Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Travis McPeak -- SecOps Makes Developers Lives Easier

22 min18 december 2018

Om avsnittet

What if a security team measured success partly by making developers’ work easier? Travis McPeak explains that approach to SecOps through concrete examples from Netflix’s cloud environment. RepoKid removes unused AWS permissions, Lemur simplifies certificate provisioning, and Security Monkey provides visibility into assets and configuration changes. Chris asks how those capabilities fit with the secure development lifecycle, incident response, and traditional application testing. Travis describes finding repetitive work or problems that cannot scale manually, then deciding whether to use an existing solution or build automation. They also discuss learning paths, books, and OWASP involvement. The conversation makes the operational side of security tangible: give teams dependable controls and useful context while reducing the everyday friction of doing the right thing.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Travis McPeak:
Travis McPeak on LinkedIn

Mentioned in this episode:
RepoKid
Lemur
Security Monkey (archived project)
Bandit
The Tangled Web

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 SecOps that helps developers with Travis McPeak
01:17 Travis’s security origin story
03:25 A security book worth sharing
04:05 Defining SecOps and introducing RepoKid
05:16 Removing permissions and managing exceptions
06:20 Security signals and incident response
08:20 Making certificate provisioning easier with Lemur
10:29 Language-specific tools and broader controls
11:52 Asset visibility with Security Monkey
13:02 Automatically correcting cloud permissions
14:32 How an operational problem becomes a tool
15:51 Where application security testing fits
17:22 Learning SecOps through community and practice

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.