The Security Repo

The Security Repo

By Mackenzie Jackson & Dwayne McDanielTechnology
Download on the App Store

The Security Repo episodes

  • Artificial intelligence, a friend or foe in cyber security - with Simon Maple from Snyk

    With the rapid development of AI we are often left wondering if AI is our friend or foe in security. In this episode, I sit down with Simon Maple from Snyk to discuss just that. We explore the different applications of AI in security and where the future is going. It's an interesting discussion so you don't want to miss it!

    Show Links: Snyk.io Blog: https://snyk.io/de/blog/ Featured article: https://snyk.io/blog/10-best-practices-for-securely-developing-with-ai/
    x.com (Formally twitter) https://twitter.com/sjmaple
    Simon BIo:
    Simon has a long and impressive record working in technology from working in startups to working for massive companies like IBM and now Snyk. Simon today is the Principle developer advocate at Snyk having previously held many leadership roles as the field CTO (again at Synky) and the Director of developer relations. He is a world-renowned speaker having spoken at many conferences including JavaOne, Devoxx Fr, Devoxx UK, JavaZone, JavaLand, JAX, and many many more.
    Today he is using his decades of tech experience to uncover many of the mysteries surrounding AI and that is what we have the privilege of discussing with him today. He uses his experience in both AI and security to answer the most difficult and interesting questions I could possibly come up with. Without further delay. Here is Simon Maple for our discussion on the new frontier in security, artificial intelligence.

    39 min
  • Scaling security and AppSec in fast moving enterprises with Jeevan Singh

    Application security can be a difficult task at all levels of a company. But as a start-up grows into an enterprise, or existing companies evolve. How do you effectively scale your security program? We have an amazing guest, Jeevan Sinhg who is the director of product security at Twilio and he is here to talk about how to scale an application security program.

    BIO Jeevan Sinhg
    Jeevan's lifelong fascination with defensive security began at a young age when I played the center-back position on my youth soccer team. I loved the thrill of preventing opponents from scoring and was intrigued by the strategy behind defensive maneuvers. The fascination grew throughout my adolescence and into university when a close friend showed me how malicious users could penetrate systems and taught me how to prevent attacks. For as long as I can remember, I’ve continually examined scenarios from every imaginable angle so I can find weaknesses and penetrate defenses in order to protect myself. As an Information Security Architect, I am still driven by this fascination and apply these same principles as I protect the company and guard customer data.
    His philosophy is to build security from the ground up and make it as transparent as possible. He does this by collaborating with software architects and senior developers to identify practical options for building secure systems, empowering developers, and working with sysadmins and network engineers to determine effective approaches for operating securely. He also works toward creating a positive security culture, instilling employees with security knowledge, and building defenses against security threats.

    39 min
  • Enterprise Software Distribution - Managing updates and security in enterprise software at scale

    One of the many advantages of the cloud revolution is that SaaS products are continuously updated, security issues are patched quickly, and it's something the consumers are less concerned about. But what about enterprise products, how do you get that same level of update efficiency and security on large on-premise products. This is one of the topics we cover in this episode with the crew from replicated as Andrew Storms VP of security and Ian Zink senior developer advocated diving into this complex and vital topic.

    Links
    Replicated - https://www.replicated.com/
    Replicon - https://www.replicated.com/resources/replicon-q2-2023
    BIO Andrew Storms
    Andrew Storms is the VP of Security at Replicated. Previously, Storms was Sr. Director of Security Products for Copado and VP of Security Services and Research at New Context. For 30 years, he has been responsible for defining and enforcing security programs for numerous security companies.
    Andrew has led initiatives with electrical utilities and the Department of Energy to research methods for automated cybersecurity threat detection and response for industrial control systems. Andrew was heavily involved in creating the STIX (Structured Threat Information Expression) standard.
    Storms' commentary on IT security issues has appeared in CNBC, Forbes, The New York Times, and many other publications. In addition, he is a CISSP, a member of Infragard, and a graduate of the FBI Citizens' Academy.
    BIO Ian Zink
    Full stack developer for 3 advanced neural networks. Ideas by the many, not by the few. Lit a fire with gasoline and lived to regret it. Wrote a program once and it compiled the first time. I dream in yaml. Also, ~20yrs doing infrastructure, performance & availability engineering, app development, ci/cd, software engineering, consulting, and dev advocacy.

    38 min
  • Securing data in a world of AI with Jeremiah Jeschke

    Many companies are banning AI systems like ChatGPT to prevent data from being leaked, but is that a viable solution? We sit down with Jeremiah Jeschke, the CEO at OfficeAutomata, to discuss the future of security in a world of ChatGPT and other AI systems.


    Links:

    Office Automata: https://officeautomata.com/

    Linkedin https://www.linkedin.com/in/jeremiah-jeschke/


    Jeremiah has over 10 years of AI Development/Programming and 10 years of CEO experience. Previously, in both private work and Active Duty as USAF Captain, he supported large-scale US Air Force development programs as a Program Manager and consultant. His projects included polar satellite development, satellite ground control station development; US Special Operations research and development; and multiple B-2 Stealth Bomber upgrade developments. Today he is the CEO of officeAutomata which is a company that helps businesses know themselves. We enable companies to improve and automate workplaces processes through Enterprise Intelligence and Process Discovery.


    30 min
  • Getting boardroom buy-in for security - CISO conversations with Walt Powell

    Getting funding to build effective security programs is challenging and often it fails because security leaders are not telling the boardroom the right 'story'. In this episode with Walt Powell we discuss exactly how to overcome these challenges by understanding how to effectively communicate with the board by expressing security challenges into a language they will relate to. We also discuss the journey to becoming a security leader and the exact skill you need to develop to get there.

    BIO: Walt is a cybersecurity thought-leader that specializes in providing executive guidance around risk, governance, compliance and IT security strategies. He helps IT organizations build strong teams and programs that can securely enable their business goals. He partners with top businesses to help design and deliver solutions that will both lead and ensure the success of their secure digital transformations.

    38 min
  • Social engineering, phishing and building grass roots communities with Dan and Ken

    In this episode, we sit down with Daniel Niefeld and Kenneth Nevers to talk about their journey into security, creating security conferences and building grass roots cyber communities.

    Get your tickets to RedHackCon free (save $200) as a Security Repo Listener use the code HRCGGuardian23 when purchasing tickets https://www.hackredcon.com/ (First 5 tickets only).
    Daniel and Ken are two of the founders of RedSeer Security, a penetration testing company based in Florida. Both however have deep roots in the cyber community including organizing and founding many conferences and events but also are the founders of BuildCyber non-profits to help low-income, veterans, neurodiverse and at-risk communities transition into cyber security. In this episode, we not only dive into Dan and Kens background but take a look at how to become involved in the cyber community and what it takes to make and organize an effective security conference.
    Show notes:
    HackRedCon -https://www.hackredcon.com/
    Build Cyber non-profit - https://www.buildcyber.org/
    RedSeerSecurity - https://www.redseersecurity.com/
    BIO: Kenneth Nevers, CSO | Offensive Security Lead at Red Seer Security, Inc.
    Current Certifications: OSEP, OSCP, CRTO, CRTE, CRTP, PAWASP
    Bug Bounty Hall of Fames: Oracle, Rackspace, Dell, TripAdvisor
    Ken holds an associate degree in computer and information science with a major in Cyber and Network Security from ECPI University in addition to several red teaming and penetration testing certifications. In his free time, Ken co-organizes BSides Roanoke, co-leads the Roanoke Information Security Exchange, is a member of the Roanoke Linux Users Group, and volunteers on the security team for DerbyCon, the Red Team Village at DefCon, and several other conferences. He is the co-founder of Hack Space Con, a co-organizer of Hack Red Con, leads the offensive security team at Red Seer Security, Christian, daddy to a daughter, two doggies, a kitty and 4 fish, plays guitar and tells dad jokes.
    BIO: Daniel Niefeld
    Daniel is the cofounder of Hack Red Con, Hack Space Con, Build Cyber and Red Seer Security. When not being tasks with keeping the hallways and bathrooms clean as the Chief Janitor, he oversees the Social Engineering program with Red Seer. With 20 years of experience as an entrepreneur, his background includes finance, risk management, underwriting complex transactions in Private Equity and technology development. He studied finance and computer science at Florida Atlantic University and Florida International University and is an advisor/Board member to a variety of organizations including the USPSC, Medical Defense Company and Rotary International Global Impact.

    49 min
  • Code signing and securing the software supply chain with Billy Lynch

    In this episode, we go on a deep dive with Billy Lynch from Chainguard into application and code signing and how it can be used to ensure the supply chain is legitimate. Billy has an impressive background including spending 8 years at Google before joining Chainguard and not only helps us understand how signing can be used in security but also what is the latest developments and technology in this field.


    Links:

    https://www.chainguard.dev/

    https://www.linkedin.com/in/wflynch/


    BIO

    Billy is a staff software engineer at Chainguard, working on developer tools and securing software supply chains for everyone! He is an active contributor and maintainer to the Sigstore and Tekton projects, and is the creator of Gitsign. Prior to working at Chainguard, Billy worked on several developer tool teams at Google including Cloud Build, Google Code, and Cloud Source Repositories.

    35 min
  • Getting started in AppSec with Tanya Janca SheHacksPurple

    In this episode, we sit down with Tnaya Janca and discuss her journey from being a developer for government agencies to becoming one of the most recognizable faces in application security and cyber security in general. This episode is especially great for anyone thinking about starting a career in cyber security and wants to know how to get started but also contains amazing insights for anyone already in the field wanting to level up.

    Show Links:
    Personal Website / Blog : https://shehackspurple.ca/
    We hack purple community https://wehackpurple.com/
    [Book] Alice and Bob learn Application Security https://tinyurl.com/7p9jy9zp
    Owasp: https://owasp.org/
    Find Local Owasp Chapters: https://owasp.org/chapters/
    Social Media for Tanya: https://www.linkedin.com/in/tanya-janca/
    Twitter: https://twitter.com/shehackspurple
    BIO: Tanya Janca, also known as SheHacksPurple, is the best-selling author of Alice and Bob Learn Application Security. She is also the founder of We Hack Purple, an online learning community that revolves around teaching everyone to create secure software. Tanya has been coding and working in IT for over twenty-five years, won countless awards, and has been everywhere from public service to tech giants, writing software, leading communities, founding companies and ‘securing all the things’. She is an award-winning public speaker, active blogger and podcaster, and has delivered hundreds of talks on six continents. She values diversity, inclusion, and kindness, which shines through in her countless initiatives.

    49 min
  • Securing the remote workforce, the future of cloud development environments

    In this episode, we sit down with Vedran Jukic, co-founder and CTO of Code Anywhere and Tomma Pulljak Senior Developer at Code Anywhere to talk about the future of development environments. We go into detail on exactly what cloud development environments are and how they can help keep the remote workforce of today secure.

    Links:
    https://codeanywhere.com/
    Bios:
    Vedran Jukic is the CTO and Co-Founder of Codeanywhere. He started the company alongside the CEO Ivan Burazin with the vision of enabling all developers to work in the cloud. They were one of the first to enter the CDE space 12 years ago and are still working on making their vision a reality.
    Toma Pulljak is 22 years old and works as a Software Developer at Codeanywhere and is also a computer science student. He handles all B2B integrations and is the lead developer for IDE customizations.

    27 min
  • Understanding digital forensics with Desi - A deep dive post breach investigations

    In this episode we sit down with Desi who is an expert in digital forensics. We explore exactly what digital forensics is, how it can be used to catch cyber criminals and what can we do in a breach to preserve evidence. It is a fascinating conversation and full of great information from the inner workings of forensics to the crazy world of deep fakes.


    Guest Bio: Desi has a strong background in IT incident response but also has spent time in industry doing insider threat management and industrial incident response. He is currently one of the cohosts at the Forensic Focus podcast.

    He has hobbies that revolve around more things cyber including CTFs but does make time for his dogs, gym, and gaming.


    Show links:

    International Association of Forensic Sciences (IAFS) 2023 - https://iafs2023.com.au/ 

    Part of that the Sydney Declaration which is the change we were talking about - https://iafs2023.com.au/sydney-declaration/ 

    ICCWS Papers- https://papers.academic-conferences.org/index.php/iccws

    DFRWS Papers - https://dfrws.org/presentation/ 

    SANS White Papers - https://www.sans.org/white-papers/ 

    Forensic Focus content https://www.forensicfocus.com/ 

    Want to learn some technical skills https://blueteamlabs.online/ is a fun place with free/paid content. I run challenge nights on my discord if people want to come along, always happy to help.


    30 min

About The Security Repo

From the publisher's feed

The security repo is a podcast that focuses on real world security issues we are all facing today. We will take deep dives into news events and have exclusive interviews with security leaders on the…