DiscoverSecrets of AppSec ChampionsYour First 90 Days in a New AppSec Role
Your First 90 Days in a New AppSec Role

Your First 90 Days in a New AppSec Role

Update: 2024-07-31
Share

Description

๐Ÿ“‹ Show Notes
Secrets of AppSec Champions: Laying the Foundation of Application Security

In the inaugural episode of the multi-part series 'Decoding Application Security,' host Chris Lindsey and guest Anthony Israel-Davis, Product Security Manager at Fortra, dive into the fundamentals of building a successful application security program for large teams. They discuss essential first steps when starting at a new company, the importance of understanding the company culture, and the critical role of security champions. The conversation covers various aspects of application security, including the implementation of SCA, SAST, and DAST tools, the nuances of API and container security, and the importance of building strong relationships with developers and QA teams. Ultimately, the episode emphasizes the incremental and strategic approach necessary for managing and mitigating risks effectively in a complex software development environment.

โ‡๏ธ Key Topics with Timestamps
00:00 Introduction to Software Building
ย 
00:59 Meet the Expert: Anthony Israel Davis
ย 
01:08 First Steps in a New Company
ย 
02:57 Understanding the Application Environment
ย 
04:54 Building a Solid Security Foundation
ย 
11:29 The Role of Static Analysis (SAST)
ย 
17:12 Empowering Teams with Security Mindset
ย 
22:07 Collaboration with QA for Security
ย 
24:47 Ensuring a Clean Build: Developer and QA Collaboration
ย 
26:17 Dynamic Scanning Explained
ย 
27:32 Regression Testing and DAST
ย 
28:05 Understanding DAST Results and Fuzzing
ย 
33:24 API Testing: A Critical Component
ย 
37:02 Containerization and Security
ย 
42:12 Building a Secure Development Process
ย 
46:39 Final Thoughts and Key Takeaways

Commentsย 
loading
00:00
00:00
1.0x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Your First 90 Days in a New AppSec Role

Your First 90 Days in a New AppSec Role

Chris Lindsey