Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Julien Vehent -- Securing DevOps

34 min14 augusti 2018

Om avsnittet

Can security become a normal part of DevOps without turning every release into an audit? Julien Vehent, author of Securing DevOps, shares what his team learned protecting Firefox services at Mozilla. He explains why security engineers belong inside product teams, how short checklists translate large security requirements into work developers can actually complete, and where creativity still matters. Julien challenges the idea that everything must be automated, showing how automation frees specialists to investigate the problems that require judgment. The conversation follows real examples involving Content Security Policy, bug bounties, website security grades, and testing in delivery pipelines. He closes by describing continuous security as a feedback loop that turns operational lessons into better requirements, controls, and engineering practices.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Julien Vehent:
Julien Vehent’s website

Mentioned in this episode:
Securing DevOps by Julien Vehent
Mozilla HTTP Observatory
ZAP
SSL Labs Server Test

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Securing DevOps with Julien Vehent
01:54 Julien’s security origin story
04:51 Defining DevOps as engineering practices
06:33 The practical story behind Securing DevOps
07:32 Making security a natural part of building software
10:28 Putting security inside the product team
13:11 Turning security requirements into checklists
16:11 Leaving developers room for creativity
17:15 Where manual security work still belongs
21:23 Mozilla’s experience with CSP and bug bounties
25:12 Observatory, SSL Labs, and pipeline testing
26:35 Continuous security as a feedback loop
30:31 Learning security by building real systems
32:39 Room to improve DevOps security

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.