there in the beginning
I wrote this note to myself, which I still have in my phone notes that basically said...do this, but for cyber
The episode has reasonable company-level specifics - headcount, funding round size, investor names, the Mac Studio deployability milestone, the 16-of-17-engineers-to-CTO flat structure - but is almost entirely absent of customer outcome data, named enterprise wins, market sizing figures, or security metrics that would give a B2B operator real benchmarks.
We're 20 people right now, 17 of whom are engineers
raised $26 million across a seed round and series A from top tier investors like Andreessen Horowitz, General Catalyst, Blackstone
The host rarely challenges claims, frequently affirms the guest's own framings back to him, and leans heavily on 'love it' and congratulatory cues; the few requests for elaboration ('bring that to life') are useful but don't generate the productive pressure that would extract sharper insight.
I think you guys are too. You got a ton of momentum right now.
And congratulations.
Computed from the transcript - who did the talking, and the words that came up most.
Sam Jones started his career as a GS-7 cyber operator in the Air Force. Today, he’s the co-founder and CEO of Method Security, a bleeding-edge, dual-use cybersecurity and AI company that has raised $26M from top investors, including Andreesen Horowitz and General Catalyst. In this BreakLine Arena conversation, Sam doesn’t just talk with Zayn (CEO and Host) about cybersecurity; he talks about building for the business effect from the onset. Sam unpacks why his team chose what he describes as the “psychotic approach” of serving Fortune 500 companies and the Department of War from day one. Resilient software isn’t a strategic choice but a structural requirement if the government and Fortune 500 are to secure their organizations. And what it means to design a company, technically and culturally, around the hardest missions first. “To become resilient, you need to test the whole of the enterprise all the time where it matters most.” This episode is about more than AI and cyber. It’s about raising standards. Building teams with real conviction. Choosing the harder path early so the ceiling stays high later and for the long game.
Transcribed and scored by The B2B Podcast Index.
Sam Jones: The government deserves the best commercial tech. I don't think that is too controversial. But you don't get it unless you're dual use, period. There's obvious things like hypersonics or something else that are obviously single use, but we're talking about software. And if the software is not commercially competed every second of every day, I would argue that is like de facto dead on arrival once it hits to some government customer because there's no way that it could withstand real competition.
Zane Knob: Welcome to the arena. At uh, Brakeline, we believe the arsenal of democracy is our people.
Narrator: We use our field tested effects based hiring methodology to connect top performers from all backgrounds with mission driven companies shaping the future of tech, defense, AI and beyond.
Zane Knob: In this space, you're going to hear real stories from the builders, operators and leaders redefining what's possible. Whether you're a founder, future founder, or not quite sure what comes next. You belong here.
Narrator: Get ready to step into the arena.
Zane Knob: Hey folks, welcome to the Brakeline arena. I'm Zane Knob and I play for team Brakeline. Today we're joined by Sam Jones, co founder and CEO at uh, Method Security. Sam and his team are building at the leading edge of cybersecurity for the most critical industries. Sam is an Air Force Palantir and SHIELD AI alum and multiple time founder. I'm so fired up for this conversation. And if you haven't heard of Method Security, then you will. Sam and the team have raised $26 million across a seed round and series A from top tier investors like Andreessen Horowitz, General Catalyst, Blackstone and leaders in security and AI. We're excited to dig into Sam's work, career path and what he's seeing on the front lines of security today. Sam, thanks so much for joining us.
Sam Jones: Zane, thanks for having me. Yeah.
Zane Knob: And Sam, um, if you don't mind, I always like to start with you just describing kind uh, of the arc of your career, a little bit about your journey. How do you reflect on the arc of your career, how you got to where you're at now with Method, your current role and what you guys are working on.
Sam Jones: Yeah, Method is this really interesting culmination of everything that myself and my founders have done professionally. And it seems like everything that we've done has been for a specific reason, training us for this moment. So it's just so exciting to be building right now. But I am a software engineer by background. Always been interested in building things, but always been called to um, especially government related missions. And that is what brought me to worked for the Air Force out of college where I was a security operator and engineer at AFT Cyber down in San Antonio supporting primarily DCO missions. Loved the mission, really disliked the bureaucracy and I wanted to build things and it just wasn't the place to do as a uh, GS7 when you're 22 there's a lot of people that push through that and I think very highly of that service. But I just wanted to go a little bit faster but still be aligned to similar missions. And that brought me to Palantir 12 years ago now and uh, help start some of their initial commercial business. This was pre commercial products. Everything that they have. Foundry did not exist when I was there in the beginning so helped build and contribute to a lot of that and then moved over to some of the government mission areas working across every military service doing things like logistics, leading our cyber business both domestically and internationally in a lot of different product development things. And that was just the best place I think to start one's career if you're you know, want the engineering culture, want that mission focus and just be surrounded by the best people to build with. Extremely grateful for that opportunity. And it's crazy to see how things turned out because when I was there felt like we were losing all the time and you know, oh, how things have changed in that sense. But I wanted to go, I wanted after I was a Palantir for over four years and wanted to get closer to some non software problems, specifically hardware and AI that brought me to Shield AI where I was a earlier uh employee there in 2018 and helped build some of their internal data infrastructure for basically collective learning and simulation and also manufacturing. And it was a real hard good lesson on no fail autonomy missions and bringing like real life AI into the world where failure is not an option. And uh, then moved on to a more traditional. Basically had an idea for method while I was there which was in essence do what we're doing at S.H.I.E.L.D. but for cyber. And I actually wrote that down in 2018 but I knew I needed a little bit more traditional security experience so I went to join a company called Stellar Cyber as VP of Product and uh, focusing on detection response, kind of learned the market, learned how to sell a little bit better and basically prepared for method but it was always method. Even after meeting my co founders at Palantir we knew we were going to start something and it uh, was just a matter of when.
Zane Knob: That's cool. That's an amazing reflection and through line I have some prepared questions that we'll get into later about kind of some of the decision making in your career that I really want the listeners to get insight from. But you just mentioned going from college directly into a GS7 position at uh, aft cyber down in San Antonio. I feel like that's such a non traditional path. Could you talk about what drove that first decision? And I love that your quote of love the mission didn't like the bureaucracy. I think that resonates with most folks that serve in government or mission focused government service. But yeah. How did you end up going from College into a GS7 position at app Cyber?
Sam Jones: I had done internships right out of college with Gdit. I actually started working for Gdit an internship three days after I graduated high school and saw some of the cyber mission. They were supporting the AFNET at the time. So got a little exposure there, got cleared and got a taste of some things. And then my civilian job was through this scholarship program called the Smart Scholarship, which basically it pays for n number of school years and then you need to contribute those n number of amounts of service years back in some engineering capacity. And BAFT Cyber was a pretty natural fit. I always knew I was going to like the mission. I thought I was going to be able to build a little bit more. So that was a little disappointing, but nevertheless got to do some cool work and meet great people, but the opportunity to make a good financial decision and support the country was kind of a no brainer.
Zane Knob: Yeah, love it. Okay, again we'll dig in more later, but let's talk about now and Method Security. So can you talk us through Method Security's mission? What you're most excited about contributing within what you've called the Cyber Industrial complex?
Sam Jones: Yeah, I would say we're trying to rethink and even attack the Cyber Industrial complex as opposed to work within its traditional boundaries. But what we are all about at Method is cyber resilience for the United States. That is the problem that we're focused on and that is our mission. And accomplishing that can't be done with a simple business model nor a simple set of security technologies. And so we're building something that is a business that more closely resembles like a Palantir anduril type sized company, albeit very focused on security. And specifically, there's two ways to unpack our mission. One is on the customers and one is on what it takes to achieve resilience. On the latter, just as anything in nature to achieve resilience you need to test yourself, challenge yourself to ensure that you can actually withstand so that you can get stronger. And helping a security enterprise do that is no different. You need to challenge yourself, you need to improve, you need to re challenge yourself, and you need to do that all the time. And historically that has been a very human, labor intensive process where you either hire expert red teamers, penetration testers and consultants to beat yourself up, provide reports so that you can improve, and then you maybe try it again next quarter and then you continue to improve very slowly. That is an unacceptable technical approach in the age of AI because AI is essentially taking cyber offense to infinity and the cost to zero at the limit. And that spells bad news for anyone that is moving too slow. And so we are basically equipping organizations with a much more trustworthy and enterprise grade set of capabilities so that they can be their own worst enemy everywhere, all the time, such that they can improve. And that is like flipping a lot of the labor market on its head and helping them rethink how certain parts of their security program function. So it's all about resilience. And our technical way of doing that is challenge, which on one end of the spectrum is like actual offensive cyber warfare. And then on the other end, it could be something as seemingly simple as vulnerability validation and prioritization, which is actually a huge time suck for enterprise security teams. On the customer and business side, I mentioned the problem that we're focused on is resilience for the United States, this is inherently a dual use problem. Cyber attackers seldom differentiate between public and private. They don't care. A lot of times these things are intertangled anyway. And so we have built the business very intentionally to serve the most important organizations across public and private sector sectors from the beginning. Which is very different from the traditional wisdom of building a startup. You know, you start small, don't you dare try to go after the Department of War or the federal government. But we said, you know, that's the stuff that matters. We're going to build that into our DNA and we're not going to do it as an afterthought. So resilience for the United States, we do it via challenge. We're dual use. Cyber is the ultimate dual use use case. And we've focused at the very top of the market for the institutions that we rely on, not smaller companies that certainly need good security. But if they were to go down and have some operational impact, no one would really blink an eye.
Zane Knob: Yeah, and when you say resilience, I think what's interesting, my time as an Air Force intel officer, there's always an interesting philosophical discussion of like where does intel stop and cyber begin? And then it came into hey, where's the physical overlap with the digital? And just all this multi domain complexity is now how we think about it. But as a former intel officer, when I hear you say resilience, I'm thinking relevance. Like what you guys are describing is like the only way to stay relevant is to build that resilient. Not architecture but I guess how would you. Is it a resilient network or resilient enterprise? How would you phrase it?
Sam Jones: It's a resilient enterprise and it's really a board of director level discussion. There's enough newsworthy happenings where organizations are meaningfully going offline and having billions of dol of impact because of that. And security for a long time has been like this cost center afterthought, but now it's like a top three board item. Because if resilience is not under control, everything operationally is at risk and it's hard to do technically. It's also really hard to do from a security leadership perspective, which there's only a small cadre of people with I think the right experience to lead Fortune 500 organizations in this new era. But you know, we're focused on the technology to support those teams to achieve what they need to technically.
Zane Knob: All right, you kind of alluded to it or kind of planted the seed of the customer set you guys are working with is at that top tier. And I want to highlight for the audience that I've heard you describe this as serving the hardest customers first. Also heard you say this is a psychotic approach. It's painful. It's a herculean effort. Can you share more about what that means and uh, to you and the Method Security team? Because you've built a team that is absolutely on fire to achieve this vision and do this mission. So talk about what that means a little bit more and why you took this approach.
Sam Jones: When we first started pitching the idea of Method Security, obviously our backgrounds are very strong in terms of the experience, but investors would be like, why would you ever try working both not only with the government from the beginning, but then also with the most annoying and complex like security buyers? That's such a bad idea. Start with your series A friends, sell some software to them, grow to the enterprise and then hire like a head of federal and go to that later. That's the playbook. But I think what we saw at Palant, so uh, myself and my other two co founders all were at Palantir very early in our careers and that's where we met, we did a lot of work together and so we've been teammates for 11 years. This was in many ways the Palantir approach. The intel community was some of the first customers then it was kind of like SOF customers. The first customers were financial institutions on the commercial side, which didn't really work out in the beginning, but then they've since kind of come back with a vengeance and it's worked out. But I think what we learned both technically and then like on Delivery and in BD's, that if you don't build into your DNA serving those types of customers from the beginning, it's very, very challenging to do that, if not impossible later on. And yet there's many companies that have like a really successful government business that started commercially small and have grown and they can sell and have a really nice business line. But I wouldn't say it's in their DNA nor is it in their mission to do so. And they're not doing program of record style delivery and revenue capture. And that's what we're after. And I don't think it is possible to do that without making that what you focus on initially and, um, doing so. Dual use I think is also just so important because the government deserves the best commercial tech. I don't think that is too controversial, but you don't get it unless you're dual use, period. There's obvious things like hypersonics or something else that are obviously single use, but we're talking about software. And if the software is not commercially competed every second of every day, I would argue that is like de facto dead on arrival once it hits to some government customer, because there's no way that it could withstand real competition. So it was kind of like we kind of forced ourselves into having like, we want to do this mission stuff, we have to do the commercial stuff at the same time. There's no other option other than this Herculean hold. And we're the team to do it. And so it is like a suicide mission. But I think we're going to pull it off.
Zane Knob: I think you guys are too. You got a ton of momentum right now. So I want to go one level deeper though, because you mentioned doing things in a program or record way and how choosing these customers from day one allowed or cultivated a DNA that's going to be required to accomplish what you want to accomplish long term. What did you have to do differently and could you bring that to life a little bit more for the audience? Like, are there any specific examples or decisions you guys had to make about the product, about funding, about the org that you look back and go like this was a decision that we had to make so that we could have this DNA.
Sam Jones: Yeah, I'll give a technical and then an org design example. Keep MHM in mind. Our founding team has a lot of experience in security software like defense tech. And so we're seeing a lot of corners that would it be impossible to see for someone that doesn't have that same experience. And so like a really good example is something that my CTO Sean and I thought through from the very, very beginning was on deployability and also guardrails for AI systems. We spent more time thinking about a lot of other AI for security companies at our time were doing a lot of work related to, you know, how cool can I make the AI in my first six months to make a killer demo? And we were tempted by that. But we knew like the long game is how can we get this system deployed in a way that a top financial institution or department of War can actually meaningfully adopt? And how can we still have great product acceleration but not shoot ourselves in the foot and limit our ceiling? And so we made very, I would say not controversial but pretty difficult design decisions around. We're not going to adopt certain like commercial technologies. We're going to make it really deployable. In this sense we're like playing for the long game. Yes, it might slow us down in the meantime, but when the time comes that we need to put all of method on a Mac studio, which we recently accomplished, it will be possible and we won't have an insurmountable amount of tech debt and shoot ourselves in the foot. I have felt that before organizationally and so we've been playing for that and that ability to do that is what technically unlocks the foundations to go after program of record style stuff. It's not like we're acute app that maybe could hope to get to IL5. We could actually be integrated into a full weapon system construct. So that's like a technical thing that we did. And on the AI side we basically had this point of view that AI is going to get just like dramatically good over the next several years. And we're not going to fight that and we're just going to ride the wave, but we're going to build the surrounding infrastructure to make it really trustworthy for security operations. And so when you really like look under the hood of our system, it's a very compound system that ensures that it only behaves in a way that a user demands it to behave. And that is done so deterministically at multiple levels. So we spent a lot of time building that as opposed to tweaking, prompting, trying to build all sorts of agents. In our first year that was non consensus. I think it's paying off with our target market. But we've been playing for those big organizations from the beginning. And then on the org design, I think we've always been looking for certain type. We're 20 people right now, 17 of whom are engineers, and we've been hiring a lot of. So like we have no sales team, which is intentional part of the org design, to go after these big customers. And then we're also hiring engineers that can almost have some of the Palantir FTE in them, either directly or indirectly, so that they can be directly with customers and we can keep the team super lean and customer focused while still building for these really incredibly complex customers. So anyway, we've been like putting off a lot of organizational functions for as long as possible and we're just like putting mission and product and tech into our DNA and we uh, think that ultimately raises the ceiling of the company.
Zane Knob: Yeah, I love that. Thank you for those two examples. It really does bring it home. And you just mentioned AI. About a month ago, there was some big news. You guys announced a partnership with OpenAI that's centered on giving us cyber operators an edge by responsibly harnessing autonomy at scale. What does that partnership unlock operationally for you all? But then also, could you bring that to life? Because most of these cyber warfare engineers, cyber operators, are in a couple floors down in an NSA site somewhere. So, uh, bring that to life for the audience of like, how's that going to impact cyber teams defending these critical missions?
Sam Jones: Yeah, so There's, I think, two reasons why we're so excited about the partnership with OpenAI. One, the technical marriage of our technical competencies is perfectly complementary. They make the best frontier models in the world, also in America. And we take that raw material and we operationalize it in the trustworthy way for offense and defense and security. And so they don't build that infrastructure, we don't build the model. We need each other for these missions. And they also are really building up a pretty incredible government business that is dedicated to serving the US's interests. And cybersecurity is a top area that we need to get right in AI, both ethically, but then also in terms of national resilience. And so when we met them and we knew some of them from prior lives, but they had kind of the same mission attitude that we did. So it's just a really natural partnership to then commit to when some organization at US cybercom has a really hard defensive cyber operations challenge that cannot be solved a la, uh, chatgpt and cannot be solved with just regular software. There is these two companies that are explicitly partnering together to solve those things and can come and basically deliver a solution that is tailored to the mission. So it's commitment to just work together technically and then also like on the go to market to really bring our competencies together to get outcomes because we both need each other in this realm. Love it.
Zane Knob: And congratulations. You mentioned early on that methods platform, that infrastructure integrates autonomous offensive and defensive tooling capability. And I've heard you say before that what it fundamentally does is it shifts security from being reactive and like reactive alerts to mission objectives and rules of engagement. Could you talk more about that reframing and the impact that it's going to have on any enterprise's ability to fight and win in cyber environments?
Sam Jones: Yeah, I don't think there's anything controversial about. If you think about how I've technically tried to unpack resilience matters, you need to challenge yourself all the time to become resilient. And that is, you know, technically very challenging. This is not necessarily a new idea. Security is funny that there's not a lot of like totally new ideas or like recycled and expanded and deployed. And even with like the new uh, like a lot of the attacks that we're seeing, it's driven by AI. It's not zero days all over the place. It's just a adversary with speed, scale and reach that is unprecedented. And so it is all the more important that the doors are shut and you're testing your defenses all the time to ensure that you're ready. So it's a lot about readiness might be a more like military aligned term, at least that resonates. But there's always been this concept of either like red teaming, penetration testing, purple teaming and doing so in software as opposed to people. And there's a lot of great companies and maybe the previous era that have been working on this and have delivered some pretty meaningful results. The challenge with the services market and then also the legacy approach to some of those software technologies is that it's not adaptable to your organization. And it's very hard, if not impossible to scale throughout a meaningfully large enterprise. To become resilient, you need to test the whole of the enterprise all the time where it matters most. And that is a really difficult software problem that was impossible before this current revolution of language models in particular. And so like we're actually delivering on some of these old ideas in a, uh, technically new way, but the ideas remain. And so our platform can be like a full blown adversary when you need it to be within the right rules of engagement. It can be this lightweight integration test like capability so that you're testing atomic portions of attacks all the time and making sure your detection program looks good. It can be this always on security engineer researcher that's looking through vulnerabilities and looking for impact and basically like serving up things on a silver platter. And it's doing all of those things all at once. And we think like that concert of activities is what moves the needle at enterprise scale and is why it's a really hard software problem and why AI today was the missing technical ingredient as compared to even a couple years ago. So this idea of continuously beating yourself up is not, you know, we did not invent that, but I think we're technically delivering on that promise for real at enterprise scale.
Zane Knob: So it makes me think of a question around when you're in these boardrooms talking with these Fortune 100 or uh, government organizations that have these mission critical enterprises and by the way, you're there with your co founders and I'll also say that I think your CTO has the greatest name in CTO history. For those who don't know, his last name is Hacker. And so Sean Hacker is the cto.
Sam Jones: Not only that, he started his career at the nsa. Um, and so there is a thing to naming destiny. And we joke that half of his enterprise value contributions to method is like his last name alone. He's an amazing cto, but the last name rocks.
Zane Knob: Yeah, I mean, I'm sure it begs the question, like he gets the question, like did he actually change his name all the time?
Sam Jones: Weekly.
Zane Knob: So you and Sean and the team are in these rooms. You just listed off some key capabilities that I feel like are probably a part of this answer, but I'd love to ask it a different way. So as when you're in these rooms within the boardrooms, what are you describing as the most critical capabilities that are going to distinguish between those that struggle to keep pace with the adversary or with the attacks that are coming versus those that do have enough resilience that they're always at least one step ahead?
Sam Jones: I think our answer would probably be trust and safety. And that is because the AI for like code development has shown everyone like, wow, this stuff is crazy. It works, it's undeniable. If someone can just walk up and basically build a complete company almost from a prompt, it's pretty incredible. And so I think there's general consensus that, okay, it should be possible to have this always on adversary that is testing you all the time so that you can stay ahead of you hurt yourself before someone else can and then you shut that door and then you do that all the time. That's the consensus, I think, because people have seen what is happening in the coding market and that's like the obvious thing I think that the board needs to know of, uh, yes, we need some capability like this and then the question is what does that look like and how? And that is I think the really challenging part because the security team has been burned too many times on loose adoption of technologies that may be affected core operations. And they do have a lot of risk posture to adopting new things. And so the most important thing for the board is are operations going to maintain and is there any way that security can also help us do more business? And any security system that just in like, you need to be able to trust the new velocity of code that is being shipped throughout your enterprise because you're increasing a lot of bugs, you're maybe doing things pretty sloppily. If you're going to be launching this adversarial blanket against yourself all the time, you need to trust 100% it's not going to mess up your business. And that is I think going to be the hallmark of both the security program and then the trusted technology underneath. And that is what is really hard. And that's not obviously something that can be vibe coded very easily. And that's what we focus on. And I think that is our key differentiator in the enterprise.
Zane Knob: You've mentioned the labor force a couple times. You mentioned the security teams, the impact how you were just talking about how they've been burnt by like loose adoption. When you think about the customers that are adopting Method Security's platform and the interaction between humans and the autonomous software that is going to continue to get better and better. How do you think about the human operator being complementary to that technology? And do you have an opinion on what that means for security team training and even talent pathways in the future?
Sam Jones: We are seeing really interesting things on force redesign and security team functional changes. It's most apparent in our commercial customers just because they're kind of adopting it more as an entire team where the federal government is often like pretty siloed you have your DCO team that does not talk to the red team, that does not talk to the OCO team, that does not talk to like the CSSP that could be improved.
Zane Knob: But understatement, uh, of the podcast.
Sam Jones: Yeah, we are seeing the coding analogies are just so good because they're so proliferated and it's been easier to really change that market, I think, where you might have a designer that can all of a sudden code now and they're just shipping things self service. You have a product manager that's not beholden to the engineering team because they can now build a prototype on their own. You have go to market teams building their own systems as opposed to buying these niche software sales tools. We're seeing something similar in security where like our software in particular helps a blue teamer that is maybe exquisitely good at logging and like querying and some defensive tasks play red for the day. Meaning that they have the software levels them up so strongly that they can actually go be the bad guy and they're all like a full self service loop. And so, okay, what should the red team be doing if they don't need to be doing that? They actually now are unlocked to do higher value activities as opposed to living ticket to ticket doing what the SOC asks them to do. So there's a lot of interesting things there. And I think any great software product should always strive to just have the lowest training bar imaginable to get up and running. And we are definitely seeing this especially in the government, where before even touching a keyboard in some of these different security professions, you need to go through like multiple years of training. And I think training is good. And if you rely on AI too much to do all your work, you effectively lobotomize yourself. And so you need to be very careful. But should we force red and offensive operators to go through multiple years of training before they can even do a job? No. There's obviously a better way to do that and we're trying to be like a part of that technical solution. I think there's so much in the security backlog as like a analogy that we don't need to shrink security teams, but I don't think we need to grow them all that much more. So like we often say you can accomplish this resilience thing, but with the team that you have and you actually need the team that you have, you don't want to shrink it, uh, because there's 10x more work that you haven't even been able to tackle than what you're doing today. So let's just like go do that backlog. But I do think this does spell really interesting impacts for the services industry. Who might charge you $50,000 for a penetration test that's like a PDF that like goes into the trash bin. Those times are done. So I think all the talent's going to basically assemble internally and they're all going to be like superhuman security operators.
Zane Knob: I love that, the techno optimist point of view too. Yeah, I agree. Okay, so switching gears a little bit because we dove pretty deep into the tech and the customer set and the way you guys have gone to market, I want to ask a few questions about the team. Obviously, really high performance. You mentioned you guys have, um, 20 employees. Currently 17 are engineers. These folks have unbelievable backgrounds. Some of the most demanding technical and operational environments. Elite teams from Palantir, Shield AI, which we've mentioned, aws, National Security Agency, multiple sectors, apartments within the Department of War. One of my favorite things to hear from founders is just how you answer the question. What is the team's hiring philosophy? How have you and your co founders thought about hiring really strategically?
Sam Jones: We have a really strong engineering first culture that I think resembles a lot of the best parts of Palantir's engineering culture, where you have small autonomous teams, you lack hierarchy, you're moving really, really fast. We have worked m hard to ensure like a mission focus throughout. It's very clear what you're signing up for method, like what we're about, what we value, the customers that we support. And if that's not for you, like that's fine, no problem, but don't apply here. And I, uh, think one lesson that I had from Palantir is that there was a lot of like ambiguity about what Palantir did for a long time. And I think that has largely been dispelled as they've refined their outbound messaging. But I saw what Anduril did in particular is they were not going to repeat that mistake. And they were super clear about what they did for whom from the beginning. And so it just created this self selecting hiring funnel that we have strived to replicate. So like we're doing defensive cyber, we're doing offensive cyber, we're supporting the US government and Fortune 500 organizations. We run a super lean engineering team where we expect everyone to ship code on their first week. And you know, we are really demanding, but we're supportive. We act like a team. We don't hire assholes. We're super low ego. No one has titles and currently every engineer reports to the CTO. The 16 out of the 17 report to the CTO right now. And so we have a gentleman from AWS who had like really serious big time responsibilities there. He's a software engineer just like a new grad would be a software engineer. And now uh, obviously he's bringing certain level of expertise and credibility and leadership that someone else isn't. But I think we've almost tried to focus more. It's very clear to us the culture that we want to build and have and feel and we've tried to put in really clear designs into our organization and our process that just ensure that it stays that way. We're flat, we're really clear about what we value externally. Like we test people with zero AI and with full blown AI to test their thinking with and without that Ironman suit. And so we're doing a lot of things really intentionally on the hiring process and then making sure we have to meet you in person, like you're getting lunch with the team, like everyone is, you're meeting every single founder and, and things like that that are maybe less controversial.
Zane Knob: Yeah, I think the hearing you even say watching Palantir's approach versus Anduril's approach of Palantir having some ambiguity or even just like leaving room for ambiguity for a long time and then Anduril take a different approach and we have hundreds of Brake liners at both those companies and very proud long term partners with both of them. And one of the things that I think because Brake Line's approach over the last 10 years, we always start talking to these top performers that come into our community, we ask them what are you optimizing for? And the other way to think about is like what effect are you trying to achieve in your career? And you're right that it allows for a self selection that's really critical to having somebody join your company at the end of that interview process that is all in, all in on the vision, all in on the grittiness that's going to be required. There's just a clarity and it's like okay, now we can execute together. And it allows for long term retention, long term outcomes, mastery of those folks. And so it's great to hear all the different ways that you all are designing and implementing an interview system so that you get that you almost future proof by design the interview system and the signals you're getting along the way. Before we move on from the interview system, is there any other example where you think about hey something that method Security intentionally does when you're selecting talent that reflects the grittiness you've alluded to and is very obvious in a lot of the stories you've talked about.
Sam Jones: I'll uh, just kind of double click on a point that I made. We test especially well. Most of our hiring is engineering hiring. We test engineering hiring with different take home assignments where we basically want to test their ability to pick up new concepts and also work with AI. It's a really good way to test like how curious someone is and how adaptable and their engineering growth mindset. Uh, take home projects are kind of controversial within tech companies. We find it to be really important because you can see the work very closely. We give like a representative large hard problem and we're testing for like how you use AI, how fast you can come up with these concepts, like obviously how good is your solution but also how well do you present the solution? Like how good is your documentation? Like have you researched like what we're doing and seen its applicability? Can you talk about that? And if someone spends 2 hours on it versus 8 hours on it is usually like a really strong signal like do they want this? And I feel like most everyone that we've hired is like gone certainly the extra mile. And to complement that like when we bring someone on site, we basically strip all of their tools away and have really hard whiteboarding problems where we're just drilling into them, having them break down problems and things like that. And I think we've like refined this over the time. And then on non engineering hires we make them either debug our system for us or pitch it to us as if we're a customer. And it's so telling. Did you research the company? Did you read every word in the documentation? Are you role playing really well? Are you clicking through the product like an expert? And if the answer is no to any of those, it's obvious you don't want to be here and that's fine. But it's like a pretty clear signal. So we give a lot of opportunity to just get into the weeds and test the grit as that's super important.
Zane Knob: I've never heard of the method security origin story, but I'd love to pivot to that and give you the opportunity. And maybe I just couldn't find it. But could you take us back to that? Where did the idea and the first conversations happen? You mentioned as a matter of time, but was it in a garage? Was it over email when you were at SHIELD with your co founders on uh, A bar napkin and a Georgetown speakeasy. Uh, what's the origin story?
Sam Jones: So we all met at Palantir between 2014 and 2016. My other co founder, Dan I was his first boss. And then Sean and I worked together leading several projects. And so we had always bounced ideas around and we developed a lot of as, say, cyber data specific tradecraft while we were working there and, like, could really tell that we were onto something. In 2018 when I worked at Shield AI, I wrote this note to myself, which I still have in my phone notes that basically said, I was two weeks into SHIELD And I wrote basically, like, do this, but for cyber. Like, what you're doing at SHIELD AI, you're building these robots that can learn from experience and they can navigate and plan and accomplish certain tasks. Here's this, like, research paper that's, like, pretty interesting. Do it for cyber. Turns out the raw materials to accomplish that were not available then in 2018. So I'm glad we didn't start it then. But Dan, Sean and I had bounced ideas in and around that idea space for the next four years straight. Every six months we have this trail of different notion workspaces where it was the next idea. And then we had a pitch deck and, like, we just kept recycling. And Sean likes to joke that I tried to get him to leave Palantir 10 times, but each time the idea got better. It, I would say, really strongly crystallized this one day in early 2023 where it's very clear, like, okay, just prototype something with GPT3. And it kind of mildly worked in terms of like, a little penetration test bot. It was very clear that this company had to happen now. And we were the only team that could deliver the thing for the US that was going to be trustworthy. And we knew you have to have the right business model, you have to have the right culture, you have to have the right, like, engineering design principles. Who else has this experience? And it was almost like we just had to do it. And I, uh, called Sean and Dan in March 2023, and we were all quickly in. We had, like, Sean and I had to unwind our current jobs, so we didn't really start working on it for several months, but we were in. Sean left Palantir, I think, in the beginning of September 2023. He was going to go on vacation to Greece before we, like, really got started. And I called him on a Friday and I was like, hey, we have a meeting with Andreessen Horowitz on Monday. He's leaving for Greece. On Tuesday he's like, can you come to San Francisco now? He was like, sure. So we were all there. We were in Palo Alto at the same hotel we used to stay at for Palantir, like basically building our pitch deck and initial demo prototype. We pitched them on Monday and then we closed a seed round while he was in Greece and then it was just off to the races. But yeah, uh, we started a lot of work just working out of my basement and just like building stuff. And eventually we got some real offices and whatnot.
Zane Knob: But I love it. You guys have nice offices. I've been to the one in New York City. You guys have great.
Sam Jones: Yeah, that was nice. We're getting a new one in D.C. which will be great too. Got get out of the shared space time.
Zane Knob: Excellent. So m. I know we're coming up on time. I want to get to the lightning round, but I want to ask one question and it can be a tight, concise answer so that I don't take up too much of your time. But we work with. There's a lot of our community that are top performers at some stage of their career. But what we've seen over the last 10 years is there's a subset of those top performers that will like you and your co founding team, be founders and get to the point where they have been working on that idea, going back and forth in a notion document for four years and say, hey, now it's time and we're all in. Let's go do this. What advice would you have to somebody listening that is at some stage in their career, but they have an inkling of like, hey, I want to build eventually any advice or even you could rephrase that question to be like, is there a best piece of advice you've ever gotten along your career that you reflect on as being something you'd want to share Now?
Sam Jones: I think the most important thing in the lead up to any decision there is just to find the smartest groups of people and just go work with them, no matter what the cost or what the role or responsibility is. And don't worry about anything else. You'll get better, you'll build a network. And without those two things, whatever you try to do probably won't happen in the way that you want it to. And so sometimes that could be taking demotions, sometimes that could be just thinking outside the box, whatever it might be. But I think that is probably the most important thing. And when the time comes, you definitely need the team. Like there are successful solo founders and more credit to them. But a lot of the timing will just be on like assembling the right people. And that is why companies predominantly fail is like that founding team doesn't work out. So I think that's worth being more patient on. But then once it's time to go, just be careful to the advice that you listen to and if you believe in yourself, just mostly shut out what everyone else is telling you and just go for it. Love it.
Zane Knob: Thank you for sharing that. And I want to finish off with a quick lightning round of just a few questions. First, what are you consuming right now? Books, podcast, shows, movies?
Sam Jones: I'm a CEO of a company and I have three kids five and under, so I'm not probably zero to all of the above.
Zane Knob: Perfect. What's a habit or practice that helps you stay grounded as a leader? Other than what you just described of three kids under the age of five?
Sam Jones: Honestly, that would be my answer is like being a parent to young children. Like you might be stressed at work, but it's a daily reminder that nothing matters as much as being a parent and whatever at work is going to be okay and we're going to figure it out. But that's probably the best reminder and habit that I go through every day forcefully, but also, ah, I enjoy it.
Zane Knob: Yeah. All right, last one. Do you have a personal mantra or principle that you feel like more than anything else guides your decision making?
Sam Jones: Probably think about that, but probably something along the lines of just like just go for it. Which is maybe kind of simple but you can have the things if you just go for it and failing is just fine. It was kind of, you know, starting a company with like a 3 year old and a 1 year old was maybe a little risky. Having a third kid like in the first year is maybe also maybe not a wise idea. But it was like what I wanted and so just going for it and you know, if you just bring that level of intensity to everything, like you can have what you set your mind to.
Zane Knob: Beautiful. Very well said. Thank you Sam Jones, CEO Co Founder at uh, Method Security for joining us in the Brake Line Arena. Thank you audience and listeners and we'll see you next time.
Narrator: Thanks for joining us for this episode of the Brakeline Arena.
Zane Knob: If you're a visionary founder building in a mission driven space and want to learn more about our effects based hiring
Narrator: approach or a purpose driven top performer seeking clarity, community and access to the
Zane Knob: most ambitious companies in America, join us brakeline.org SAM.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.