Sign up to save your podcastsEmail addressPasswordRegisterOrContinue with GoogleAlready have an account? Log in here.
A Podcast dedicated to forging iron clad relationships between developers, engineers, operations, and security practitioners by discussing hot topics in the world of DevSecOps. This podcast aims to ai... more
FAQs about Relating to DevSecOps:How many episodes does Relating to DevSecOps have?The podcast currently has 82 episodes available.
September 24, 2020Episode #012: What DevSecOps means to a SCRUM master with Jenn MolyneauxSend us a textJenn Molyneaux joins the crew as the very first guest! ( https://bit.ly/3ctCLJu ). Jenn is a Senior SCRUM Master who brings her wealth of experience and patience to the table to help us all understand how we can work better together. We had a great time recording this one and are excited to start getting more opinions and views on the show. We talk about DevSecOps in Agile/SCRUM, how to handle security issues, how to develop relationships across teams and getting leadership buy-in for your projects. We also get Jenn's opinions on bugs vs vulns, which we all know is a hot topic....more1hPlay
September 18, 2020Episode #011: Bugs vs Vulns - what's your opinion?Send us a textSecurity and Engineering go head to head in a conversation about bugs vs vulnerabilities and where we think they should fall in the grand scheme of product development. Unfortunately we threw this one together at the last minute as we had to scramble due to some life events. Keep an eye out for our intended episode next week on Agile/Scrum with Jenn!...more35minPlay
September 11, 2020Episode #010: Security Configs, Default Configs, and other decisions we regretSend us a textThis episode we riff on some of the hotter topics we discussed during Episode 9 as we cover security misconfigurations, default misconfigurations, and the responsibility of application/infrastructure configs in an organization. We talk about how to best interact with other teams to ensure configurations are manageable, maintained, and in the right hands...more41minPlay
September 04, 2020Episode #009: OWASP Top 10: Awareness, not MeasurementSend us a textIn this episode we cover the OWASP Top 10, a popular security awareness document and how DevOps and Product Engineering are typically exposed to it. While it's made waves in the industry we discuss how to use and how not to use this document and give some opinions on categories that fall into the DevSecOps sphere of work. This isn't your typical "What is SQL Injection" episode, so give us a listen and hopefully you come out the other side with a new viewpoint on using the top 10 to help your organization. Also, Ken introduces this episode after a little too much coffee, so in case you're wondering - it does NOT start in 2x speed....more42minPlay
August 19, 2020Episode #008: Testing Depths of the DevSecOps River with Both FeetSend us a textThere are so many types of tests across DevSecOps and we try to cover as many as possible from SAST to Contract testing. Simon covers his dislike for test-driven development, Ken talks through writing security tests against requirements, and Jamieson brings automation testing to light with new toolsets and process developments. We all had some preconceived notions going into this, but it was an eye opening and long episode. We hope you enjoy!...more56minPlay
August 12, 2020Episode #007: Service Mesh, more than a Sean Connery sidecar to your Indiana Jones AppSend us a textIn this episode we get back to tech in the DevOps centric topic of Service Mesh. Ken and Simon chat with Jamieson about concerns and first thoughts on service mesh in their respective experiences. If you're looking at spinning up service mesh within your organization or just want to learn more about it this episode gives highlights from different professional perspectives. We end with some ways to pitch this internally to get buy in from departments that may challenge your next push into service mesh....more43minPlay
August 05, 2020Episode #006: How Engineering Titles Affect Your Communication with Development and Product Engineering TeamsSend us a textIn this episode we take another people centric approach with Simon Dollo as we explore the difference between developers and product engineers. We explore Simon's engineering history and work to identify more meaningful and effective ways of communicating with people writing code. ...more42minPlay
July 31, 2020Episode #005: Know Your Audience, the Face of Documentation and Training in a DevSecOps WorldSend us a textIn this episode we discuss product engineering security Easter eggs and try to stay on track talking about how to get other departments and teams to adapt your latest and greatest process, tool, or optimization. The conversation quickly devolves into a side track on documentation where we discuss the pitfalls of traditional documentation tactics in the fast paced world of Agile development and continuous deployment. Speaking of Easter Eggs, Ken's cat makes an earnest request to be a part of the show....more38minPlay
July 22, 2020Episode #004: Be careful with your logs aka a hand grenade with a dictionary attached to itSend us a textThis time on Relating to DevSecOps we cover application logging, how it's viewed by different teams and what those teams are looking to get out of them. We cover some tips and tricks with logging challenges like ACTUALLY implementing a logging standard, the importance of logging severity levels, and the challenge with the appropriate amount to log. Join us for our divergent opinions and challenges we've faced in the real world....more39minPlay
July 08, 2020Episode #003: Bookending DevSecOps starting with Threat ModelsSend us a textStarting on the left side of the SDLC, we talk about Threat Modeling experiences from all perspectives and the fundamental issues with checkbox security. We almost get through a whole episode without making fun of Perl and are still waiting for a Perl developer to reach out and tell us how wrong we are. We attempted to get to application logging perspectives but ran into a timewall. Keep an eye out for Episode #004 as we tackle DevSecOps from both sides....more35minPlay
FAQs about Relating to DevSecOps:How many episodes does Relating to DevSecOps have?The podcast currently has 82 episodes available.