Max Moroz

CEO

Mountain View, California, United States16 yrs 4 mos experience
Highly StableAI Enabled

Key Highlights

  • Secured platforms for over 1 billion users.
  • Scaled security teams from 3 to 40 members.
  • Revamped Bug Bounty program, doubling valid reports.
Stackforce AI infers this person is a Cybersecurity expert with extensive experience in securing large-scale platforms.

Contact

Skills

Core Skills

Security EngineeringTeam ManagementInformation SecuritySoftware EngineeringVulnerability ResearchQuality AssuranceSoftware Development

Other Skills

Product SecurityInfrastructure SecurityCross-functional AlignmentSecurity AssuranceBug BountyIncident ResponseAI SecurityOSS-FuzzFuzzingChrome SecurityCode CoverageSecurity VulnerabilitiesWi-Fi SecurityVPN ServiceQA Automation

About

Highly technical security engineering leader with a proven track record of securing large-scale systems (1+ billion users), hiring and developing high-performing teams, driving cross-functional alignment, managing security and privacy risks, and navigating complex regulatory environments.

Experience

16 yrs 4 mos
Total Experience
2 yrs 8 mos
Average Tenure
2 mos
Current Experience

Instacart

Head of Product Security, Director of Security Engineering

Mar 2026Present · 2 mos

  • Product and Infrastructure Security for Instacart (NASDAQ:CART) and affiliates worldwide.
Product SecurityInfrastructure SecuritySecurity EngineeringTeam Management

Bytedance

Head of Security Assurance, Director of Security Engineering

Nov 2020Mar 2026 · 5 yrs 4 mos · Сан-Хосе, CA

  • Defined the vision and owned the execution of the security engineering strategy for all of TikTok's global platforms (Short Video, LIVE, Local Services, Lemon8), protecting over 1+ billion users across 150+ countries.
  • Scaled a world-class, multidisciplinary, global security organization from 3 to 40 people across Product Security, Red Team, Infrastructure Security, Detection & Response, and Governance.
  • Drove a secure-by-design culture shift across a X,000-person R&D organization by embedding automated security controls and tooling into the SDLC, improving developer velocity and enabling teams to build safer products faster.
  • Revamped Bug Bounty program, resulting in 2x growth of valid reports. Streamlined incident response and optimized third party risk management to reduce losses for the business.
  • As Security BP, improved ByteDance's security and privacy posture with regulators and external partners, addressing government concerns and enabling business deals.
  • Co-authored the A2AS standard, proposing a framework for protecting agentic AI systems.
Security EngineeringCross-functional AlignmentSecurity AssuranceTeam ManagementBug BountyIncident Response+1

Google

Information Security Engineer, Team Lead

Nov 2015Nov 2020 · 5 yrs · Mountain View, California

  • Led OSS-Fuzz adoption and external outreach, reporting 20,000 bugs in 350+ popular open source projects, including OpenSSL, TensorFlow, ffmpeg, and others.
  • Built Chrome's first ever code coverage pipeline–previously deemed impossible due to the codebase complexity. Gained leadership buy-in and made complex changes across multiple codebases, including 20x optimizations in LLVM and architectural changes in Chrome. Post-launch, successfully transitioned the project to a newly funded 3-person team.
  • Optimized the Chrome security review process after surveying 50+ SWE and PM colleagues. Established and enforced SLAs for reviews and expanded the pool of reviewers from 5 to 18.
  • Drove fuzzing adoption in Chrome (scaled to 600 fuzzers and discovered 4,000 bugs). Mobilized 500+ SWEs across Android, Core and Cloud to write fuzzers, identify and fix security flaws.
  • Collaborated with Google Project Zero on Variant Analysis for Chrome browser and research projects (e.g. the UXSS paper).
  • Core developer of ClusterFuzz, a distributed fuzzing system running on 30,000 CPUs, and FuzzedDataProvider (part of Clang), a widely used interface for deterministic multi-input fuzzing.
OSS-FuzzFuzzingChrome SecurityCode CoverageIncident ResponseInformation Security+1

Synack red team

Security Researcher

Mar 2015May 2017 · 2 yrs 2 mos

  • Vulnerability Research, invite-only Bug Bounty programs
Vulnerability ResearchBug Bounty

Avuln

CEO, co-founder

Dec 2014Nov 2015 · 11 mos

  • Identified security vulnerabilities and risks in products and networks for banks and an international media company, reporting findings to CTO-/CIO-level clients.
  • Developed a secure Wi-Fi router prototype for smart homes: AVULNATOR (demo: https://vimeo.com/132646597).
  • Launched a fully automated and scalable paid VPN service with 100+ monthly active users.
  • Research blog: https://blog.avuln.com/
  • The company is not active at the moment.
Security VulnerabilitiesWi-Fi SecurityVPN ServiceSecurity Engineering

Актив (aktiv co.)

2 roles

Deputy Head of Testing Department

Aug 2014Feb 2015 · 6 mos

  • QA automation
  • Optimization of testing infrastructure
  • Staff recruiting & training
QA AutomationTesting InfrastructureQuality Assurance

Software Developer

Jun 2012Aug 2014 · 2 yrs 2 mos

  • Multi-platform middleware for usb-tokens and smart cards
  • Mobile applications and libraries (iOS, Android)
  • Continuous integration tuning
Middleware DevelopmentMobile ApplicationsSoftware Development

Intel corporation

Intern Software Developer

Jun 2011Jun 2012 · 1 yr

  • Development of video coding and image processing algorithms:
  • H.265 (HEVC) implementation
  • Performance optimization of existing video encoders
  • Color space converter development
Video CodingImage ProcessingSoftware Development

Microsoft

Microsoft Student Partner

Jan 2010Jan 2012 · 2 yrs

  • Member of Microsoft Student Partner program
  • Learning Microsoft products and evangelism among students
  • Imagine Cup participation
  • Events organization
Microsoft ProductsEvent Organization

Education

USC Gould School of Law

Master's degree — Law

National Research Nuclear University MEPhI (Moscow Engineering Physics Institute)

Master's degree — Computer and Information Systems Security / Information Assurance

Stanford University Graduate School of Business

Executive Education

Stackforce found 100+ more professionals with Security Engineering & Team Management

Explore similar profiles based on matching skills and experience