
Alyssa Miller — Experiences with DevOps + Automation and beyond
Om avsnittet
Automating security tests is useful, but it does not by itself make a development team secure. Alyssa Miller, a former developer and application security practitioner, explains how DevOps changes the way security work should happen. She begins with her path into hacking and a striking penetration-test story in which a web application exposed domain-level privileges. The discussion then moves toward prevention: threat modeling during user-story development, reusable reference architectures, and feedback that helps engineers make better decisions early. Alyssa shares lessons about organizational change, realistic starting points, and the limits of adopting tools without changing habits. She also offers career advice for newcomers, emphasizing curiosity, clear interests, and the many paths that can lead into security.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Alyssa Miller:
→ Alyssa Miller’s website
Mentioned in this episode:
→ Threat Modeling: Designing for Security — first edition
→ Jenkins
→ BSides Las Vegas
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 DevOps, automation, and Alyssa Miller
02:30 Alyssa’s path from development into security
07:06 What makes application security compelling
08:19 Reaching domain admin through a web application
12:39 Defining DevOps through practical experience
15:21 Where security fits in DevOps
16:43 Threat modeling early in development
22:41 Asking security questions within user stories
25:46 Moving beyond automated scanning
30:35 Reference architectures that help developers
31:06 Organizational challenges in adopting DevOps
33:41 Choosing a realistic starting point
36:55 Career advice and finding your interests
41:27 The Blue Team Con community
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.