About Aerospike and my role
Aerospike is the operational database that keeps applications predictable, even as conditions change, powering some of the world's largest enterprises. As a member of the leadership team, I oversee strategic decisions around how we build, secure, and scale our engineering operations, including how we protect our software supply chain.
The challenge: CI/CD supply chain risk
One of our concerns is CI/CD supply chain risk. As our build and deploy pipelines grow in complexity, so has our exposure to software supply chain attacks, the kind that are increasingly targeting GitHub Actions workflows and open source dependencies. We knew this was a critical area for us that needed proactive protection before something went wrong.
What we tried before
We evaluated many amazing products, including traditional cloud security platforms. While each had strengths in other areas, the solutions we looked at required us to migrate all our Actions runners to self-hosted machines to enable meaningful CI/CD pipeline monitoring. That was a significant infrastructure lift we were not prepared to take on.
On top of that, the platforms we evaluated did not offer the native, purpose-built support for CI/CD dependency security we sought. Meaning we could spend significant amounts of time shifting infrastructure, to only get half of the value we wanted.
How we found StepSecurity
StepSecurity consistently published blog posts about newly discovered attacks and supply chain vulnerabilities. Crucially, each post also included the solution to protect against them and in-depth analysis. That pattern stood out. It showed they weren't just monitoring the space, they were actively a leader in the space.
Why we chose StepSecurity
StepSecurity uniquely solved a problem no one else could: it gave us powerful network-level protection for our CI/CD pipelines without requiring us to shift to self-hosted runners. It was the only platform with direct, focused support for CI/CD dependency security, providing many features out of the box that we lacked natively.
The capabilities that mattered most
Network-level pipeline protection without infrastructure changes, and native CI/CD dependency security coverage. The ease of adoption relative to alternatives was also a major factor.
That is what I would have told you when we first started using the platform… But in my opinion StepSecurity's strongest asset is the team you get along with the product. They are fast to react to changes in the threat landscape, constantly taking our feedback and actually making actionable plans and continuously making the product better.
The impact
We've moved from a reactive security posture to a proactive one, which is one of our core goals. StepSecurity gives us continuous visibility and protection across our pipelines so we're not scrambling to respond after the fact.
Measurable results
With the addition of StepSecurity we have been able to cut the amount of work the team does with each new NPM worm from days to minutes/hours, making the task boil down to checking a dashboard.
How our workflow changed
The team now has confidence that our CI/CD environment is covered without the overhead of managing self-hosted infrastructure. Security has become embedded in our pipeline, not bolted on after the fact.
In summary
"StepSecurity gave us enterprise-grade CI/CD protection without forcing us to overhaul our infrastructure all while uniquely and proactively securing how we build software. It's a cornerstone of our security team moving to a proactive security organization rather than a reactive one."
- Marek Counts




