# Andrew Hartnett, CTO

Andrew Hartnett is the chief technology officer at Bitwarden, leading the engineering organization. He brings extensive experience building, operating, and maintaining products at the intersection of open source, massive-scale data, cybersecurity, and observability, gained across startups, large institutions, and major corporations. Andrew co-founded Rackspace Managed Security and led its engineering and development organization, ran the Core Data Platform organization at New Relic, and most recently served as CTO of One Identity, where he transformed the organization and its processes to embrace an AI-assisted future. He is passionate about driving innovation and accountability while fostering a collaborative engineering culture rooted in excellence and delivery.

---

### Andrew Hartnett, CTO

Andrew Hartnett is the chief technology officer at Bitwarden, leading the engineering organization. He brings extensive experience building, operating, and maintaining products at the intersection of open source, massive-scale data, cybersecurity, and observability, gained across startups, large institutions, and major corporations. Andrew co-founded Rackspace Managed Security and led its engineering and development organization, ran the Core Data Platform organization at New Relic, and most recently served as CTO of One Identity, where he transformed the organization and its processes to embrace an AI-assisted future. He is passionate about driving innovation and accountability while fostering a collaborative engineering culture rooted in excellence and delivery.

![Andrew Hartnett headshot](https://bitwarden.com/assets/55pYW5XDDKoY7T9G2yegkk/454e0f0021b6ea05103f1bae84518361/Copy_of_new_LinkedIn_foto.png)

[Headshots](https://drive.google.com/drive/folders/1gAcgEe86TRPc_We-YlKM9OPc-J8lMBlD?usp=drive_link)

[Follow](https://www.linkedin.com/in/andrew-hartnett/)

## Areas of expertise

### Engineering leadership

![icon-roadmap-1-blue](https://bitwarden.com/assets/5D8VocIWyaigF1g29Y3olG/f1210ee1184b7f623ff214b0882463c3/icon-roadmap-1.png)

### Large-scale data platforms

![icon-open-source-3-blue](https://bitwarden.com/assets/1FcbqUUMorbAR9lqRbqLkD/9ef3c35333a0d6db1701c6c49a57bb17/icon-open-source-3.png)

### AI and agentic workflows

![icon-AI](https://bitwarden.com/assets/6J5sdJojI54hnkO5vMahC5/952e4201701a4050c9e95bcde26ee6b8/icon-AI-background.png)

### Open source software

![icon-open-source-2-blue](https://bitwarden.com/assets/3Pf9ZZrgNVFs7kQ1KVZ6ZJ/91e1118f8b19614779737cd4cb101a17/icon-open-source-2.png)

### Identity security

![icon-identity-blue](https://bitwarden.com/assets/686cFj55C3zIG8xfiiGg6D/001a3cc2d6b8c8af8d618b089e3f1751/icon-identity.png)

### Cloud infrastructure and observability

![icon-cloud-security-blue](https://bitwarden.com/assets/7N2fvc88XMwkAkrmKd6E5j/397e6db5e205e2c484a7a7e9ad419113/icon-cloud-security.png)

**National Insider Threat Awareness Month 2026: Expert Insights**

"Insider risk can stem from the deliberate misuse of legitimate access or from an honest mistake, and the potential damage grows when accounts retain broader access than a person needs. Stolen credentials present a different threat, but excessive permissions can magnify the impact in much the same way. Credential management is foundational, but organizations also need to govern what happens after access is granted, particularly for privileged access to critical systems and sensitive data. That means enforcing least privilege, reviewing access as roles change, and maintaining visibility and auditability into who accessed what and when."

![vmblog-speakers](https://bitwarden.com/assets/1udn7jFiujrwSNAv2tPMIQ/77bea76131c5ff321e72f2278a405b3c/vmblog-speakers.png)

[Read the article](https://vmblog.com/bylines/national-insider-threat-awareness-month-2026-expert-insights/)