Skip to content

Who I Am

Ryan Hurst sitting on wooden steps outdoors

I’m Ryan Hurst. The path to where I am today began before the internet, when 300 baud seemed fast. That journey took me into operating system security at Microsoft and eventually into the systems that help people and organizations know what to trust online.

Over more than three decades, my career has spanned cryptography, identity, the WebPKI, cloud infrastructure, and the systems that connect them. I’ve led engineering, product, operations, and compliance organizations, and now focus on how automation can make assurance continuous and practical.

Today I am CEO of Peculiar Ventures, where we build products and open-source libraries that collectively receive tens of millions of downloads each week. We solve difficult problems for major enterprises in AI, security, cryptography, and identity, and work with ambitious companies to turn complex technologies into durable businesses.

I advise early-stage and later-stage startups, and work with technology leaders on product strategy, crisis response, organizational transformation, AI governance, post-quantum transitions, regulatory navigation, and building engineering, product, security, operations, and compliance organizations that can deliver under pressure. Companies including SandboxAQ, Binarly, Defakto, and SpruceID have relied on my counsel.

What I’ve Built

At Google, I led Cloud Security and Trust Services, where my teams:

  • Founded and scaled Google Trust Services, now one of the world’s largest certificate authorities
  • Served as an advisor to Let’s Encrypt as it made HTTPS broadly accessible
  • Advanced Certificate Transparency and Binary Transparency, including the ecosystem of logs and monitors that made the certificates the web relies on publicly auditable
  • Built Google Cloud products such as Cloud CA, Managed Active Directory, and certificate lifecycle tools
  • Built workload identity systems for Google’s internal infrastructure and Google Cloud, and was a subject-matter expert for Cloud KMS and Cloud HSM

Before Google, I was Chief Security Officer at 21.co, a private Bitcoin miner that designed its own ASICs and ran its own data centers. In 2015 I built the systems and products that safely managed Bitcoin holdings that would be worth billions of dollars today.

At GlobalSign, I led the company through the industry crisis created by the DigiNotar attacks. We rebuilt its technology and operating model, moving it from outsourced CA operations to an independent engineering and operations organization capable of running critical trust infrastructure itself.

Across those roles and earlier work with Amazon to establish its certificate authority, I have created, led, or advised the authorities behind roughly 60% of the certificates issued on the web.

At Microsoft, I led Windows teams responsible for TLS, certificates, smart cards, biometrics, and enterprise networking. I formalized and managed the company’s Root Program, authored the EAP-TLS standard, and led technologies including DNS, DHCP, RADIUS, and Network Access Protection. I also led Cryptography in Windows and built the Windows Biometric Framework, which became the foundation of Windows Hello. Later, as a security architect in Microsoft Online Services, I led security engineering for the advertising business.

In every role I have focused on turning structural risk into lasting infrastructure that others can depend on.

Standards and Ecosystems

Much of this work has happened between organizations, where no single company can solve the problem alone. My standards work spans the IETF, Trusted Computing Group, ISO, and NIST, including EAP-TLS, OCSP, PIV, PKIX, and PDF.

I have spoken at RSA Conference, InfoSec World, and other industry events, and advised or worked with startups and large organizations including Apple, Cisco, Entrust, and Cloudflare. The recurring challenge has been the same: aligning technology, incentives, and operations well enough for an ecosystem to keep its promises.

What Drives Me

Good security is not about paranoia or perfection. It is about designing systems that stay honest under pressure.

I try to balance security, privacy, and business needs so that secure systems are not only strong but usable. Collaboration and transparency have always mattered more to me than compliance for its own sake.

My work has evolved from fixing individual protocols, to shaping how ecosystems stay aligned to exploring how reasoning itself can help keep them that way.

Beyond the Tech

I have written here since 2006 about security design, the WebPKI, compliance, technology policy, human behavior, and what AI changes about them. I also mentor engineers and share what I have learned from building and repairing complex systems.

Security, at its core, is about keeping promises at scale.


Want to connect? You can find me on LinkedIn, X/Twitter, or Bluesky. I’m always interested in discussing the intersection of security, privacy, and business innovation.