Matthew Goodrich — CTO
I've spent my career at the intersection of engineering, product, and security — often literally, having worked all three functions at the same company. That experience has shaped everything about how I approach security: I understand why engineering teams deprioritize security work, because I was one of them. I understand why product teams resist slowing down for security reviews, because I ran one. At Alteryx, I built the product security program from the ground up — starting as one of the first product security hires embedded in the engineering organization, and growing it into a mature function with full SSDLC coverage, OWASP ASVS adoption across the product portfolio, a production PSIRT, threat modeling standards, and a custom remediation tracking tool that improved security issue closure rates by more than 60%. Along the way I've led teams and programs across security architecture, DevSecOps, product security strategy, and GRC — moving deliberately across engineering, product management, and information security organizations based on where security leverage was highest. Today I serve as Chief Security Architect — the only individual contributor on the CISO's direct staff. No direct reports; full strategic scope. My job is making sure security moves at the speed of the business, not the other way around. My conviction is that security is an engineering discipline, not a compliance function. That means writing Python to automate evidence collection, building unified control frameworks that satisfy multiple compliance standards simultaneously, and designing AI governance policies that extend existing security controls rather than creating a parallel bureaucracy. I write about security leadership, product security, GRC engineering, and AI governance at mattgoodrich.com, and have appeared on the CISO Series podcast.
Stackforce AI infers this person is a SaaS security architect with extensive experience in product security and compliance.
Location: Seattle, WA, USA
Experience: 14 yrs 8 mos
Skills
- Information Security
- Governance, Risk Management, And Compliance (grc)
- Product Security
- Application Security
- Product Management
- Cloud Security
- Security Architecture Design
- Identity And Access Management (iam)
- Leadership
- Software Architecture
- Devops
- Network Security
Career Highlights
- Built product security program from the ground up at Alteryx.
- Achieved over 60% improvement in security issue closure rates.
- Serves as Chief Security Architect with strategic influence.
Work Experience
Alteryx
Senior Director, Information Security - Chief Security Architect (1 yr 2 mos)
Director, Product Security & Architecture (2 yrs 6 mos)
Director, Product Security Strategy (3 mos)
Director, DevSecOps (10 mos)
Director, Security Architecture & Engineering (7 mos)
Principal Security Architect (5 mos)
Staff Product Security Engineer (7 mos)
Slalom Consulting
Solutions Architect - Cloud, DevOps, and Security (1 yr 11 mos)
ProofID Ltd
Principal Security Architect, Professional Services (2 yrs 3 mos)
K2
Software Engineering Manager (1 yr 2 mos)
HOSTING
Engineering Technical Lead (1 yr 8 mos)
Seros Inc
Security Engineer (1 yr 4 mos)
Education
Bachelor of Science at Colorado State University