Ankur Shah has spent much of his career arriving just as the map of enterprise computing needs to be redrawn. First came communications and mobile software. Then data escaped the office and moved into cloud services. Later, applications themselves became cloud-native, assembled from containers, code repositories and infrastructure that could change by the minute. Each transition created a familiar lag: builders reached the new territory first, while security teams tried to stretch old controls across unfamiliar ground.
Now the boundary is moving again. AI software is becoming less like a reference desk and more like a junior operator. It can retrieve a document, open a tool, write code, schedule a meeting or follow a chain of instructions. The useful part is agency. The dangerous part is also agency. Shah's latest company, Straiker, begins with that symmetry.
His bet is that the unit to protect is no longer only a model, prompt or application. It is a sequence of behavior. Which agent is running? What can it reach? Who instructed it? What did it do next? Those questions sound procedural because they are. The future Shah describes is not a distant philosophical argument. It is a set of permissions, tool calls and consequences inside an enterprise.
“The realization came when AI moved from generating content to taking actions.”Ankur Shah, 2026
A filter built before the wave
There is an old clue to how Shah chooses problems. In 2017, while explaining why he had left CipherCloud for the young cloud security company RedLock, he published a simple filter: market, product, people. The market had to contain a large, explicit need. The product had to reveal its value quickly. The people had to be capable, committed and prepared for the emotional range of an early-stage company.
It was practical founder logic from someone who was not yet a CEO-founder. Shah had started in engineering and moved through enterprise communications and product roles at Orative, Cisco, Citrix and Symantec. At CipherCloud, he worked on the then-new problem of controlling data inside cloud applications. He thanked CipherCloud founder Pravin Kothari as a mentor and wrote candidly about the “roller coaster” of company building. The point was not romance. Startups, he argued, reward people willing to push through long low periods.
RedLock fit his filter. Public cloud use was accelerating, the security market remained unsettled, and a purpose-built product could show customers value without a sprawling deployment. Palo Alto Networks acquired RedLock in 2018. Its technology became a foundation for Prisma Cloud, and Shah stayed to help turn an early product into a platform.
Engineering and product work across enterprise communications, mobile software and collaboration.
Cloud access security and SaaS encryption product leadership at CipherCloud.
RedLock becomes part of Palo Alto Networks; Prisma Cloud grows into a code-to-cloud platform.
Co-founds Straiker with Sreenath Kurupati to discover, test and protect enterprise AI agents.
What scale taught him
At Palo Alto Networks, Shah eventually served as senior vice president and general manager of Prisma Cloud. He oversaw more than 1,000 people across engineering, product and customer success. Over five years, the business expanded from one module to a broad cloud-native application protection platform and grew revenue 50-fold. Those numbers describe scale. The more important lesson for Straiker is architectural.
When a new computing model appears, security often arrives as a feature bolted to an existing system. That may work for a while. Then the differences compound. Cloud infrastructure changed too quickly and sprawled too widely for traditional data-center controls. A platform category formed around the new reality. Shah believes AI agents are following the same route, only faster.
This is the founder's advantage of having operated both ends of the company curve. Shah has seen a compact product become a large organization, and he knows what gets lost between the whiteboard and the installed base. He also knows platform is an earned word. A company earns it by covering a workflow customers cannot afford to split into disconnected fragments.
Three verbs for an unruly system
Straiker reduces its pitch to three verbs: discover, test and protect. Discover AI inventories agents, model connections, tools and data sources. Ascend AI attacks agents before deployment, looking for ways they can be manipulated or pushed into unsafe behavior. Defend AI watches agentic workflows at runtime, tracing activity and blocking threats as events unfold.
The sequence is useful because no single control can carry the whole job. A company cannot test an agent it does not know exists. A successful pre-launch test cannot predict every interaction in production. Runtime detection improves when it absorbs attacks found during testing, while testing improves when it learns from real behavior. The loop, not any individual feature, is the product thesis.
Shah's language makes agents sound less like conventional software and more like co-workers with credentials. They can have broad scope, unclear provenance and a habit of chaining actions together. A harmless request can become risky several steps later. Security therefore has to interpret behavioral signals across a session rather than scan one prompt for a suspicious phrase.
Visibility before policy. Map agents, tools and connected data before deciding what “safe” means. Then test real chains of behavior and keep the runtime review close enough to act.
The optimist who reviews the output
Cybersecurity can turn every conversation into a forecast of ruin. Shah resists that posture. He calls himself a technology optimist and frames AI as a force multiplier. In his view, experienced people should use the tools while retaining responsibility for review. An agent might produce much of a first draft, but the most experienced engineer should still examine what ships.
The distinction matters because Straiker is not built around stopping AI adoption. Its commercial purpose depends on customers deploying more capable systems. Shah's preferred future has builders moving quickly and security giving them credible room to move. “We want customers to build the future so we can help secure it,” he said in a long-form interview.
His curiosity is not confined to the executive layer. While leading Straiker, he picked up coding again with AI tools. His son was learning Python, and Shah joked that he needed to learn faster. The anecdote carries a useful admission: the rules have changed enough that experience alone is insufficient. He once compared entering AI security to discovering he was no longer playing cricket but baseball. The field looked familiar. The mechanics demanded first-principles learning.
“We should think about this as a positive sum, not a zero-sum game.”Ankur Shah at the 2026 SC Awards
A company catches its moment
Straiker launched publicly in 2025. By June 2026, it said run-rate revenue had grown more than 15 times in under a year. The company announced a $64 million Series A led by Marathon Management Partners with Citi Ventures, Illuminate Financial and Workday Ventures, alongside continued support from Bain Capital Ventures and Lightspeed. Total reported funding reached $85 million.
Shah said demand had outpaced forecasts and directed the new capital toward product, the company's STAR Labs threat research and international expansion pulled by enterprise customers. It is a telling allocation. Product deepens the loop. Research expands the library of how agents fail. Global expansion follows the customers already asking for help.
The speed attracts attention, but Shah's older writing supplies the better lens. A startup still needs a real market, a product that proves itself quickly and people prepared for the grind. The nouns around him have changed from cloud workloads to autonomous actors. The filter has not.
What remains human
Shah received the 2026 SC Award for Security Executive of the Year, recognition that included not only product growth but his record of developing people. The award account described his support for emerging leaders whose work reached efforts such as the OWASP Agentic AI Top 10 and Women in CyberSecurity. It is a quiet counterweight to the popular image of an AI company as a handful of people delegating everything to machines.
Away from product diagrams, his answers loosen. Asked what made him proud beyond social media, Shah named his family and children. Asked about life outside AI security, he talked about learning to code alongside his son. Asked about food, he chose Indian cuisine and offered a short tour of Bay Area restaurants. These are small details, but they clarify the ambition: automation is interesting because people have better things to do, not because people are incidental.
Straiker's challenge is now the one Shah has spent years preparing to meet. It must turn early category insight into a durable platform without losing the fast feedback that made the insight useful. Agents will keep changing. Their tools, permissions and attack paths will change with them. The security system must learn at the same pace.
For Shah, that is less a reason for panic than a reason to build. The career pattern is clear: follow the new computing model, identify where the inherited controls stop working, and assemble the missing layer. This time, the software on the other side can act. So can he.