Profile Engineer → strategist → founder Kubescape joined CNCF Incubation Open source, runtime context and a 5 a.m. surf

People / Cloud Security / Open Source

Shauli Rozen Put Kubernetes Security in the Hands of the People Who Ship It

The ARMO co-founder took a winding route from compression code to the boardroom, then bet that cloud security would work better if developers could inspect it, try it and shape it themselves.

Before cloud security became a forest of acronyms, Shauli Rozen wrote compression software. This was the era before smartphones smoothed away the rough edges of mobile media, when moving a picture between devices could require an engineer to worry about formats, sizes and transcoding. Rozen has recalled that work with the faint amusement of someone describing an extinct household appliance. It also gave him a durable professional instinct: complex machinery is only useful when it disappears behind an outcome a person can understand.

That instinct followed him through a career that looks, at first glance, delightfully incapable of sitting still. He studied communication systems engineering at Ben-Gurion University, moved into product work, crossed the Atlantic for an MBA at Wharton, tried management consulting, returned to Israel and took strategy roles at Amdocs and Optimove. By the time he co-founded ARMO, he could speak several corporate dialects: the precision of engineering, the abstractions of strategy, the impatience of a customer and the hopeful grammar of a startup.

Rozen has a compact name for this progression: “an engineer turned businessman turned entrepreneur.” The phrase implies three transformations, but his work suggests accumulation instead. The engineer still wants evidence. The businessman asks who receives value. The entrepreneur wonders whether the whole exchange can happen faster.

“I have always been looking to diversify and do and learn new things.”Shauli Rozen

The scenic route had a destination

At Wharton, Rozen studied finance and strategic management and co-led the school’s Israel club. Consulting at Boston Consulting Group sharpened the habit of taking a complicated organization apart and finding where a decision could matter. Amdocs gave him product strategy at scale. Optimove, where he became chief strategy officer and general manager, supplied a lesson he now repeats with the firmness of a useful warning: you are not building a product for yourself.

This is more subtle than the standard instruction to “listen to customers.” Engineers building for engineers can still confuse familiarity with empathy. They know how a system was made, which means they naturally admire the mechanism. A user arrives with a job to finish and no obligation to admire anything. Rozen learned to move between those chairs. His career’s apparent zigzag becomes coherent when viewed as practice in perspective.

He met Ben Hirschberg, the technical co-founder who would become ARMO’s CTO, and tells the origin with endearing self-demotion. Hirschberg, he says, is brilliant - “much more brilliant than I am” - and had the idea that set the company in motion. Leonid Sandler joined them as a co-founder. The trio began with a conviction that Kubernetes security needed to account for a system whose moving parts, permissions and services multiply faster than a neat diagram can contain them.

Two years of looking, two weeks of moving

The first version of the answer was not the final one. Rozen has described roughly two years spent discovering how companies were adopting Kubernetes and what they actually needed. The market was not yet ready for the original security proposition. Teams had more immediate problems around visibility, configuration and posture. So ARMO made a sharp move. In about two weeks, it prepared and released Kubescape as an open-source Kubernetes security tool in 2021.

The launch put the product where its intended users already lived: on GitHub, in command lines and inside workflows they controlled. A DevOps engineer did not have to accept a brochure’s promise. They could run a scan, inspect the result and decide whether the software understood their cluster. Rozen liked the change from conventional B2B selling, where a suit, a meeting and a polished pitch often precede contact with the product. With open source, the software entered the room first.

2021Kubescape launched as open source
$30MARMO Series A announced in 2022
2025Kubescape reached CNCF Incubation

Early GitHub momentum gave the thesis a visible pulse. ARMO announced a $30 million Series A in April 2022, led by Tiger Global with Hyperwise Ventures and existing investors Pitango First and Peled Ventures participating. The capital mattered, but the more interesting asset was the feedback loop. Users could reveal needs through issues, pull requests and the blunt truth of adoption. Kubescape entered the Cloud Native Computing Foundation’s Sandbox in late 2022 and moved to Incubation in January 2025, a step that signaled both technical maturity and a broader life beyond one vendor’s walls.

Shauli Rozen speaking in an ARMO shirt beside his name and the 20 Minute Leaders mark
The uniform is startup formal: black ARMO T-shirt, headset microphone, complicated infrastructure explained in human language.

Security that survives contact with production

Kubernetes creates a peculiar negotiation. Security teams want controls. Developers and operators need the application to keep working. A recommendation that is theoretically safe but operationally destructive is not a remedy; it is a new incident with better intentions. Rozen often returns to the fear beneath this negotiation: teams hesitate to remediate because they might break the application.

ARMO’s answer has been context. Connect what the cluster is configured to do with what the workload is actually doing. Use runtime evidence to distinguish an exposed path that matters from a theoretical possibility buried in a mountain of alerts. Give the person responsible for the system a shorter list and a reason for every item on it. This is part technical architecture and part courtesy. Nobody carrying a pager at 3 a.m. needs another dashboard congratulating itself for finding 8,000 things.

“The biggest concern security and DevOps teams have is the ability to apply security remediation without breaking the application.”Shauli Rozen

The same logic now carries ARMO into AI workloads. Traditional software is expected to follow paths developers wrote. Agents can choose tools, retrieve data and generate new actions while they run. The configuration file may remain unchanged while behavior wanders somewhere novel. Rozen’s recent writing focuses on this gap between declared permission and live intent. The old static question - what could happen? - is being joined by the urgent runtime question: what is happening, through which identity, and how quickly can it be stopped?

The principle beneath the product

Reduce the distance between a signal and a safe decision. Open source shortens the distance to trust. Runtime context shortens the distance to relevance. Clear remediation shortens the distance to action.

The founder with salt water in the schedule

Rozen’s public persona is technical without being solemn. One presentation introduced his life as a loop: surf at 5 a.m., build Kubernetes security products at 8, put three boys to bed at 9, repeat. He enjoys scuba diving and free diving as well, and has described reaching 26 meters on one breath. It is a sport hostile to frenzy. Calm is not decoration down there; it is equipment.

He also enjoys ouzo, partly for the anise taste and partly, perhaps, because ordering it gives a person character before the glass even arrives. On social media he once proposed a Kubernetes restaurant serving “Pod-Thai,” pasta with open source and clustered cream for dessert. Followers replied with “node-les,” “kubelette” and other crimes against menus. Rozen contributed one more: naturally, the restaurant would have a full “menufest.” Cybersecurity contains enough genuine danger. It can survive a pun.

The playfulness sits comfortably beside a serious operating belief. Rozen says chance often moves a person from one stage to another, followed by the ability to act on it. His own path supports the formulation. Communication protocols did not announce a straight road to cloud security. An MBA did not erase the engineer. Consulting did not prevent a return to startup life. Each turn supplied a tool that became useful later.

Kubescape is the clearest expression of that accumulated toolkit. It is an engineering artifact, a distribution strategy and a community compact. It asks developers to participate in security without pretending they have stopped caring about shipping. It gives security teams evidence without pretending every possible weakness is equally alive. And it lets ARMO build a commercial company while a neutral foundation helps the open-source project grow on its own terms.

Listen closely, then make the useful thing

Founders like to describe vision as seeing around corners. Rozen’s version is more grounded. Talk to the user. Notice when the market is not ready. Change the form of the product without abandoning the problem. Let people test the claim themselves. The glamour is limited; the compounding effect is not.

ARMO’s next chapter expands the runtime thesis from containers into software that can make decisions of its own. The technical vocabulary will change. The organizational problem will feel familiar. Operators will face more signals than attention. Security teams will need to separate unusual behavior from dangerous behavior. Developers will resist controls that make useful systems unusable. The bridge must hold while everyone is walking across it.

Rozen arrived here by refusing to treat any earlier identity as wasted motion. He can still enjoy a Linux command line, frame a market, take a customer call and make a terrible Kubernetes food joke. The through line is not reinvention for its own sake. It is translation - between machine and user, developer and defender, possibility and evidence. In a field famous for noise, that is a quiet and practical ambition.