DiscoverDevSecOps Podcast
DevSecOps Podcast

DevSecOps Podcast

Author: Cássio Batista Pereira

Subscribed: 64Played: 756
Share

Description

The DevSecOps Podcast explores the intersection of software development, cybersecurity, and modern engineering, with a strong focus on Application Security and DevSecOps.Each episode brings practical conversations with security professionals, engineers, researchers, community leaders, and industry experts about the challenges of building and operating secure software at scale.We go beyond tools and vulnerability scanning to discuss secure development, security culture, threat modeling, AppSec programs, AI, automation, cloud security, security testing, maturity models, and the realities of integrating security throughout the entire software development lifecycle.Expect technical insights, real-world experiences, lessons learned, strong opinions, and honest discussions about what actually works, what does not, and where software security is heading next.If you build software, secure applications, lead engineering or security teams, or simply want to understand how modern organizations can deliver software faster without losing control of security, the DevSecOps Podcast is for you.

Become a supporter of this podcast: https://www.spreaker.com/podcast/devsecops-podcast--4179006/support.
212 Episodes
Reverse
In a digital landscape where security breaches make headlines daily, the ability to engage developers and decision-makers on security matters is more critical than ever. In this episode, Lisi Hocke unveils the secret to transforming security champions from mere titles into influential advocates who drive meaningful change across teams. Lisi, a seasoned expert with over 17 years in tech, shares her insights from the frontlines of application security. You’ll discover how to capture the attention of developers and management alike, ensuring that security conversations resonate and lead to proactive measures. Learn the art of speaking their language, building trust, and contextualizing risks to make security relevant and compelling. We break down essential strategies for establishing effective security champion programs, tackling common pitfalls that lead to failure, and exploring innovative approaches that make security an integral part of the development process. You’ll also hear about the critical importance of automation and systems that inherently promote secure practices without overwhelming teams. The stakes couldn’t be higher: neglecting to engage effectively can lead to devastating breaches and costly repercussions. This episode offers a roadmap to not only prevent harm but also foster a culture where security is everyone's responsibility. Perfect for security professionals, developers, and anyone involved in product development, this episode is your guide to creating a more secure future. Tune in to learn how to elevate your security practices and empower your teams today!Become a supporter of this podcast: https://www.spreaker.com/podcast/devsecops-podcast--4179006/support.Support: Nova8, Checkmarx, Snyk, Conviso, Gold Security, CyberSec Games and PurpleBird Security.
In a world dominated by screens, how do we reignite the joy of face-to-face interaction? In this episode, Cássio Pereira and Marcos Santos sit down with Devika Gibbs, co-founder of Cybersec Games, to explore the transformative power of physical games in cybersecurity training. Devika reveals how her passion for board games is reshaping the way teams learn and collaborate, proving that true connection happens in person, not behind a screen. Devika shares the origin story of Cybersec Games, sparked by a simple index card idea, and explains why physical interaction is essential for building trust within teams. You'll discover:The unique benefits of playing games in a physical setting versus digital platforms.How to overcome generational shifts towards screen reliance in team training.The surprising outcomes of using games to enhance empathy and communication in professional environments.Real-life applications and success stories from organizations that have embraced this innovative approach.The stakes are high: without understanding the value of physical interaction, organizations risk losing the essence of teamwork and collaboration. Devika emphasizes that investing in physical games not only fosters deeper connections but also leads to better training outcomes compared to traditional digital methods.This episode is essential listening for cybersecurity professionals, educators, and anyone interested in enhancing team dynamics through the power of play. Dive into the world of Cybersec Games and discover how bringing people together can transform the way we learn and grow in the digital age. Don't miss out on this enlightening conversation that promises to change your perspective on training and teamwork!Become a supporter of this podcast: https://www.spreaker.com/podcast/devsecops-podcast--4179006/support.Support: Nova8, Checkmarx, Snyk, Conviso, Gold Security, CyberSec Games and PurpleBird Security.
How mature is your DevSecOps program, and how do you know what to improve next?In this episode, we talk with Timo Pagel, creator of DSOOM, the DevSecOps Maturity Model, about why organizations need structured guidance to build security into software development without turning maturity into a bureaucratic checkbox exercise.We explore why many companies delay maturity assessments until their development environment becomes difficult to control, how security evaluations should reflect each organization’s actual context, and why copying a generic framework rarely produces meaningful improvement.Timo also shares how DevSecOps maturity models must evolve as AI becomes part of everyday software development. As teams increasingly rely on AI-assisted coding, maturity models need to address new risks, practices, and responsibilities associated with AI-generated code.The conversation also covers a topic that maturity models often ignore: failure. Progress does not come from pretending every initiative worked perfectly. It comes from learning what failed, adapting the approach, and using those lessons to build stronger and more resilient engineering practices.A practical conversation about DevSecOps maturity, realistic assessments, AI-assisted development, organizational growth, and the value of learning from mistakes.Become a supporter of this podcast: https://www.spreaker.com/podcast/devsecops-podcast--4179006/support.Support: Nova8, Checkmarx, Snyk, Conviso, Gold Security, CyberSec Games and PurpleBird Security.
In this episode of the DevSecOps Podcast, we talk with Juliane Reimann about turning one of the most common tensions in software development into real collaboration: the relationship between agile teams and IT security.Although both sides want reliable and robust software, security checks are still often left until the end of the development lifecycle. The result is predictable: vulnerabilities are discovered too late, remediation becomes expensive, delivery pressure increases, and security is treated as a blocker instead of a partner.Based on her presentation, “From Conflict to Collaboration,” Juliane explains why security findings are often detected but not addressed quickly, what causes defensive reactions toward security tools and processes, and how early, continuous security integration can improve communication, ownership, and delivery.A practical conversation about breaking silos, reducing friction, and making security part of the development workflow from the beginning.Become a supporter of this podcast: https://www.spreaker.com/podcast/devsecops-podcast--4179006/support.Support: Nova8, Checkmarx, Snyk, Conviso, Gold Security, CyberSec Games and PurpleBird Security.
In this episode of the DevSecOps Podcast, we talk with Nariman Aga-Tagiyev about how behavioral science can help improve Application Security programs. Based on his presentation, “Keep It Between Us: Manipulating Humans for Better AppSec (Ethically),” we discuss motivation, skills, tips, habit formation, and how to transform security activities into sustainable behaviors within development teams. We also explore BJ Fogg's Behavioral Model, the Octalysis Framework, and the Habit Cycle in an Application Security context, including the risks of using gamification, pressure, or behavioral manipulation inappropriately.Become a supporter of this podcast: https://www.spreaker.com/podcast/devsecops-podcast--4179006/support.Support: Nova8, Checkmarx, Snyk, Conviso, Gold Security, CyberSec Games and PurpleBird Security.
loading
Comments