
Julien Vehent -- Securing DevOps
Om avsnittet
Can security become a normal part of DevOps without turning every release into an audit? Julien Vehent, author of Securing DevOps, shares what his team learned protecting Firefox services at Mozilla. He explains why security engineers belong inside product teams, how short checklists translate large security requirements into work developers can actually complete, and where creativity still matters. Julien challenges the idea that everything must be automated, showing how automation frees specialists to investigate the problems that require judgment. The conversation follows real examples involving Content Security Policy, bug bounties, website security grades, and testing in delivery pipelines. He closes by describing continuous security as a feedback loop that turns operational lessons into better requirements, controls, and engineering practices.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Julien Vehent:
→ Julien Vehent’s website
Mentioned in this episode:
→ Securing DevOps by Julien Vehent
→ Mozilla HTTP Observatory
→ ZAP
→ SSL Labs Server Test
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Securing DevOps with Julien Vehent
01:54 Julien’s security origin story
04:51 Defining DevOps as engineering practices
06:33 The practical story behind Securing DevOps
07:32 Making security a natural part of building software
10:28 Putting security inside the product team
13:11 Turning security requirements into checklists
16:11 Leaving developers room for creativity
17:15 Where manual security work still belongs
21:23 Mozilla’s experience with CSP and bug bounties
25:12 Observatory, SSL Labs, and pipeline testing
26:35 Continuous security as a feedback loop
30:31 Learning security by building real systems
32:39 Room to improve DevOps security
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.