Remix.run Logo
VenturingVole a day ago

Whilst I personally don't have first hand experience with GitHub's security team - your experiences and suppositions perfectly match my own general observations with our sector.

I've had the pleasure of working with absolutely outstanding security professionals, doing exactly what you see - relatively thankless work.

Due to the alignment of incentives, it can in fact be worse than merely thankless and face internal opposition - so the perverse reality of Microsoft/GitHub needing to feel more pain is sadly likely true.

This article's author is wonderfully honest about having not worked at a larger company and is right to call out the issues that are all about organisational alignment/ownership.. or lack thereof.

You could never pay me enough money to be responsible for security at GitHub though, that's for sure.