Breaking
Rick Fitz - CEO & Chairman, Contrast Security Former SVP & GM at Splunk 25+ years enterprise software $274M total funding raised Inside-out application security pioneer Series E company leader University of the Pacific + Golden Gate University MBA SignalFX acquisition architect at Splunk Pleasanton, CA headquarters Rick Fitz - CEO & Chairman, Contrast Security Former SVP & GM at Splunk 25+ years enterprise software $274M total funding raised Inside-out application security pioneer Series E company leader University of the Pacific + Golden Gate University MBA SignalFX acquisition architect at Splunk Pleasanton, CA headquarters
Rick Fitz, CEO of Contrast Security
Profile  /  Enterprise Security

Rick Fitz

CEO & Chairman  |  Contrast Security

The man who helped Splunk buy SignalFX thinks the entire application security industry is solving the wrong problem. And he has a patented sensor inside your apps to prove it.

AppSec CEO Splunk Alumni 25+ Yrs Enterprise San Francisco

Security from the inside out

Most application security tools sit outside the software they're supposed to protect. They scan. They probe. They send requests and wait for responses and catalog everything that looks suspicious. The result, as Rick Fitz has been saying since he took the CEO job at Contrast Security in April 2023, is a pile. A backlog. A queue of thousands of potential issues that developers have neither the time nor the context to triage properly.

Contrast Security plants sensors inside the application. Not scanning from outside - instrumented from within, watching how code actually behaves at runtime. When a vulnerability gets touched, Contrast knows. When production traffic probes a weakness, Contrast sees it first. Fitz describes this as inspecting "from the inside out," and he came to the role specifically because his background made him believe the approach is not incremental - it's a category shift.

He joined Contrast in April 2023 after more than six years running Splunk's IT Operations and Application Development Market Group as SVP and General Manager. Before that, 25-plus years building, selling, and scaling enterprise software. Two degrees - a BS in Computer Engineering from the University of the Pacific, and an MBA from Golden Gate University. The engineering degree came first. That sequence matters: Fitz thinks like an engineer, operates like an executive.

"My background enables me to understand the value of inspecting an application from the inside out, which is why I believe Contrast's unique Shift Smart approach will redefine the market."
- Rick Fitz, on joining Contrast Security as CEO, April 2023
25x ARR growth since 2014
$274M Total funding raised
25+ Years in enterprise software
1000x Cash reserve growth since 2014

Six years at Splunk's growth machine

When Splunk acquired SignalFX in 2019 for $1.05 billion, Rick Fitz was in the room. As SVP and GM of the IT Operations and Application Development Market Group, he owned the division that would integrate the observability platform into Splunk's portfolio. It wasn't just SignalFX - his tenure included multiple acquisitions, each requiring him to manage integration, retain talent, and build go-to-market motion for products that hadn't existed inside Splunk the year before.

The Splunk job was not a simple one. The IT operations and application development market sits at a permanently contested intersection - every major cloud provider, every observability startup, and every legacy monitoring vendor competes there. Fitz had to hold ground on all sides while helping Splunk position for its eventual $28 billion acquisition by Cisco. He left Splunk in 2021, before the Cisco deal closed, having built the division into a significant part of the company's enterprise portfolio.

Battery Ventures' Dharmesh Thakker, who backed Contrast Security, cited Fitz's Splunk track record directly when endorsing his appointment. "Previous experience scaling large software companies" was the phrase used. That is investor-speak for: he has done this before, at a comparable company, and he did it well.

Old Way
🔍
Scan from outside. Generate backlogs. Guess at priority. Slow developers down.
VS
Contrast Way
🔐
Instrument from inside. See real runtime behavior. Know what's actually being attacked.

90 days of listening, then moving fast

On April 10, 2023 - the day he actually started at Contrast, eight days before the press release went out - Rick Fitz made a public commitment. He would spend his first 90 days listening. Customers. Employees. Partners. Industry leaders. He wrote an open letter and published it, describing his intent before he'd done anything else. For a new CEO, that is a specific kind of statement: it signals that the playbook he's running is deliberate, not reactive.

The company he inherited had strong fundamentals. Contrast Security, founded in 2014, had grown its annual recurring revenue 25 times over and expanded its workforce 10-fold. It had raised $274 million in total, including a $150 million Series E in November 2021. The outgoing CEO, Alan Naumann, stayed on as President and board advisor to smooth the transition - an arrangement that said more about Naumann's confidence in Fitz than anything in the press release.

The RSA Conference in San Francisco came two weeks later. Fitz was there, at the Contrast booth, still in his first month. That is where enterprise security deals are made and market positions are publicly staked. Showing up at RSA in week two is not required. It is a choice, and it's the kind of choice that tells you something about how a new CEO is thinking about pace.

His core argument to the market is not new - Contrast has been making it since 2014 - but Fitz brings the Splunk credibility needed to deliver it to CISOs and CIOs who might have dismissed application instrumentation as too complex for their teams. When he says "I've seen what runtime data does for IT operations at scale," he is drawing on six years of watching Splunk customers do exactly that with infrastructure. The extension to application security is, from his perspective, logical.

"When you're using the information you have in a production setting, it allows you to prioritize issues that are worth fixing - things that are potentially either being probed or attacked."
- Rick Fitz, interview with Information Security Media Group, January 2025

AI won't replace the people problem

In January 2025, Fitz sat down with Information Security Media Group and said something that ran against the grain of the moment. Application security, he argued, needs people - not just AI. The vulnerability backlog problem is not purely a data problem. It is a skills problem. Organizations don't have enough security engineers who understand application code deeply enough to triage findings, and no AI model changes the fundamental shortage of human expertise in that gap.

His logic is consistent with his runtime-first philosophy. AI can help process signals, but the signals have to be meaningful in the first place. A scanner that produces 10,000 findings gives AI 10,000 things to categorize. An instrumented application that produces 200 confirmed, runtime-verified vulnerabilities gives AI 200 things to actually fix. The starting material matters. Garbage in, garbage out - even with a large language model sorting the garbage.

Contrast Security offers managed services alongside its platform, precisely because many organizations don't have the staff to run a sophisticated AppSec program independently. Fitz frames this as accelerating security maturity, not a concession to customer weakness. The distinction is subtle but important for an enterprise sales motion: you're not selling a replacement for expertise, you're selling a shortcut to building it.

"Scanning sometimes creates a whole pile or a backlog of things that potentially need to be addressed. Using the runtime to organize that work is very powerful." - Rick Fitz

How you build 25 years of enterprise instincts

1995
Graduated University of the Pacific with a BS in Computer Engineering. Started building enterprise software at a time when "enterprise software" meant installing CDs on Windows NT servers.
2000
Completed MBA from Golden Gate University. Added the business layer to the engineering foundation - a combination that would define his career path from builder to operator to executive.
2015
Joined Splunk as SVP and General Manager of the IT Operations and Application Development Market Group. Begins the work of turning a data platform into a multi-product enterprise company.
2019
Splunk acquires SignalFX for $1.05 billion under his division. Presents with SignalFX CEO Karthik Rau at Splunk .conf19. Appears on Big Data Beard podcast discussing the acquisition strategy.
2021
Departs Splunk after 6+ years building the IT/AppDev market group. Contrast Security raises $150M Series E the same year.
April 2023
Named CEO and Chairman of the Board at Contrast Security. Publishes open letter on day one. Attends RSA Conference in week two.
2024
Named to CRN's Web 150 list of top web security executives. Continues leading Contrast Security's growth in a tightening enterprise security market.
January 2025
Major interview on managing application security vulnerabilities, AI's role in AppSec, and the case for runtime monitoring over static scanning tools.
"I'm an executive leader with strong technical roots."
Open letter to customers, April 2023
"Organizations often struggle to prioritize application security vulnerabilities due to the large volume of potential issues created during development and testing."
Interview, January 2025
"My background enables me to understand the value of inspecting an application from the inside out."
CEO appointment press release, April 2023

Five things worth knowing

01
Contrast Security holds patents on the sensor technology embedded inside applications - the core IP behind Fitz's "inside-out" security philosophy. He didn't build it. He bet his career on it.
02
The company had already grown its cash reserves 1000x since 2014 before Fitz joined. He inherited a fundamentally sound business and an industry-wide credibility problem around AppSec tools.
03
He was at Splunk when it was worth roughly $25B. Cisco bought it for $28B in 2023 - after he'd left. The timing is not a footnote. It explains why he was available to take the Contrast role.
04
His University of the Pacific degree in Computer Engineering (1995) predates Google, Firefox, and the commercial iPhone by over a decade. That's a long view on how software gets built and broken.
05
Outgoing CEO Alan Naumann - who built Contrast from its 2014 founding - stayed on as President and board advisor during the handoff. In the startup world, that kind of structured, cooperative transition is rarer than it sounds and signals genuine confidence in the incoming leader.

The record

  • Named to CRN's Web 150 list of top web security executives (2024)
  • Led Splunk's IT Operations and Application Development Market Group through landmark acquisitions including SignalFX ($1.05B)
  • Appointed CEO and Chairman of the Board at Contrast Security, April 2023
  • Track record of scaling software companies from early stage to $1B+ in revenues
  • Led Contrast Security's continued post-Series-E growth phase ($150M raised, Nov 2021)
  • Over 25 years building enterprise software across the full stack from engineering to executive leadership