← All talks

Are you ready to leverage DevSecOps?

BSides DC · 2019Published 2019-10Watch on YouTube ↗
Speakers
Tags
CategoryTechnical
StyleTalk
About this talk
DevSecOps integrates security as a continuous metric throughout the development lifecycle rather than bolting it on at the end. This talk equips security practitioners with education, resources, tools, and practices to champion DevSecOps adoption within engineering teams while minimizing friction across the organization.
Show original YouTube description
As a security practitioner, the trend of Agile and DevSecOps is coming. Whether developers or management are pushing for it, you should be prepared. DevSecOps sets security as a metric of success for developers and encourages security to be a consideration continually through a project lifecycle. This is a vast improvement to the usual methods of taking security into consideration only at the end, in the beginning, or avoiding talking to security at all. You should be seizing the opportunity to leverage the popular DevSecOps movement to your advantage. I want to arm you with ideas on education, resources, tools, and practices to do DevSecOps well from a Security department standpoint. At the end of my talk, I want you to be able to increase the security posture of your engineering teams without drastically increasing friction for any of the other teams. nicole schwartz (Product Manager, Secure at GitLab) Nicole Schwartz (@CircuitSwan) is a Product Manager for the GitLab Secure team. In her career, she has been in Product, System Administration, and Agile coaching. Before her career ever started she was a Hacker, and forever will be. When she isn't working she attends conventions (you may have known her as @AmazonV) and volunteers at SkyTalks and Diana Initiative.