Security at Slack: A Team Built on Diverse Paths

Slack’s approach to security is rooted in a workforce that doesn’t fit a single mold. Within the company’s Security organization, nearly a third of employees identify as women, and women make up more than a third of its leadership. The team’s composition reflects a broader cultural commitment to inclusion, but the stories of the individuals themselves reveal something more specific: how varied technical and non-technical backgrounds converge to build a stronger security practice.

The Product Security Structure

Slack’s Product Security team is embedded with development teams to ensure secure product-building practices are standard. Their work spans the development lifecycle, from building components for complex security problems to deploying detection tools and delivering customized developer training.

Two years ago, the team split into two distinct groups with complementary mandates:

  • ProdSec Classic (PSC): Focused on traditional application security, this team performs security reviews of new features, runs static and dynamic scanning, coordinates penetration tests, manages the bug bounty program, and provides frameworks for vulnerability detection and secure development lifecycle improvements.
  • ProdSec Foundations (PSF): A newer team with backend engineering capabilities, PSF aims to “future proof” the platform against entire classes of vulnerabilities by building secure-by-default services, libraries, and tools.

The Product Security Foundations team has delivered several projects with measurable impact on the platform’s resilience:

  • Image Processing Service: A new service designed to isolate production data and infrastructure from vulnerabilities in image processing libraries while improving upload performance, reliability, and security.
  • lib_crypto: A “misuse resistant” cryptography library for Slack’s backend. PHP exposes low-level interfaces requiring callers to specify potentially confusing security parameters; this library addresses that by using strictly typed input and output objects.
  • HTML Sanitizer: Protects against cross-site scripting by sanitizing HTML for unfurled links. This library is open source and available on the public SlackHQ repository.
  • Log Canary: Automatically detects and alerts on accidental logging of tokens and sensitive data such as message content, channel names, or file names.

Current team priorities include authentication hardening, malware detection and prevention, and Kubernetes hardening.

From Engineer to Leader

Nikki Brandt, Engineering Manager for Product Security Classic, was initially interviewed for a management role but was told directly by then-CSO Geoff Belknap that she lacked the management experience for the position. She joined as an engineer instead.

Before Slack, Brandt worked as a consultant moving between Bay Area tech companies, which gave her an unusual vantage point on organizational culture. What stood out at Slack was transparency and the absence of silos across the engineering organization. Within a year, she owned the security review process. Soon after, a management role opened that allowed her to retain technical responsibilities while developing people-leading skills.

Brandt spent 18 months in that hybrid role before moving into full-time management at the start of 2020. She credits the support network through her transition: leadership, particularly Larkin Ryder and Suzanna Khatchatrian, and seeing other women successfully shift from individual contributor to engineering manager.

Career Pivots Supported from Within

Lauren Rubin joined Slack in 2016 as a Senior Technical Recruiter, hiring across Engineering teams including Security. Eighteen months later, she became the company’s first Technical Program Manager for Security—a move enabled by Slack’s internal mobility culture and the Security leadership team itself.

The support was practical, not just symbolic. While pregnant with her first daughter, Rubin was encouraged to step away from day-to-day duties to attend a security bootcamp program. That foundational knowledge aided her work as a Senior Technical Program Manager, where she has helped define and implement programs around incident management streamlining, technology hygiene and end-of-life technologies, QBR vendor reviews, Hacktober security awareness, bug bounty coordination, vulnerability patching, JIRA optimization, and security tooling proof-of-concept evaluations.

Vivienne Pustell, a Senior Risk & Compliance Engineer, came to tech from teaching—and brought a teacher’s instinct for continuous learning. At Slack, she found that formal education was not merely permitted but encouraged, even when it wasn’t directly tied to her role. As her technical knowledge deepened, Pustell began working with more cross-functional teams and providing more technical leadership internally. In 2019, she enrolled in a part-time software engineering bootcamp, with her team backing her journey and letting her apply new skills at work before the program ended.

For Pustell, career growth isn’t about which classes you take; it’s about the enabling environment. “The most important thing to have in a career is the chance to grow,” she says, noting she’s been supported in learning through in-house training, on-the-job collaboration, and external courses.

Building First, Then Breaking

Carly Robinson, a Senior Security Software Engineer, took a deliberate path into security. After graduating from Hackbright in 2015, she wanted to learn how to build systems before learning how to break them. That decision led to four years as a backend application engineer working across Enterprise, Platform, Operations, and Infrastructure pillars, using PHP/Hack, JavaScript/TypeScript, and Go, designing billing systems and public-facing admin APIs, wrangling Terraform to provision AWS infrastructure, and configuring Thanos to scale Prometheus metrics across a fleet of servers.

Last October, a coworker sent her a link to an opening on the Product Security Foundations team. The group focused on building secure-by-default tooling and was led by an entirely female management team. The opportunity combined her building background with the chance to learn offensive security thinking, and she moved into that role. In ten months, the team has refactored a tool for monitoring Slack’s AWS operations, launched an education program for software developers, built testing for Slack Authentication systems, and led adoption of its secure-by-default libraries.

Robinson highlights the team’s emphasis on knowledge-sharing among people with unconventional career paths in security. That mix of experience, she says, is a meaningful asset for the work itself.

Slack’s Security organization is actively hiring across Product Security, Security Operations, and Risk & Compliance. Open roles are listed at slack.com/careers.