Jon Oltsik
Principal Analyst in Residence · theCUBE Research
Position Evolution
3 tracked across this operator's appearancesSame operator, on the record, on the same topic, at different points in time. Each delta below is anchored to verbatim transcript spans verified against source — no paraphrases. This is the alumni-graph moat: SemiAnalysis cannot reproduce this query because they don't have the speaker-stable corpus.
AI governance as security foundation
Hardenedconfidence 82%In June 2026, Oltsik flagged AI security as a new requirement needing new skills and tools. By July 2026, he had moved from identifying the need to prescribing a concrete governance-first action plan, including stakeholder alignment, policy formation, and vendor evaluation. The shift from 'it's a requirement' to a step-by-step CISO playbook signals growing conviction and operational specificity.
"Not only do we have to have secure cloud development, but we have to have secure AI development. And that may involve some new skill sets, some new tools, but it's a requirement."
Source on theCUBE ↗"So the first thing that I would do is I'd get all of the stakeholders in place and if you don't have strong governance, build strong governance. Now a lot of that starts with what are we trying to do here? So no one's going to play... Well, developers will play with AI, but if I'm a CEO, I'm going to say, well, what's the business value here?"
Source on theCUBE ↗Security-developer integration imperative
Shiftedconfidence 78%Earlier, Oltsik framed security-developer cooperation as a mutual benefit story centered on reducing conflict and improving application quality. By RSAC 2026, the framing had shifted to managing developer enthusiasm for AI specifically, emphasizing guidance and training over collaboration as equals. The tone moves from partnership to gentle oversight, reflecting the new risks AI-assisted development introduces.
"The more those two groups are working in parallel or cooperatively instead of in conflict, the better for security, the better for the organization. We'll get better applications, more secure applications, and we'll mitigate risk."
Source on theCUBE ↗"And we have to start with training our developers, training consumers, because this is a new world. And so from a security point, yeah, training about things like prompt injection and sharing confidential data, certainly. But the developers, this is a playground for them. So we have to put some, maybe not guardrails, but some guidance for them."
Source on theCUBE ↗Vendor landscape openness for AI security
Shiftedconfidence 75%In June 2026, Oltsik's vendor advice was implicitly conservative — use tools to enforce existing frameworks and policies. By July 2026, he was actively warning CISOs not to default to incumbent vendors and to cast a wide net for AI security solutions. This is a meaningful reorientation from framework-enforcement tooling toward market disruption awareness, driven by the pace of AI innovation.
"So it starts with the policy and the framework, and then it's applying those policies and frameworks and then it's monitoring those policies and frameworks. Now, there are often a lot of tools to do that, but the key is being able to again catch those policy violations."
Source on theCUBE ↗"What I'm saying and what I'm seeing proactive CISOs do, cast a wide net because the history, historically strong vendors may not have the best solution for you. And there's a lot of innovation. A lot of it's going to fall on its face. You and I have seen this a million times in the industry, but someone's going to come through and have a revolutionary or at least a very good evolutionary platform for AI and security. So be open-minded."
Source on theCUBE ↗All theCUBE appearances (9)
RSAC Conference 2025 | Roger Grimes, KnowBe4
GUEST
RSAC Conference 2025 | Day 2, RSAC AnalystANGLE
GUEST · theCUBE Research · Principal Analyst in Residence
RSAC Conference 2025 | John Sapp, Texas Mutual Insurance & Company
GUEST
RSAC Conference 2025 | Markus Ludwig, ticura
HOST
RSAC Conference 2025 | AnalystANGLE
HOST · theCUBE Research · Principal Analyst in Residence
RSAC 2026 Conference | RSAC Show Wrap
GUEST · theCUBE Research · Principal Analyst in Residence
RSAC 2026 Conference
GUEST · theCUBE Research · Principal Analyst in Residence
RSAC 2026 Conference
GUEST · theCUBE Research · Principal Analyst in Residence
AppDev Done Right Summit | Research Spotlight - DevSecOps: Security by Design
GUEST · theCUBE Research · Principal Analyst in Residence