


Sneha Regmi is the Director of Security Operations and Resilience Engineering at Affirm. She brings more than 13 years of cybersecurity experience building and maturing security programs from the ground up. In addition to her leadership role at Affirm, Sneha is involved as a Limited Partner investor with U&I Ventures, which focuses on early stage startups and technology driven companies solving novel problems. She also serves as a board advisor to Mitiga, an AI-native zero-impact breach prevention security platform that unifies data across cloud, SaaS, AI and identity.
Sneha has spent her career leading through ambiguity and making critical decisions when the stakes are highest. Her foundation in cybersecurity was built in investigations and detection engineering, a domain that demands a sharp investigative mindset and decisive action across all levels of an organization. From managing intense incident situation rooms to navigating executive level communication, she has spent years translating chaotic security events into structured, resilient operations. That experience shaped how she built and matured security operations throughout her career, from leading critical programs at a large e-commerce company, to navigating an IPO at a healthcare technology company, to driving resilience in her current role at a major fintech company.
She developed a philosophy of accountability, transparency and empathy along the way. For the teams Sneha leads, these are not abstract values. They are operating principles that help people stay clear, coordinated, and calm under pressure. In her experience, the same threat can hit two organizations and lead to very different outcomes. The difference often comes down to preparation.
“True operational resilience is not proven on a sunny Tuesday afternoon,” says Sneha. “It is proven when a critical incident hits at two in the morning. When actual firefighters arrive at a fire, they are the most calm people in the room because they know exactly what they are going to do. Our job as security leaders is to bring that same clarity and structured focus to chaotic situations.”
Maturity Is Not a Checklist Exercise
Cybersecurity maturity is often treated as a compliance exercise. Baseline frameworks such as those provided by NIST (National Institute of Standards and Technology) provide structure, accountability, and a foundation. But compliance alignment is a starting point, not a complete security strategy.
True maturity means augmenting baseline frameworks with business context by knowing which technical assets matter most, where the highest risk exposures live, and how an incident could affect production systems and customers. The real engineering work is translating abstract frameworks into capabilities that reduce risk, then testing whether they hold up under pressure. The organizations that handle incidents well are not always the ones with the longest checklists. They understand what matters most, know where the real risks are, and test whether their teams can withstand unexpected events.
The Feedback Loop Most Programs Miss
A common gap in modern security programs is treating prevention, detection, and response as separate domains. When teams own disconnected tools, they operate in parallel instead of as a cohesive system. Incidents must actively inform controls. When a detection fires, teams uncover insight into attacker behavior, visibility gaps, and control failures. That knowledge should feed directly back into detection workflows and prevention architecture.
Credential abuse is a clear example. When an adversary exploits a privileged account, adding more alerts is rarely enough. The incident should push teams to ask what needs to change in prevention posture, whether that means phishing-resistant multi-factor authentication, faster session revocation, tighter access rules, or better detection logic. Without that feedback loop, monitoring only documents failures and does not help reduce the attack surface.
Strong response capabilities matter just as much. Prevention will never be flawless, so business outcomes depend on how quickly a company contains blast radius, communicates clearly, and accelerates decisions. Blameless retrospectives help teams examine failures without judgment and build a culture that performs under pressure.
Once operational readiness is in place, Sneha believes the conversation must turn to human sustainability and protecting the energy and focus of the people doing the work.
“Security Operations has historically asked a lot from people,” Sneha says. “The work can be intense and mentally draining, especially when teams are carrying constant alert volume and still expected to show up sharp for the incidents that really matter. The promise of agentic AI is not just speed. It is giving teams back time and focus, bringing a long awaited Hallelujah moment to the industry. It allows us to automate the exhausting administrative grind so that when a major incident does hit at two in the morning, the responder showing up to lead the situation room is fresh, focused, and ready to solve the problem.”
AI and the Next Operating Model Shift
Embedding agentic AI in security operations represents the next major shift. Organizations must separate the trend into two discussions. The first is AI for security. The second is security for AI.
On the defensive side, AI can help with investigation summaries, alert triage, enrichment, reporting support, and repetitive workflow assistance. But the larger opportunity is to rethink the operating model itself. Over time, AI can help teams move toward agentic workflows, where lower risk tasks are automated and humans focus on judgment, context, and business risk.
But this shift has to be deliberate. Security teams cannot automate simply because the technology can. They need confidence thresholds, validation mechanisms, escalation paths, risk boundaries, and ways to detect when AI output is incomplete, uncertain, or wrong. A low risk enrichment step may be a good candidate for automation. A containment action that could disrupt production requires a much higher bar. The better question is what confidence we need before letting AI take action, how we validate its recommendation, and when a human should stay in the loop.
This trajectory mirrors what many security operations teams experienced with SOAR (Security Orchestration, Automation, and Response) platforms. Most organizations did not begin by fully automating complex response workflows. They started with enrichment, repeatable playbooks, and lower risk actions. Over time, as confidence grew, they expanded automation into more sophisticated workflows with human review at the right decision points. Agentic AI adoption in SecOps should follow the same pattern. Start where the risk is lower, measure quality, build trust, and expand only when the process is reliable.
The other side of the conversation is security for AI. As companies adopt AI across engineering and business workflows, policies and awareness training are necessary, but they are not enough. Security teams need visibility into how AI is being used, what data is flowing through these systems, which tools are approved, and where sensitive business context may be exposed.
The most effective approach is to partner early with engineering and product teams. That may include centralized AI gateways, Model Context Protocol gateways, secure development patterns, configuration checks, logging, access controls, and scalable enforcement through enterprise platforms. The specific architecture will vary by company, but the principle is the same. Security has to be built alongside AI adoption, not added after the fact.
Building Programs That Hold
Ultimately, resilient security programs are built by people, not tools. Frameworks, controls, automation, and AI all matter, but they only work when teams understand the business, communicate clearly, learn from incidents, and know where human judgment still matters most. Effective security leadership requires both technical depth and operational judgment.
Like the firefighters she describes, the best security leaders arrive calm because they prepared before the alarm went off. The tools will continue to change. Adversaries will continue to adapt. What stays constant is the need for programs, and people, built to hold when it matters most.