
Sign up to save your podcasts
Or


Attendees
Guest: Ori Troyna
Guest title: Global head of product security at Payu
Company: Payu
Abstract
Payu, a global fintech gaint acquired Zooz , a small payment startup. In this episode we talk with Ori Troyna, Global head of product security at Payu about the challenges that such a merger between two very different companies with different engineering methodologies and how they cope with those challenges.
Timing:
1.14 Ori introduce himself
11.40 challenges of merging small companies into financial giants. Integrating different technologies stacks into one.
18.33 how to build the organizational structure the consolidate the different companies and technology stacks
21.30 understanding the acquisition considerations of PayU and its effect on security considerations
27.0 solving the consolidation challenges - the people angel. Moving to tribes and clans and providing security goals
34.30 the difference between product security and IT security
36.0 solving the consolidation challenges - the process angel. How to integrate different tribes and clans to create one joint development backlog and mature devops
46.40 solving the consolidation challenges - the technology angel. Building global infrastructure that support multiple projects
53.22 summary and last words
Attendees
Guest: Tal Arad
Guest title: Former CISO
Company: CEVA logistics
Abstract
Consuming SaaS from various vendors can be a challenging task, the first challenge is to distinguish who are the mature providers that you can trust your data with, and the second challenge is auditing them and their services. In this episode we talk with Tal Arad, former CISO of CEVA logistics about the challenges of selecting SaaS providers and how to auditing them wisely.
Timing:
0:35 introducing our guest
02:30 Introducing Ceva Logistics and the CISO challenges
5:55 How to get started in as a new CISO
9:20 Challenges with SaaS providers - distinguishing between mature and immature
Providers
16:15 tips for selecting SaaS providers
22:30 what happens when something happens and choosing providers carefully
24:50 Tips for managing ongoing relationships with SaaS providers
34:27 Summary and final words
Attendees
Guest: Oded Hareven
Guest title: Founder & CEO
Company: A-Key-Less
Abstract
Application Secret management is becoming one of the biggest challenges for application security. With cloud, CI/CD and micro services architecture we discover that we are using a growing number of encryption keys, API keys, SSH keys tokens and connection strings. In this episode we talk with Oded HarEven, Founder at A-Key-Less about the challenges of secret management and the way to build secure secret management solution.
Timing
0:00
Intro and introducing our guest
1:40
Application secret management - defining what secret is, and what is secret management
6.00
Challenges with encryption keys
9:47
How to handle application secret management and encryption keys - requirements and best practices
12.25
Zero trust in key management - what does it mean and how to implement it
20:10
The process of integrating keys with cloud platform
25:35
A-Key-Less state of the market approach
27.35
Summary and conclusions
From the publisher's feed