The Secure Developer

Navigating The Terrain Of Shared Responsibility With Iftach Ian Amit


Listen Later

Today we have a great guest who brings battle tested perspectives on security from both inside and out, Ian Amit! Ian is Chief Security Officer at Cimpress and founder of the Penetration Testing Execution Standard as well as Tel Aviv DEFCON group (DC9723). Ian has worked on everything from pen testing to red teaming, risk management, research, and national security too. We kick things off hearing about Ian’s journey in the field starting out tinkering with computers in his early teens and working on application security in its nascent phase, before he moved into consulting and then went full circle from the vendor to customer side in his current position. Ian moves on to talk about his approach to vetting vendors in light of being one himself once, and the experiences he had working at Amazon of the difficulty of drawing the line as far as shared responsibility for security between cloud providers and clients goes. We then move to hear more about the mass customization services Cimpress provides before digging into their practices for offering custom security to their clients. Ian sheds light on the minimum standards Cimpress’s clients need to meet in regards to their secure software development practices and more. He talks about how Cimpress guides their clients in this manner using a secure SDLC framework and the ‘paved road’ approach, weighing in on how this is also expanding their best practices further afield. We wrap things up hearing about the challenge of finding metrics to measure their evolving systems, and Ian talks about their use the NIST Cyber Security and FAIR frameworks in this regard. Tune in for some brilliant insights from a man who has done it all!

Follow Us

  • Our Website
  • Our LinkedIn

...more
View all episodesView all episodes
Download on the App Store

The Secure DeveloperBy Snyk

  • 4.7
  • 4.7
  • 4.7
  • 4.7
  • 4.7

4.7

21 ratings


More shows like The Secure Developer

View all
The a16z Show by Andreessen Horowitz

The a16z Show

1,104 Listeners

Risky Business by Risky Business Media

Risky Business

372 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,088 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

73 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners

The 404 Media Podcast by 404 Media

The 404 Media Podcast

399 Listeners

Prof G Markets by Vox Media Podcast Network

Prof G Markets

1,475 Listeners

Training Data by Sequoia Capital

Training Data

40 Listeners