
Colin Medfisch
Building the future of identity security
Senior Product Manager
Duo · Cisco
What I'm Working On
Exploring the intersection of identity, security, and AI. Currently focused on Agentic AI Security at Duo, building products that help organizations secure AI-driven workflows.
Experience
Driving Duo's evolution beyond MFA into a comprehensive Identity platform. Currently focused on three strategic bets: Agentic AI Identity, securing how autonomous agents authenticate and authorize across enterprise systems; broader IAM management, expanding Duo's footprint into full identity lifecycle governance; and Admin Security, hardening the controls that protect the people who protect everyone else.
Drove strategic growth of Duo's Identity portfolio, expanding the product line from MFA to SSO to a full Security-First IAM suite and leading its 0-to-1 market entry.
- Took Duo SSO from concept to enterprise scale, personally leading discovery calls, drafting design docs, and running customer pilots
- Partnered with Cisco IT on migration off their legacy SSO provider, handling requirements gathering and rollout end-to-end
- Coined the tagline "Identity simplified. Security amplified." which became the enduring positioning for Duo's identity line
- Balanced roadmap with scrappy hands-on work: wrote internal scripts, built demos, and iterated based on live customer input
Led product development across two engineering teams, driving a transformative shift from MFA provider to Trusted Authentication partner.
- Directly responsible for 20x monthly authentications, 5x user base, and 10x customer expansion
- Spearheaded end-of-life motion for the legacy on-premise SSO offering through close collaboration with stakeholders across Duo and Cisco
- Streamlined feature request processes for diverse user types, empowering pre-sales, post-sales, and technical support teams
- Maintained the product roadmap, delivering quarterly and ad-hoc updates to stakeholders with strategic recommendations
Provided technical expertise and architectural guidance to enterprise customers, optimizing business outcomes.
- Led training sessions for new Customer Solutions Engineers, instilling best practices for successful enterprise deployments
- Actively contributed to product improvement efforts, serving as the primary feedback loop between high-value customers and Product
Collaborated with Customer Success Managers, Sales partners, and Product team, delivering tailored architectural guidance and troubleshooting support.
- Advocated for customer feedback, closing gaps and driving product enhancement across the Duo platform
Scaled global support operations by engineering internal automation tools and driving organizational growth.
- Led training and tool development for global support teams, contributing to seamless customer experiences
- Analyzed support ticket trends to guide product development efforts, promoting continuous improvement
Delivered front-line technical resolution for a rapidly growing user base, transforming reactive support interactions into long-term customer advocacy.
Conducted technical and risk assessments on cyber security events for a 30k-employee enterprise.
- Co-led implementation efforts and user workflow development for v1 Splunk Enterprise Security and Archer GRC tooling
- Conducted endpoint and network forensic analysis, developing custom SIEM use-cases to detect emerging threats
- Designed foundational incident response workflows and reporting frameworks to scale the SOC
Gained foundational experience in Governance, Risk, and Compliance (GRC) by supporting the organization's path to HITRUST certification.
- Pioneered development and productization of HMHS's Security Awareness and Training program, rapidly adopted by partner Blue Cross Blue Shield organizations
- Developed the Information Security and Risk department's RFP intake system and automated security event ticketing and escalation systems
Conducted QA engineering activities for Android and iOS builds of AniMates and Visual Voicemail applications, addressing customer feedback and enhancing user experience.
Writing
From Protocol to Practice: Secure the AI Agent Ecosystem with Duo
Secure your AI agent ecosystem with Duo's MCP integration, supporting the latest OAuth standards for scalable, least-privilege access control.
AI SecurityOAuth 2.0's Next Chapter: Enabling the AI Security Revolution
AI agents are already becoming part of daily work. OAuth ensures they operate within safe boundaries. Duo makes that governance secure, scalable, and simple.
IdentityHarmonizing Access Control with Routing Rules
How Duo SSO's Routing Rules enable organizations to authenticate users across multiple SAML identity providers and Active Directory sources simultaneously.