Abnormal AI

Shrivu Shankar - How a $5B Cybersecurity Company Runs on AI Agents

Today's episode is with Shrivu Shankar, VP of AI Strategy at Abnormal AI - a $5B cybersecurity company. What makes this one unique is that Shrivu joined as an intern in 2021 and got promoted every single year until he reached VP, so he's basically watched AI go from a niche engineering tool to something that's reshaping entire companies from the inside.

We get into how AI is catching cyberattacks so sophisticated that even humans can't tell they're fake, how engineers at a $5B company have basically stopped writing code themselves, and what that means for everyone else on the team.

We also go deep on why context engineering is replacing prompt engineering as the real moat, how they used GPT-3 with zero safety guardrails to generate fake phishing attacks as training data, and what it actually takes to become an AI native company at 1,500 people.

One of the most technical and eye-opening conversations I've had. You don't wanna miss this one.

Shrivu Shankar - How a $5B Cybersecurity Company Runs on AI Agents
Episode still: Shrivu Shankar, Abnormal AI

What this episode covers

An operator-level look at agent deployment in cybersecurity, including workflow design, ownership, evaluation, and the organizational patterns behind production AI.

Why this matters in practice

Teams get value from agents when they treat them as owned operational systems with evaluation and feedback—not as isolated demos.

Chapters

  1. 00:00Intro
  2. 00:58Who is Shrivu and what is Abnormal AI
  3. 01:39Why cybersecurity and machine learning
  4. 03:13Intern to VP in 4 years — how it actually happened
  5. 05:44What Abnormal AI does and how it started
  6. 09:10The vendor fraud attack so convincing the victim didn't believe it was real
  7. 10:45What GPT-3 changed for cybersecurity
  8. 13:01Using synthetic data to train models — and how they measured it
  9. 16:49How a 1,500 person company actually adopts AI internally
  10. 19:50How engineering, PM, and platform roles are changing right now
  11. 23:17The biggest AI misconception Shrivu keeps hearing
  12. 27:35What Shrivu's day actually looks like as VP of AI Strategy
  13. 28:53Engineers stopped writing code. Here's what they do instead.
  14. 32:28Why product teams are getting much smaller
  15. 34:31Why context engineering beats prompt engineering
  16. 36:31Spec-driven development and how Nora Tech Plan works
  17. 39:14How to scale context engineering across an entire eng org
  18. 40:30What the manager role looks like in the agent era
  19. 42:17What skills actually matter for managers now
  20. 43:29AI is making orgs flatter. Is that a good thing?
  21. 45:08How the C-suite is getting closer to the work
  22. 46:41What agents actually are and how tool calling works
  23. 48:05How agents improved Abnormal's detection pipeline
  24. 50:56The AI phishing coach — how it works and why it matters
  25. 53:30The internal AI data analyst agent
  26. 56:13Dozens of internal agents — the ones Shrivu is most proud of
  27. 57:15Where agents fail (it's usually not the model)
  28. 58:52What Shrivu would tell a CEO just starting with agents
  29. 01:00:19Sending sensitive security data to LLMs — how they handle it
  30. 01:01:47What becoming AI native actually means in practice
  31. 01:03:37What most people still get wrong about AI in the enterprise
  32. 01:04:31How to write documents with AI without it sounding like AI
  33. 01:06:40Claude Code vs Codex — which one and why
  34. 01:09:27How Shrivu stays ahead and his take on MCPs
  35. 01:11:33How the team uses Claude Code skills
  36. 01:12:47Using hooks for shift-left validation in large codebases
  37. 01:13:42How to manage context in a massive monorepo
  38. 01:14:56Building tool-agnostic rules across Claude, Cursor, and Code Rabbit
  39. 01:16:55Why infra teams are becoming agent harness teams
  40. 01:17:57Wrap up

Key takeaways

  • How cybersecurity changes the AI agent bar
  • Agent ownership and operating rhythm
  • Evaluating AI workflows in production
  • What founders should copy from Abnormal AI
The companies getting value from agents are treating them as operational systems, not demos.

Related topics

More episodes