Apurva Davé

Chief Marketing Officer

About Author

Apurva Davé is the chief marketing officer at Aembit. He likes to take small things that are important and make them big things that are even more important. He did that at Riverbed, from its early days through its IPO; at Jut, which he founded; at Sysdig, from seed stage to unicorn; and at Google Cloud Security, where he helped triple the team and revenue. Despite his obsession with growth, Apurva still enjoys surfing small waves with his longboard. But hey, you can’t grow everything.

Expertise

  • Cybersecurity
  • Cloud security
  • Identity and access management
  • Non-human identity
  • Workload identity and access management
  • Developer and infrastructure security
  • Security product strategy
  • Developer-focused marketing
  • Go-to-market strategy
  • Category and company building

Education

  • Bachelor’s degree in computer science, Brown University
  • Master of Business Administration, University of California, Berkeley, Haas School of Business

Articles by Apurva Davé

Most workload credentials, the API keys, tokens and passwords that connect your services, carry “always on” access that never expires.
AI agent identity breaks down when agents authenticate across OAuth, API keys and managed identities simultaneously. Learn why single-protocol solutions fail.
While companies pour resources into securing employee accounts with MFA, zero trust and regular access reviews, service accounts still get created with static credentials, granted sweeping permissions and then left unmanaged. This creates a growing population of identities that operate outside traditional IAM controls.
The Trivy incident exposed a credential architecture failure, not just a supply chain one. Here’s the case for workload identity and access.
AI agent identity security is the set of practices and controls that treat AI agents as distinct, governable identities with their own authentication, authorization and audit requirements.
Secret remediation is the process of responding to an exposed credential by revoking it, rotating it and removing every trace of it from your environment.
The OWASP Top 10 for LLM Applications is the most widely referenced framework for understanding these risks. First released in 2023, OWASP updated the list in late 2024 to reflect real-world incidents, emerging attack techniques and the rapid growth of agentic AI.
Agentic AI introduces new cybersecurity risks, primarily concerning autonomous identity, tool chain exposure, and cascading compromises, requiring security teams to urgently adopt least-privilege identity frameworks and real-time monitoring designed specifically for self-directed, persistent workloads.
Securing MCP requires a fundamentally different approach than traditional API security.
How do you govern entities that can learn, adapt, and act independently while maintaining security and compliance?
The core problem is that human IAM was never built for workload scale or behavior.