Seeding AppSec

Empowering Developers to Impact Security (Positively)


Listen Later

In our world of coding, how we think and act might be our best shield in the mix of tech and safety. It's not just the lines of code that matter, but the heart behind them. As tech keeps changing, our choices and teamwork become our guiding light, shaping a safer digital space.


In today’s episode of the Seeding AppSec, we explore the compelling parallels between software development and security with Cassio Goldschmidt. Cassio unveils the duality of backlog management and how often, in the rush of prioritization, numerous tickets find themselves lost in the shadows. But beyond tools, tactics, and processes, he delves deep into the critical role culture plays. He dives into why fostering a culture of security transcends mere compliance and becomes the bedrock for genuine progress and empowerment. And as we wrap, Cassio offers golden nuggets of advice for aspiring security professionals and shares a personal recommendation that promises serenity amidst chaos.


Whether you're a developer, a security enthusiast, or just curious about the nexus between the two, this episode promises insights that will both enlighten and entertain.



What we cover on the episode:


[00:00 - 21:18] Empowering Developers and Shifting Left

  • Empowering developers is crucial for secure coding and design, fostering innovation and ownership.
  • Shifting left in security involves early detection and prevention of vulnerabilities, reducing future complexities and embarrassment.
  • Trustworthy automation tools are vital for effective garbage-in, garbage-out prevention in the development process.
  • Ensuring Git posture is essential, including verifying code reviewers' identities and detecting unusual comment styles to enhance security.
  •  

    [21:19 - 37:10] Security Beyond Developers

    • Security isn't just about developers; it also involves aspects like branching strategy, pull request reviews, and status checks.
    • Address vulnerabilities early during development, as fixing them in a backlog can lead to neglect and increased risk.
    • Aligning incentives between security and development is crucial for better security outcomes and involves education, automation, and empathy.
    • Cultivating a culture of security is essential, fostering awareness and collaboration between security and development teams.

    • Connect with Cassio!

      LinkedIn: https://www.linkedin.com/in/cassiogoldschmidt/

      Check out ServiceTitan’s services at: https://www.servicetitan.com/


      We hope you enjoyed this edition of Seeding AppSec! Check out the latest trends in application security discussed with our esteemed guests from around the globe. Don't miss any future episodes; subscribe to Seeding AppSec on Spotify, YouTube, Google Podcasts, or Apple Podcasts.

       

      This podcast is proudly brought to you by Arnica, a revolutionary application security solution reshaping how AppSec teams tackle risk identification and mitigation. Explore Arnica.io for detailed information about their cutting-edge security solution, featuring real-time pipelineless risk identification and git posture management. Protect your developers, code, and products without compromising development velocity.

       

      Stay connected and informed by following Arnica.io on LinkedIn and Twitter for the latest updates and insights on application security.

       

      Thank you for joining us on this enlightening journey into the world of Application Security! Remember to prioritize security and continue seeding AppSec in your organizations. Until next time, stay secure and keep innovating!

       

      Key Quotes

       

      "Empowering People is always a good idea. If people trust that you know your stuff, that you are not throwing things over the fence for them, they will come and ask your opinion, and they will ask, how to best create or develop solutions." Cassio Goldschmidt

       

      "Creating a culture of security goes way beyond just development, but really the entire company. And you really start creating awareness." - Cassio Goldschmidt

      ...more
      View all episodesView all episodes
      Download on the App Store

      Seeding AppSecBy Arnica IO