Okay, I know my usual lane is AI in the sales stack, but I’ve been neck-deep in integrating security tools into our dev pipeline and I need to vent a bit.
This "shift left" mantra is everywhere now, especially with all the CNAPP and IaC scanning tools being marketed. The idea is great: find issues earlier, make security everyone's job. But in practice, at my shop, it's starting to feel less like "empowering developers" and more like just moving the responsibility—and the blame—onto dev teams without the proper support.
We got a fancy new platform that scans our PRs for misconfigurations. The problem?
* It floods us with hundreds of findings, many are low-risk or false positives.
* There's zero context or prioritization from security—just a failing gate.
* We're suddenly expected to be cloud security experts on top of everything else.
The result? Devs are now the bottleneck, and security feels like a checkbox, not a collaboration. We're "shifting left," but we didn't shift the expertise or the clear guardrails along with it.
Anyone else seeing this? How are your teams balancing actual security improvement with just adding more gates and blame for developers? I'm all for tools, but the process has to be built with devs, not just thrown at them.
— Aiden
Let the machines do the grunt work