A cloud-security dashboard is a gifted tattletale. It can point to the public bucket, the extravagant permission and the unpatched workload, then present the lot in red. Its manners deteriorate at precisely the moment somebody asks what to do next. The answer usually involves an engineer, a ticket, several meetings and a nervous pause before anyone changes production. Marina Segal has spent much of her career in that pause.
Segal is the CEO and co-founder of Tamnoon, a Seattle-area company devoted to the work after detection. Its premise is plain enough to survive the thicket of cloud-security initials: finding a problem and safely fixing it are different jobs. Modern tools have industrialized the first. The second still depends on context - who owns the resource, what relies on it, whether it is in production and what might snap if the obvious fix is applied.
Her route to this conclusion runs through more than two decades of consulting, governance, enterprise security and product management. She worked at Deloitte, managed security inside technology companies, helped build cloud-security products at Dome9 and Check Point, and later directed product work at Sysdig. Each stop sharpened the same irritation. Visibility improved. Alerts multiplied. Remediation remained the part everyone admired from a safe distance.
“We wanted to finish what everybody just started.”Marina Segal, on Tamnoon’s purpose
When the alarm works, but the house still smokes
At Dome9, Segal worked with Idan Perez and Zohar Alon, who would become her Tamnoon co-founders. Dome9 was an early builder in cloud security posture management, the practice of continuously checking cloud environments for risky configurations. Check Point acquired the company in 2018. The trio had helped make the cloud legible, but legibility produced its own operational bill.
Segal describes three pressures that kept recurring. The number of cloud protection platforms outpaced the people available to operate them. Automated actions lacked business context, so a technically correct change could still be ruinous. And manual remediation was slow, expensive and liable to annoy the engineering team that had to execute it. The scanner's red badge might be accurate while its proposed fix remained dangerously naive.
There is a broad founder's lesson in this. Markets lavish attention on the front of a workflow. The first step is easy to demonstrate, easy to count and pleasant to place in a screenshot. Value often accumulates farther along, in the tedious handoff where software meets an organization. Segal followed the cloud alert beyond the demo and found a business hiding in its unfinished consequences.
The product began with sleeves rolled up
Tamnoon did not begin by disappearing into a room to build a gleaming platform. Segal has said the company provided a service before it had a complete product. The first months were hands-on: listen to customers, examine real alerts, learn which information changed a decision and discover how much caution production deserved. Then came months of calls to validate the company and product roadmaps.
This sequence looks inefficient only if learning is excluded from the calculation. A human expert remediating an actual environment encounters the tacit checks that a requirements document misses. Is this resource tagged properly? Does the nominal owner still own it? Is the proposed change reversible? Would closing a port protect the system or merely prevent customers from using it? Every awkward case becomes design material.
The neglected half of the cloud-security loop
The approach also changed Tamnoon's relationship with early buyers. Segal reached beyond close friends and warm introductions. One early customer came through someone she had known only during a short project years before. The connection looked too faint to be useful, which was exactly why the result stayed with her. People are often willing to hear a thoughtful story if a founder is willing to ask without ceremony.
When a workflow depends on judgment, perform it manually before automating it. The exceptions are not noise. They are the product specification.
Trust is a control system, not a mood
Segal's view of automation is refreshingly conditional. Software is well suited to gathering evidence, correlating alerts, removing duplicates, drafting remediation plans and repeating actions that have earned confidence. A person remains valuable when the environment is unfamiliar, the proposed change has a large blast radius or the available evidence is thin. The interesting design problem is deciding where that boundary sits, then moving it carefully as the system learns.
Tamnoon calls its AI agent Tami. The wider model pairs machine-scale investigation with cloud experts who validate ambiguous or risky decisions. Its purpose is not to decorate managed services with a chatbot. It is to make scarce expertise stretch further without pretending expertise has become unnecessary. The product must know when it knows enough to act and when it needs another pair of eyes.
That philosophy gave Segal an unusually sober AI story at a moment when autonomy was being handed out like conference tote bags. Tamnoon's longer-term destination is still ambitious: Level 5 autonomy for known, repeatable remediation patterns, with minimal human intervention. Yet the path matters as much as the label. Proven actions graduate toward automation. Novel problems and consequential changes keep human attention.
In other words, trust becomes operational. It can be expressed through evidence, confidence scores, approval thresholds, audit trails and reversible steps. This is useful beyond security. Any AI system touching money, customers or production should have an explicit theory of when it may act. “The model seemed confident” is not a control. It is the beginning of an incident report.
Governance met product, and neither escaped unchanged
Segal's education at Tel Aviv University combined information systems and management with an MBA focused on technology, innovation and entrepreneurship. Her early professional years at Deloitte revolved around governance, risk, compliance and enterprise systems. Later roles at GetInsured and Credit Karma put her inside the organizations expected to live with security policy, not merely recommend it.
That range is visible in Tamnoon's design. Security people may see a serious exposure. Engineers may see a fragile production dependency. A compliance team may see evidence that must be retained. Leadership may see a risk decision with a budget attached. The fix has to survive all four perspectives. Segal's career crossed those boundaries before her company made them its product surface.
Former colleagues describe her as methodical and organized, someone who can deliver against tight timelines without surrendering quality. Her own public comments are more playful. Asked for a favorite Tamnoon memory, she chose the satisfaction of solving serious customer exposures, then added team offsites. It is a tidy pairing: work solved, people together, perhaps a dashboard allowed to sulk alone for the evening.
A security company without the apocalypse palette
Tamnoon also made a small but revealing aesthetic rebellion. Cybersecurity favors black backgrounds, red warnings and hooded silhouettes. Segal's team chose green and a positive message. The company wanted to look like the part of security where a problem gets solved, not another vendor arriving with fresh reasons to panic. The visual choice supports the operating model: Tamnoon aims to act as an extension of a customer's team, not a machine that tosses more alerts over the wall.
The human emphasis extends to Segal's community work. She serves on the board of the Cloud Security Alliance's Seattle chapter and has founded women-in-security meetup communities in the Bay Area. Public conversations about her founder journey repeatedly return to mentorship, persistence and creating visible success stories for the next generation. These are practical network effects. A field short of experienced people cannot afford to make belonging needlessly difficult.
Her advice on fundraising carries the same preference for clarity. A company is either raising or it is not. When Tamnoon was not, Segal preferred customer conversations to ambient investor courtship. The rule guards the scarcest resource in an early company: concentrated attention. In September 2024, that focus culminated in a $12 million Series A led by Bright Pixel Capital, with Tamnoon reporting more than $18 million raised in total.
“You can be either raising or not raising.”Segal on protecting a founder’s focus
The destination is a smaller queue
Tamnoon's recent direction pushes beyond remediation into prevention. If a system understands how a misconfiguration was introduced and how a safe fix behaves, it may be able to stop the next version before it enters production. Segal has also written about expanding partnerships across the cloud-security ecosystem and bringing environment-specific agent skills to more teams and industries.
The sharper aspiration is not an empty dashboard at any cost. Segal defines the goal around the critical risks that matter to a particular organization. A sandbox error and a production-path exposure may look identical in a generic queue. Context separates an interesting finding from an urgent one. Zero critical backlog is therefore less a slogan than an agreement about what deserves to interrupt the day.
This is where Segal's story lands: at the stubborn distance between information and outcome. Her career helped build systems that could see the cloud clearly. Her company is an argument that seeing should create an obligation to finish. The wrench may never photograph as well as the alarm, but when the loose screw is in production, everyone eventually learns which tool matters.