
Sign up to save your podcasts
Or


David Melamed of Jit brings us a new wrinkle in our ongoing series of developer security topics! Melamed says we should move beyond “shift left,” shifting the security earlier in the CI/CD pipeline, into “Born Left,” a platform in which security tools are in the hands of developers at the point of creation. Melamed talks about his early programming experiences, his Ph.D. in Bioinformatics, and the delineation of responsibilities between developers and the DevSec team. All that and a bit of CTO talk.
0:00 - Moving from “shift left” to “born left”
3:05 - How David Melamed got into cybersecurity
6:00 - Choosing your cybersecurity job path
11:15 - Daily work as a cybersecurity CTO
13:02 - How to become a cybersecurity CTO
15:10 - Keeping a company on track
16:40 - DevSecOps shift left to born left
21:08 - Born left, and overall security
23:13 - Accountability for developers
25:07 - Application security and born left
29:33 - What will DevSecOps and born left look like in the future?
31:00 - How to work in software development security
34:35 - First steps to a cybersecurity development job
35:30 - What is Jit?
38:33 - Learn more about Melamed
39:08 - Outro
– Get your FREE cybersecurity training resources: https://www.infosecinstitute.com/free
– View Cyber Work Podcast transcripts and additional episodes: https://www.infosecinstitute.com/podcast
About Infosec
Infosec’s mission is to put people at the center of cybersecurity. We help IT and security professionals advance their careers with skills development and certifications while empowering all employees with security awareness and phishing training to stay cyber-safe at work and home. More than 70% of the Fortune 500 have relied on Infosec Skills to develop their security talent, and more than 5 million learners worldwide are more cyber-resilient from Infosec IQ’s security awareness training. Learn more at infosecinstitute.com.
Paul Giorgi of XM Cyber, a man who told me his favorite way to learn new skills is to break things and put them back together, walked me through the basics of setting up your own cybersecurity practice lab at home for not too much money. But watch out because he says that once you start, your excitement about hands-on practice and buying old servers on eBay can get overwhelming!
0:00 - Build your own cybersecurity practice lab
1:30 - How to practice with a home cybersecurity lab
5:48 - Resource requirements for a cybersecurity lab
8:48 - Cost of a cybersecurity lab
10:28 - First projects for a cybersecurity lab
13:02 - Learn more about Paul Giorgi and XM Cyber
13:42 - Outro
About Infosec
Infosec’s mission is to put people at the center of cybersecurity. We help IT and security professionals advance their careers with skills development and certifications while empowering all employees with security awareness and phishing training to stay cyber-safe at work and home. More than 70% of the Fortune 500 have relied on Infosec Skills to develop their security talent, and more than 5 million learners worldwide are more cyber-resilient from Infosec IQ’s security awareness training. Learn more at infosecinstitute.com.
Karen Worstell is a 25-year veteran of the tech, IT and security space; she’s a senior cybersecurity strategist at VMware and a chaplain. This episode goes to many fascinating places, from her days learning coding on a TRS-80 computer, how her extremely visual and right-brained approach to learning has influenced her security journey, her experiences as a woman in the industry and how her work as a chaplain brought her back from a security industry hiatus to help people suffering chronically from burnout. There’s also a bit about XDR — and its a big deal!
0:00 - Burnout in cybersecurity
3:06 - Karen Worstell's start in cybersecurity
6:11 - A family of inventors
9:35 - Physical sciences and computer sciences
16:00 - Work as a senior cybersecurity strategist
18:18: - Working as a woman in cybersecurity
23:15 - Changes to make cybersecurity equitable
31:40 - Strategies for hiring equity in cybersecurity
34:00 - Burnout in cybersecurity
48:35 - Helpful cybersecurity organizations
51:37 - Why is XDR so important?
56:10 - Learn more about Worstell
56:44 - Outro
– Get your FREE cybersecurity training resources: https://www.infosecinstitute.com/free
– View Cyber Work Podcast transcripts and additional episodes: https://www.infosecinstitute.com/podcast
About Infosec
Infosec’s mission is to put people at the center of cybersecurity. We help IT and security professionals advance their careers with skills development and certifications while empowering all employees with security awareness and phishing training to stay cyber-safe at work and home. More than 70% of the Fortune 500 have relied on Infosec Skills to develop their security talent, and more than 5 million learners worldwide are more cyber-resilient from Infosec IQ’s security awareness training. Learn more at infosecinstitute.com.
Today on Cyber Work, Nir Valtman, CEO and co-founder of Arnica, discusses developer behavior-based security. In short, there are lots of ways that backdoors or vulnerabilities can make their way into developer code. One door we can close on these intrusions is implementing processes that detect behavior anomalies in developers. Think of your bank monitoring for unusual purchases calling you to ask whether you really just spent $300 on a bobblehead from The Last of Us that’s shipping from Brazil. If you did, not judging, full speed ahead. If not, then we’ve got a problem on our hands. Valtman explains the benefits and the limitations of behavior-based security measures, as well as tips for developers-in-training.
0:00 - Developer behavior-based security
2:56 - Nir Valtman’s start in cybersecurity
4:40 - Moving into the developer world
8:20 - Working as a cybersecurity CEO
10:33 - A typical day for a cybersecurity CEO
19:30 - Monitoring product features
20:15 - DevSecOps behavior-based security
27:42 - Flagging irregular online purchases
30:35 - Impact of pre-fab code on behavior anomaly detection
33:28 - GitHub impact on developer behavior and security
38:09 - Ensuring you don’t skimp on sec in DevSecOps
42:35 - What should future developers know?
44:56 - Skills and experiences for budding developers
51:09 - What is Arnica?
54:57 - Outro
– Get your FREE cybersecurity training resources: https://www.infosecinstitute.com/free
– View Cyber Work Podcast transcripts and additional episodes: https://www.infosecinstitute.com/podcast
These days, keeping your security, IT or research team close now that more of us than ever work remotely is a challenge. How do you keep team bonds strong when your main interaction path is your tiny little colleagues trapped in little squares on a computer monitor? Susan Morrow has been managing a remote team for almost two decades. She dispenses wisdom on coordinating schedules in multiple time zones, ensuring everyone’s moving toward the same goal and helping team members of all work styles to do and feel their best.
0:00 - Cybersecurity team remote work
2:30 - Remotely working with multiple teams
4:16 - What doesn't work remotely?
5:51 - Avoiding remote work pitfalls
7:27 - Solving team drift
9:19 - Learn more from Susan Morrow
9:58 - Outro
About Infosec
Infosec’s mission is to put people at the center of cybersecurity. We help IT and security professionals advance their careers with skills development and certifications while empowering all employees with security awareness and phishing training to stay cyber-safe at work and home. More than 70% of the Fortune 500 have relied on Infosec Skills to develop their security talent, and more than 5 million learners worldwide are more cyber-resilient from Infosec IQ’s security awareness training. Learn more at infosecinstitute.com.
James Stanger, chief technology evangelist at CompTIA, walks through their new Data+ certification. Infosec is proud to provide bootcamp and course training for a range of CompTIA certifications, and James helpfully breaks down the basics of data analytics, the types of learning you’ll need to engage in to pass and why security professionals have a lot more data analyst in their job role than they might think. All that, and a bit of geeking out about the humanities.
0:00 - CompTIA Data+
3:40 - How did James Stanger get into cybersecurity?
5:00 - From literature to IT
9:50 - Working for CompTIA as a tech evangelist
13:22 - What makes up a tech evangelist role?
18:00 - CompTIA's new Data+ certification
26:06 - Why is Data+ important for pros?
32:38 - Prerequisites for Data+ certification
40:05 - What does Data+ teach you?
43:53 - Training materials for Data+ certification
– Get your FREE cybersecurity training resources: https://www.infosecinstitute.com/free
– View Cyber Work Podcast transcripts and additional episodes: https://www.infosecinstitute.com/podcast
About Infosec
Infosec’s mission is to put people at the center of cybersecurity. We help IT and security professionals advance their careers with skills development and certifications while empowering all employees with security awareness and phishing training to stay cyber-safe at work and home. More than 70% of the Fortune 500 have relied on Infosec Skills to develop their security talent, and more than 5 million learners worldwide are more cyber-resilient from Infosec IQ’s security awareness training. Learn more at infosecinstitute.com.
Today on Cyber Work, my guest, Jack Nichelson, wants you to know something. AI is coming! But it’s not SkyNet; it’s not the rise of the machines. Whatever unnerving story you’ve read in the past few weeks about ChatGPT and what it will or won’t do to humanity, I’d like you to join us here and get a much fuller picture of AI as a tool and our role in shaping and building it.
0:00 - ChatGPT AI
2:50 - How Jack Nichelson got into cybersecurity
4:45 - Types of IT cybersecurity roles
6:57 - AI versus human value
10:46 - Life as a CISO
15:12 - The ChatGPT story
19:37 - Where is AI at right now?
24:20 - Actual applications of AI in the future
30:04 - Areas of study to enter cybersecurity and AI
34:27 - Where AI tools may lead cybersecurity
37:00 - Training for future AI malware
40:20 - Software to spot AI malware
44:50 - What is Inversion6?
46:55 - Learn more about Jack Nichelson
47:12 - Outro
– Get your FREE cybersecurity training resources: https://www.infosecinstitute.com/free
– View Cyber Work Podcast transcripts and additional episodes: https://www.infosecinstitute.com/podcast
About Infosec
Infosec’s mission is to put people at the center of cybersecurity. We help IT and security professionals advance their careers with skills development and certifications while empowering all employees with security awareness and phishing training to stay cyber-safe at work and home. More than 70% of the Fortune 500 have relied on Infosec Skills to develop their security talent, and more than 5 million learners worldwide are more cyber-resilient from Infosec IQ’s security awareness training. Learn more at infosecinstitute.com.
Amber Schroader, CEO of Paraben, explains the different ways to pursue a career in digital forensics, like pursuing a college degree or studying toward a certification. And if a certification, which one will take you on the path you want? Schroader also talks about what doors can open for you, where to get started, and which upper-level certs you should work toward so you’re prepared for the job you want.
0:00 - Breaking down digital forensics certifications
1:08 - Different ways to learn digital forensics
2:07 - Digital forensics college courses versus certifications
3:45 - Main digital forensics certifications and paths
5:20 - Finding a digital forensics niche
6:18 - Hands-on projects for digital forensics experience
7:25 - How to get started in digital forensics
8:34 - Learn digital forensics
9:01 - Outro
About Infosec
Infosec’s mission is to put people at the center of cybersecurity. We help IT and security professionals advance their careers with skills development and certifications while empowering all employees with security awareness and phishing training to stay cyber-safe at work and home. More than 70% of the Fortune 500 have relied on Infosec Skills to develop their security talent, and more than 5 million learners worldwide are more cyber-resilient from Infosec IQ’s security awareness training. Learn more at infosecinstitute.com.
Jacob DePriest, the VP and deputy chief security Officer at GitHub, talks about development security. In 2021, GitHub significantly ramped up its security department. DePriest told me all about the commitment to security and how you can move your organization toward a developer-focused security team. Whether you’re just hearing about GitHub now or you’re using GitHub from the moment your work day starts, you’ll want to check out this episode.
0:00 - GitHub's cybersecurity strategy
2:30 - How did you get into cybersecurity?
5:00 - Moving up in cybersecurity
8:57 - Working with NSA
10:08 - Working as a chief security officer
13:35 - Communication in cybersecurity
15:00 - What is GitHub?
17:46 - Coding as a team
19:30 - GitHub's security team
21:18 - Security threats GitHub faces
22:28 - GitHub's role in software security
25:10 - Navigating GitHub's tools
28:50 - How to study cybersecurity
30:54 - Entering software security
33:55 - Security tips for developers
36:45 - Learn more about DePriest and GitHub
38:25 - Outro
– Get your FREE cybersecurity training resources: https://www.infosecinstitute.com/free
– View Cyber Work Podcast transcripts and additional episodes: https://www.infosecinstitute.com/podcast
About Infosec
Infosec’s mission is to put people at the center of cybersecurity. We help IT and security professionals advance their careers with skills development and certifications while empowering all employees with security awareness and phishing training to stay cyber-safe at work and home. More than 70% of the Fortune 500 have relied on Infosec Skills to develop their security talent, and more than 5 million learners worldwide are more cyber-resilient from Infosec IQ’s security awareness training. Learn more at infosecinstitute.com.
Learn more about the (ISC)² CGRC certification: https://resources.infosecinstitute.com/overview/cgrc/
Enroll in a CGRC boot camp: https://www.infosecinstitute.com/courses/isc%C2%B2-cgrc-training-boot-camp/
Infosec instructor and returning guest Leighton Johnson talks about the recent (ISC)² CAP certification change: the Certified Authorization Professional (CAP) is now Certified in Governance, Risk and Compliance (CGRC). Why are they changing the name of the CAP certification? Is the CAP content going to change as well? What does this mean for the future? Let’s figure this out together.
0:00 - CAP vs. CGRC certification
1:40 - What jobs require a CGRC certification?
2:50 - Why change the CAP name to CGRC?
4:17 - Is CAP exam content different from CGRC?
6:00 - Should I upgrade CAP to CGRC?
7:35 - Study tips for the CGRC exam
9:13 - Learn more about CGRC
9:53 - Outro
About Infosec
Infosec’s mission is to put people at the center of cybersecurity. We help IT and security professionals advance their careers with skills development and certifications while empowering all employees with security awareness and phishing training to stay cyber-safe at work and home. More than 70% of the Fortune 500 have relied on Infosec Skills to develop their security talent, and more than 5 million learners worldwide are more cyber-resilient from Infosec IQ’s security awareness training. Learn more at infosecinstitute.com.
From the publisher's feed