Meet The Engineers Behind The Defenses You Trust

Because legendary security doesn’t engineer itself

  • The most impactful security innovations often start with engineers willing to question how things have always been done. 
  • From safer execution to endpoint data detection to cloud-scale telemetry, purposeful engineering can turn pain points into lasting security advantages.
  • These breakthroughs sit as the foundation for many of the defenses security teams rely on today, helping  build more connected, intelligent protection against today’s volatile threats. 

You probably don’t think much about the people behind the security technology you rely on every day. It's understandable. You’re busy making sure it works, and keeps working, as attackers turbo boost their playbooks with AI. But behind every trusted defense are engineers asking difficult, sometimes strange, questions, or obsessing over the smallest details—all to challenge what’s possible. 

Across endpoint, network, cloud, and data security, Symantec® and Carbon Black® engineers have tackled many problems, at times finding solutions in unexpected places. Their methods may look different, but they share a common goal: solving hard security problems to make protection stronger and easier to use for the real people counting on it.

That’s why we’re spotlighting three engineers behind that work, the breakthroughs they helped bring to life, and how those very innovations advanced the solutions protecting your organization today. 

CP3 makes complex security logic safer to run

Right now, security teams face a complexity challenge. As attackers grow more sophisticated and faster, security software needs to run increasingly complex logic on customer machines. But the more complexity, the harder it is to run safely and fast enough to matter. For security leaders, that can mean more performance overhead, more risk, and more friction. Suddenly, the very software designed to protect a system could itself become a point of vulnerability.

Broadcom engineer Costin Ionescu set out to solve that tradeoff with CP3 (short for C++ Protected). His approach was perhaps unconventional. Instead of relying on traditional isolation methods, he turned to the compiler itself to create a controlled execution environment. A sandbox small enough to be efficient, but contained enough to be safe. 

The engine fueling many of our greatest hits

Today, CP3 is an invaluable part of the core technology used across the Symantec cybersecurity portfolio, as well as Carbon Black Cloud. It helps power complex security use cases including anti-malware and scripting emulators, AI/ML inference scanners, command line and AMSI scanning, and so much more. That same focus on containing untrusted activity extends to Adaptive Isolation, which uses threat intelligence to identify actors that aren’t yet confirmed as malicious (but aren’t exactly trustworthy either) and prevents them from modifying critical resources on the endpoint. The result is security that can do more without asking your endpoints to take on more than they can handle. 

EMDI brings exact data matching to the endpoint

Generative AI may no longer be breaking news, but the security conversation around it is far from over. As a fixture in most modern workplaces, with employees pasting confidential material into chatbots and companies experimenting with internal models, its impact on the threat landscape is still evolving. For data protection teams, the proverbial hourglass is running out faster as sensitive information moves at greater scale and speed than before.

That means data loss prevention (DLP) systems need to detect sensitive data being submitted to AI engines and LLMs, and companies training AI systems need to remove sensitive information from training datasets to prevent indirect leakage. "At a high level, DLP is very much what we call ‘stop stupid,'" said Yuval Tarsi, Distinguished Engineer at Broadcom. "It’s [about] how we prevent users from unintentionally exposing data they shouldn’t.”  Dedicating his career to this mission, Tarsi took on the challenge of improving Exact Data Matching (EDM), a long-standing capability that allows systems to identify records such as personal information or account data without actually storing the sensitive data itself. 

One man’s obsession with efficiency 

Making EDM work efficiently on secure servers was complex enough. Making it work on laptops and endpoint devices, with far fewer resources and less control over the environment, was something many engineers had tried to solve without success. Against all odds, Tarsi’s unexpected breakthrough, EMDI, found a way to make EDM practical in resource-constrained environments. And quickly became the architectural foundation for how Symantec DLP protects sensitive data on endpoints today. Now, your data protection can extend to where sensitive data actually lives: the endpoint.  

LC makes massive-scale security telemetry searchable

Moving endpoint security to the cloud might sound simple now, but let’s not forget the sheer amount of data those endpoints can generate. When Carbon Black began making the move from on-premises deployments to the cloud, the team faced a problem that existing technology just couldn’t solve. The new system would need to ingest tens of millions of security events per second while storing and searching across tens of petabytes of telemetry. Davor Roglic, a Carbon Black architect and engineer, and his team looked at data lakes, pushed Elasticsearch as far as they could, and even explored whether multiple clusters could be stitched together. None of it held up. “At that point,” Roglic recalled, “we realized there was no such system in the world.” 

That left them with one option: build it from scratch. Together, they designed LC (pronounced “Elsie”), a data store built to ingest and search massive volumes of security telemetry with an architecture that could scale linearly without internal friction. After that, each system was stress-tested and put under trial. Every failure led to a better design, until it matched the scale they had first envisioned. 

From one impossible problem to something so much bigger

Fast-forward about ten years, and what began as a solution to a seemingly impossible engineering problem became the backbone of Carbon Black Cloud, supporting millions of endpoints generating petabytes of telemetry. Now running on Google Cloud, Carbon Black Cloud brings that scale together with Symantec’s threat intelligence and security technologies, creating more opportunities for integrated protection across the environment. The very system Roglic and his team worked relentlessly to perfect continues to evolve, helping defenders collect, search, and connect the telemetry they need to investigate complex threats and understand what’s happening across the endpoints they protect. 

When thoughtful engineering meets today’s toughest challenges  

Modern security can be incredibly sophisticated and complex, but as Ionescu, Tarsi, and Roglic each showed in their own way, there’s always room to rethink how it works. They questioned assumptions, faced every challenge head-on, and paid attention to details that make security work in the real world. Rather than innovating for innovation’s sake, they purposefully engineered technologies that help protection work harder for the defenders counting on it. 

For talented engineers to have the freedom to pursue these difficult problems, they need tangible support and investment. In fiscal 2025, Broadcom invested $11 billion in R&D overall—more than $20,920 every minute. It’s through that commitment that our engineers have the backing to challenge assumptions, pursue ambitious ideas, and turn difficult problems into technology that can stand the test of time—and AI.

In fiscal 2025, Broadcom invested $11 billion in R&D overall—more than $20,920 every minute.

That same mindset and support is behind Symantec CBX, a unified, attack-trained XDR platform. Bringing together Carbon Black’s pioneering EDR with Symantec’s battle-tested prevention and data security technologies, CBX connects signals across domains and arms defenders with a complete picture of their environment. With AI-powered capabilities that keep humans at the help, security teams can correlate those signals faster, spend less time piecing together an attacker’s trail, and more time stopping them. For resource-constrained teams facing the same sophisticated threats as the largest enterprises, that advantage can mean a world of difference. 

We believe security should give defenders the advantage, not add to their workload—and that belief is engineered into the security solutions we deliver. 

Schedule a 1:1 demo or to see how CBX can help security teams of all sizes move from fragmented signals to a high-caliber defense. 

Request a free 30-day trial to experience how CBX can help you speed investigations, eliminate blind spots, and take you from reaction to prediction. 

You might also enjoy

Upcoming Events

See what's next

Threat Updates

Get the latest