How the former ByteDance CISO led a 3-billion-user platform through congressional hearings, an international ban threat, and the biggest failure of his career
There are not many people who can say they have been personally subpoenaed to testify before the U.S. Senate about the security of a platform used by 3 billion people. Roland Cloutier can. As the former Chief Information Security Officer of ByteDance, the company behind TikTok, Cloutier spent years defending one of the most scrutinized platforms in the world, through congressional hearings, international bans, and relentless political pressure.
In a candid conversation with Jay Bavisi on The Cybersecurity Podcast by EC-Council, Cloutier pulled back the curtain on what it actually takes to lead security at that scale. The conversation ranged from team-building philosophy to the three jobs every CISO now has because of AI, and it closed with a rare admission: his own biggest professional failure.
From Federal Law Enforcement to the C-Suite
Cloutier’s path into cybersecurity did not start in a security operations center. He began his career in the military, working for the Department of Defense in aerospace defense as a combat security policeman, before moving into federal law enforcement. It was there, working criminal and civil investigations, that he first encountered the “computer stuff” that would define his career.
“I couldn’t even spell computer at the time,” Cloutier said. He went back to university, studied computer science, and discovered a passion for technology that pulled him out of federal law enforcement and into the private sector. The switch, he noted with a laugh, also doubled his paycheck.
What followed was a career built around a simple throughline: stopping bad guys, whether in law enforcement or in the private sector. Along the way, Cloutier developed a reputation for building high-performing security teams, a skill he credits directly to his military background.
The CISO Mindset: Stop Absorbing the Blame
CISOs, Cloutier argued, are too often the scapegoats when something goes wrong, and it is a major reason the role has such high turnover. But he believes much of that burden is self-inflicted.
“People that do this work are passionate. They’re passionate about defending, about doing the right thing, about engaging their business to do it. And oftentimes they blame themselves more than other people blame them.”
His prescription is a mindset shift: stop trying to be the final decision-maker on business risk. Instead, operate as a business leader who provides transparency, sound advice, and clear options, then lets the business decide. “When we hold the decisions to ourselves, that’s typically when things go wrong,” he said.
That philosophy extends to how he builds teams. Cloutier described assembling what he calls “command staff,” senior leaders who rotate roles every two to three years so that no single person becomes a point of failure. The goal is a team of well-rounded practitioners who can step into any seat if a colleague is unavailable, creating an organization that can respond quickly no matter where a threat emerges.
Three Jobs, One Title: The CISO’s New Mandate Under AI
Much of the conversation centered on artificial intelligence, and Cloutier was direct about how it is reshaping the CISO role. In his view, today’s security leaders now carry three distinct, equally important responsibilities.
The first is enabling the business to use AI at competitive speed. “The CISO has to be focused and engaged in ensuring the organization can use the technology it is necessary to be successful and win in the market,” he said, adding that this comes before, not instead of, governance and standards.
The second is defending against AI-powered attacks, a threat Cloutier has watched evolve firsthand. He recalled seeing automated, sub-second attack patterns against platform controls years ago that had nothing to do with a lone attacker at a keyboard. “That’s pure automation against a control you just implemented, and it’s testing its new attack against you,” he said. “That was four years ago. The world has changed.”
The third job is running the security organization itself like a business. With budgets that can reach tens of millions of dollars and staff levels rivaling a mid-sized company, Cloutier believes CISOs must apply the same AI-driven efficiency gains to their own operations that they expect from the rest of the enterprise.
A Bold Prediction: Some Security Jobs Will Disappear
Cloutier does not see AI simply adding tools to the security stack. He predicts it will eliminate entire categories of work while creating new ones.
“I’m sorry to say it to the GRC and the third-party risk teams, but those jobs are not going to exist.”
If a system can continuously map data flows, evaluate third-party controls, and deliver active threat intelligence automatically, he argued, the manual version of that work becomes redundant.
In its place, Cloutier expects a wave of entirely new specializations: certified data science defense specialists, AI pipeline architects, API security engineers, and what he calls AI threat control defense engineers. “There are these big new bubbles of work that are coming up that we don’t have anybody in there,” he said. “If someone wants to be really successful, they start thinking three, five years down and start training themselves for it.”
His advice to practitioners is to treat this the way the industry treated the shift to cloud computing a decade ago: painful in the transition, but ultimately a net positive for the profession. “I’m actually hopeful,” he said.
Inside the Subpoena: Truth, Transparency, and a Trusted Team
No part of the conversation drew more attention than Cloutier’s account of preparing for congressional and Senate testimony during his time at ByteDance. His approach, he said, boils down to four things: truth, transparency, facts, and an amazing team.
“Proper preparation prevents piss-poor performance.”
Cloutier described a rigorous preparation process that began with understanding exactly what was being asked, and why. He worked closely with legal teams to anticipate difficult questions and rehearsed with colleagues who could challenge him the way lawmakers would.
Asked whether he felt attacked during questioning, Cloutier estimated it happened perhaps 20 percent of the time, but said he did not resent it. “They got a job to do,” he said. “If the technology I’m defending is operating within their areas, they have a right to ask me hard questions.”
His guiding principle for separating legitimate security concerns from geopolitical noise was simple: “Program consistency counts.” A security program grounded in real, ongoing threat understanding, he said, gives a CISO the footing to answer any question, regardless of the politics surrounding it.
The Personal Cost of a Year Under Scrutiny
The congressional and Senate hearings Cloutier faced were not a single event but a period lasting roughly a year, layered on top of running a global security organization across dramatically different time zones and cultures.
The toll was real. Cloutier described losing sleep, working stretches from early morning to late at night, and neglecting his own physical health for months at a time, despite knowing better. “People in these positions don’t think of it as a physically intensive job, but it is,” he said. “You have to be healthy to do this job.”
He credits keeping his team motivated through a single word: mission. Employees who understand exactly what they are protecting, he said, whether that is millions of small businesses or hundreds of millions of users in a given country, stay engaged even under intense pressure. “Whatever your company is, your people need to know the mission and be able to articulate it,” he said. “You can throw as much money as you want at them. If they’re not into the mission, they’re going to go to the next place.”
The Failure He Still Thinks About
Asked directly about the biggest failure of his career, Cloutier did not deflect. He pointed to his early days at ByteDance, which began on April 1, 2020, in the middle of the COVID-19 pandemic.
Cloutier normally relies on months of in-person time with a new organization, traveling to meet teams and understand a company’s culture before implementing his security playbook. The pandemic made that impossible.
“My failure is applying a playbook without the level of due diligence and transparency necessary to make the right decisions about the strategic operations you’re developing.”
It took roughly three years, he said, before he recognized that the approach did not fully fit the company he was building it for.
A Playbook for the Next Generation of CISOs
Cloutier’s story is, in many ways, a preview of what is coming for the entire profession. AI is compressing timelines, automating entire job categories, and raising the stakes for every enterprise CISO. At the same time, the fundamentals he leans on, transparency, consistency, trusted teams, and a clear sense of mission, remain unchanged.
For CISOs, board members, and risk leaders navigating an increasingly public and increasingly automated threat landscape, Cloutier’s central message is straightforward: the tools will keep changing, but the discipline of truth and preparation will not.
This article is based on Episode 15 of The Cybersecurity Podcast by EC-Council, featuring host Jay Bavisi in conversation with Roland Cloutier, former CISO of ByteDance (TikTok).
Roland Cloutier
(fmr) Global Chief Security Officer TikTok & ByteDance, ADP, EMC. Partner / Principal – The Business Protection Group LLC . Advisor / Board Member / Global Speaker / Author

