hi! it’s lovely to meet you :)
about me
the professional
I'm part software developer, part storyteller, and part person who worries about what our systems do to the people inside them.
These days I'm Chief Product and Technology Officer at NINJIO, where I work on human risk. That's the industry's polite way of saying that most security problems involve people, and people aren't a system you can patch.
Nobody planned this career, least of all me. But looking back there's more of a thread than it felt like at the time. I've spent twenty years working where technology meets people, and I've gradually moved to the people's side of that line.
Mine is a story best told over a cup of coffee but in case we don’t have that chance…
some work highlights:
Apprentice software developer age 17 for UK HMRC (tax).
BSC Hons Computer Science and Artificial Intelligence - Aberystwyth University (15 years before that was a valid career path - oops)
Wrote real-time radiation monitoring software for CERN in Switzerland.
Five years doing technical counter terrorism work for UK Government.
Seven year itch as a penetration tester and red teamer (breaking things for the greater good)
Short stint as a security auditor (now reformed) at KPMG.
Founder of SafeStack - an application security education platform, later acquired by NINJIO
10 plus years helping some of the fastest growing companies on earth bring security to their software development lifecycles without getting in the way of doing the cool innovation stuff. (Think CISO meets appsec engineer meets relationship counsellor)
a few notable things outside of my paid work:
Founded In2securITy, a nonprofit that has taught cyber security to a thousand students
Co-authored two books, (Security for Everyone and Agile Application Security).
Written for publications including Forbes, and been covered in WIRED and MIT Technology Review
Keynoted and sat on panels at conferences around the world, including Black Hat USA
Chaotic podcast host and story collector with Build Amazing Things (securely)
what I'm working on now:
In 2023 my team built a working clone of my face and voice as a surprise. They meant it kindly. When my company was sold, that clone was listed among the assets.
I'm writing my way through what that taught me about consent, ownership, and what happens to a synthetic version of a person after everyone who authorised it has moved on. I'm doing it in public, while the team I now lead builds the same capability for customers who are asking for it, because I'd rather think out loud than pretend it's settled.
the human
In my spare time I enjoy reading (epic fantasy novels of questionable quality), restoring old furniture & machinery and macro photography.
I’m an introvert that has spent 15 years pretending to be an extrovert (I’m getting pretty good at it). I love stories, games and play of all kinds. Many people say I have a calming voice.
Oh, and I hate having my picture taken and have a natural ability to go from normal to awkward in seconds when confronted by a camera. You have been warned..
official biography
Laura Bell Main is Chief Product and Technology Officer at NINJIO, where she leads work on human risk and synthetic identity. She founded the application security education platform SafeStack, acquired by NINJIO, and has spent over twenty years working at the point where technology meets the people who use it — from counter-terrorism and red teaming to security education.
She is the co-author of Agile Application Security and Security for Everyone, has been featured in WIRED and MIT Technology Review, and speaks internationally, including at Black Hat USA. She writes and speaks about the parts of security that involve people rather than systems, most recently on what organisations must settle before using deepfakes of their own staff.