Pros
The company is ambitious and is building a product with the potential to significantly impact its market. Engineering execution is fast moving and leadership is highly focused on meeting delivery milestones.
Cons
During my time at Freenome, the organization did not have dedicated security leadership at the executive or VP level (e.g., no CISO/CSO or equivalent). Product and enterprise security responsibilities appeared to fall indirectly under engineering and product leadership. As a result, security considerations were often balanced against delivery timelines rather than owned as a first class function. For a company developing and operating a regulated, safety critical product, this is an unconventional and high risk approach compared to industry norms. The VP of Engineering and Chief Product Officer are clearly driving execution and delivery. However, without independent security leadership, decisions related to risk acceptance, secure design and long term operational resilience are centralized within roles whose primary charter is shipping product. This approach differs from peer companies in regulated environments, where security leadership is typically established prior to external launch. It will be interesting to see how this model scales as the product matures and faces real world adversarial, regulatory and operational pressures.