The Security Repo

The Security Repo

By Mackenzie Jackson & Dwayne McDanielTechnology
Download on the App Store

The Security Repo episodes

  • Enhancing Security Through Community and Innovation - A Conversation with Avi Douglen

    This episode we are joined by Avi Douglen, Founder and CEO of Bounce Security. Avi, a key figure in the security community and former OWASP chapter chair. The discussion covers the significance of OWASP, its resources, threat modeling and Avi's personal journey within the organization.

    Listeners will gain insights into the concept of value-driven threat modeling and how it can enhance security measures by focusing on what truly matters for a product. Avi also shares his views on the unique challenges and risks the security community faces, the necessity of inclusivity, and the pivotal role of threat modeling in security processes.
    Avi also gives us his insights into the best and worst security advice they’ve encountered, providing both humorous and thought-provoking anecdotes. Whether you're a seasoned security professional or new to the field, this episode is packed with valuable takeaways on building and maintaining robust security practices. Tune in to learn from Avi’s extensive experience and his innovative approaches to securing products effectively.
    Show Notes:
    Social Media for Avi
    Linkedin - https://www.linkedin.com/in/avidouglen
    Twitter (X) - https://twAvi Douglen - Bounce Security | LinkedInitter.com/sec_tigger
    Bounce Security - https://www.bouncesecurity.com/
    Avi on OWASP - https://owasp.org/www-board-candidates/2023/avi_douglen
    OWASP Global Lisbon - https://owaspglobalappseclisbon2024.sched.com/avid2

    41 min
  • Behind the Scenes of Offensive Security with Bobby Kuzma

    Today we sit down with Bobby Kuzma, Director of Offensive Cyber Operations at Pro Circular and adjunct professor at the University of Washington. Bobby shares his unique journey into the world of penetration testing, including how he accidentally acquired his CISSP certification. We delve into the fascinating world of offensive security, discussing the highs and lows of pen testing, the importance of creativity in cybersecurity, and Bobby’s current work on leveraging AI to enhance security testing. Tune in for an insightful conversation filled with real-world stories, expert advice, and a look at the future of cybersecurity.Show NotesBobby’s Linkedin - https://www.linkedin.com/in/bobbykuzma/

    Introduction - 0:00 Accidentally getting CISSP - 1:09Talking about failures in pen-testing - 6:33 Stories when things go wrong - 9:30 Legal issues with pen-testing - 17:30 Have you been arrested? 21:00What advice would you give to your younger self - 23:00 Best and Worst - 28:16

    34 min
  • Frameworks and Relationships: J Wolfgang Goerlich on Security Strategy

    Today we welcome J Wolfgang Goerlich, an advisory CISO, mentor, and strategist. We delve into the intricacies of security design frameworks and the importance of building and maintaining relationships in the cybersecurity field. Wolfgang shares his expertise on creating effective security programs, fostering trust within teams, and navigating the challenges of the CISO role. Tune in to gain valuable insights on cybersecurity strategy and the significance of collaborative relationships in achieving security goals.



    Show Notes:

    Linkedin: https://www.linkedin.com/in/jwgoerlich/

    X / Twitter: https://x.com/jwgoerlich

    Website: https://jwgoerlich.com/

    Securing Sexuality: https://www.securingsexuality.com/



    Introduction - 0:00

    Security Design Framework - 1:00

    Security obstacles & user experience - 6:50

    Become a CISO - 9:05

    Wolfgang's journey to CISO - 12:50

    Managing relationships in security - 17:10

    Building effective teams - 28:30

    Best and Worst - 29:40


    37 min
  • Nuclear Security & Cyber Resilience: Insights from KPMG's Andrew Elliot

    Today we dive into the fascinating world of nuclear energy and cybersecurity with Andrew Elliot, a senior manager at KPMG's cybersecurity team. Andrew shares his journey from a nuclear engineer to a cybersecurity expert, providing unique insights into the importance of security culture, the resurgence of nuclear energy, and the critical role of cybersecurity in protecting critical infrastructure. Tune in to explore the complexities of nuclear security, the significance of cybersecurity training, and the future of energy security.


    Show Notes:

    Linkedin - https://www.linkedin.com/in/andrew-elliot-3a25b95b/


    0:00 - Introduction

    1:07 - Getting started in nuclear energy

    3:35 - Resurgence in nuclear

    9:55 - Nuclear security to KPMG

    12:15 - Effective security exercises

    16:20 - Lessons from nuclear security

    19:45 - The goal of security in companies

    21:50 - Opinion on Cyber Insurance

    26:50 - Where /when to invest in security

    32:02 - Best and Worst


    38 min
  • Securing the Future - The Art of Threat Modeling with Paul McCarty

    In this episode of The Security Repo, we dive deep into the world of threat modelling with Paul McCarty, a veteran in the field of DevSecOps and founder of SecureStack. Paul shares his journey from being a Unix admin to working with high-profile organizations like NASA and GitLab. We explore the essentials of threat modeling, the significance of cloud-native security, and frameworks he has developed for threat modeling like TVPO. Tune in to learn how to stay ahead in the ever-evolving landscape of cybersecurity.


    Show Notes

    Paul’s GitHub https://github.com/6mile

    DevSecOps Playbook - https://github.com/6mile/DevSecOps-Playbook

    Secure Code Red training - https://sourcecodered.com/Linkedin - https://www.linkedin.com/in/mccartypaul/


    Introduction: 0:00

    Pauls Journey: 1:10

    the Cloud Native Mission: 2:55

    Pauls History with Threat Modeling: 4:00

    TVPO Framework for Threat Modeling 6:52

    When Should Companies Start Threat Modeling 10:15

    When to Threat Model: 12:00

    Unique Risks of Threat Modelling Open-Source 13:50

    Red Team Code Puppets: 21:48

    Best and Worst: 28:00

    33 min
  • Pen Testing in Academia - University Cybersecurity Challenges with JR Johnson

    In this episode of The Security Repo, we dive into the fascinating world of cybersecurity with JR Johnson, a seasoned information security professional with over 14 years of experience. JR shares his journey from web development to penetration testing and cybersecurity consulting, highlighting the unique challenges faced by higher education institutions. Tune in to learn about the complexities of securing university networks, the importance of foundational security practices, and JR's expert advice for both IT professionals and students. Whether you're interested in cybersecurity or work in academia, this episode offers valuable insights into protecting educational environments in the digital age.

    Social Media for JR
    X (Twitter): https://x.com/infosecjr
    Linkedin: https://www.linkedin.com/in/jr-johnson-853952203/

    41 min
  • From Desktop Support to Red Team: Brendan Hohenadel Journey in Cybersecurity

    Join us in this episode of The Security Repo Podcast as we dive into the world of cybersecurity with Brendan Honadle. From his humble beginnings in desktop support to becoming a skilled red teamer, Brendan shares his inspiring journey and fascinating stories from the field. Discover the strategies, tools, and techniques used in offensive security, and gain insights into the challenges and triumphs of penetration testing. Whether you're a cybersecurity enthusiast or a seasoned professional, this episode is packed with valuable lessons and real-world exploits you won't want to miss.


    41 min
  • Navigating AI in Cybersecurity: Insights from Sonya Moisset

    In this episode of The Security Repo, we are thrilled to welcome Sonya Moisset, a Senior Advocate at Snyk and a renowned expert in DevSecOps, cybersecurity, and AI. With a wealth of experience as a public speaker, mentor, and top contributor to the tech community, Sonya shares her deep insights into the evolving landscape of AI in cybersecurity.

    Join us as we dive into the pressing issues surrounding generative AI and large language models (LLMs), including the concept of shadow AI, the risks of using AI tools without proper oversight, and real-world examples of security breaches involving AI. Sonya discusses the importance of implementing robust security policies and fostering an open dialogue within organizations to mitigate these risks.

    We also explore fascinating topics such as prompt injection attacks, the role of AI in both offensive and defensive cybersecurity strategies, and the emerging frameworks guiding ethical AI use. Whether you're a security professional, a developer, or simply curious about the intersection of AI and cybersecurity, this episode offers valuable knowledge and practical advice.


    .Show Links

    Sonya Moisset social media links

    Linkedin: https://www.linkedin.com/in/sonyamoisset/

    X (Twitter): https://x.com/SonyaMoisset

    Introduction: 0:00

    What are the security risks with AI and LLMs: 1:10

    Prompt Injection Car Dealership: 6:39

    Prompt Injection: 8:46

    Guardrails for AI: 16:00

    Using AI for Red Teaming: 25:19

    Regulations for AI security 32:16

    Best and Worst: 34:10


    37 min
  • Securing Kubernetes Dashboards: Insights from Tremolo Security's CTO

    In this episode of The Security Repo, Dwyane McDaniel and Marc Boorshtein delve into the intricacies of Kubernetes dashboard security. Marc, the CTO of Tremolo Security, brings his extensive experience in identity and access management to the table, discussing the challenges and best practices for securing Kubernetes dashboards. The conversation explores the importance of dashboards, common security pitfalls, and innovative solutions to enhance user access and safety. Tune in for valuable insights on navigating the complex landscape of Kubernetes security.

    Show Notes
    Learn more about Tremolo - https://www.tremolosecurity.com/
    Follow Marc
    Linkedin - https://www.linkedin.com/in/marc-boorshtein-5979a82
    Twitter (X) - https://x.com/mlbiam
    Intro: 0:00
    Kubernetes dashboards, why?: 0:45
    Why don't we talk about k8 dashboard: 3:50
    Security concerns with Dashboards: 10:37
    The value of dashboards in k8: 12:37
    What is Tremolo: 18:55
    Common pitfalls for K8 security: 26:10
    Besta and worst: 34:46

    40 min
  • The Secrets behind GitGuardian: Building a security platform with Eric Fourrier

    Join us this week as we host Eric Fourrier, co-founder and CEO of GitGuardian. Discover the journey of GitGuardian from a side project to a leading code security platform. Eric shares insights on the startup's growth, the integration of AI in security, and the future of protecting digital assets. Tune in for an engaging discussion on advancing code security in our digital world.

    Show Notes:
    GitGuardian https://gitguardian.com
    State of Secrets Sprawl Report https://www.gitguardian.com/state-of-secrets-sprawl-report-2024
    GitGuardian Blog https://blog.gitguardian.com
    Eric Fourrier Socials
    Linkedin: https://www.linkedin.com/in/ericfourrier/
    inro: 0:00
    Origin of GitGuardian: 0:55
    Why wasn't secrets detection a big problem: 5:08
    State of Secrets Sprawl Report: 09:50
    Can we solve secret leakage: 18:08
    Finding secrets outside source code: 22:22
    The evolution of GitGuardian: 25:18
    Single pane of glass: 30:15
    The problem of remediation: 32:55
    The role of AI in security tools: 36:10
    Best and Worst: 42:25

    46 min

About The Security Repo

From the publisher's feed

The security repo is a podcast that focuses on real world security issues we are all facing today. We will take deep dives into news events and have exclusive interviews with security leaders on the…