* L0pht / @stake: security research, red teaming, and source code auditing, IIRC.
* BBN: research.
* NFR: technical advisory board.
* DARPA: Managing a program that provided grants for new security products and tools.
* Google ATAP: Google's "invention studio".
* CyberUL: Testing of security products.
None of these jobs really suggest a background in building a security program. I've worked with some large companies in a similar space to Twitter building their security programs and you can spend the first 6-12 months just trying to justify the new budget. Often that money has to come from another team or teams and he would have to justify that. He was apparently only there roughly a year.Again, I don't doubt Mudge's bonafides. I don't doubt his security knowledge. But this job was nothing like any he's had in the past.
I also don't doubt his claims. Everything he's stated is almost certainly true. It does take more than a year to fix most of these problems and I wonder if he just got frustrated with the political battles that occur in these situations.