EPISODE · Feb 13, 2020 · 44 MIN
Alyssa Miller — Experiences with DevOps + Automation and beyond
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Automating security tests is useful, but it does not by itself make a development team secure. Alyssa Miller, a former developer and application security practitioner, explains how DevOps changes the way security work should happen. She begins with her path into hacking and a striking penetration-test story in which a web application exposed domain-level privileges. The discussion then moves toward prevention: threat modeling during user-story development, reusable reference architectures, and feedback that helps engineers make better decisions early. Alyssa shares lessons about organizational change, realistic starting points, and the limits of adopting tools without changing habits. She also offers career advice for newcomers, emphasizing curiosity, clear interests, and the many paths that can lead into security.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Alyssa Miller:→ Alyssa Miller’s websiteMentioned in this episode:→ Threat Modeling: Designing for Security — first edition→ Jenkins→ BSides Las VegasFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 DevOps, automation, and Alyssa Miller02:30 Alyssa’s path from development into security07:06 What makes application security compelling08:19 Reaching domain admin through a web application12:39 Defining DevOps through practical experience15:21 Where security fits in DevOps16:43 Threat modeling early in development22:41 Asking security questions within user stories25:46 Moving beyond automated scanning30:35 Reference architectures that help developers31:06 Organizational challenges in adopting DevOps33:41 Choosing a realistic starting point36:55 Career advice and finding your interests41:27 The Blue Team Con community
Embed this episode
What this episode covers
Automating security tests is useful, but it does not by itself make a development team secure. Alyssa Miller, a former developer and application security practitioner, explains how DevOps changes the way security work should happen. She begins with her path into hacking and a striking penetration-test story in which a web application exposed domain-level privileges. The discussion then moves toward prevention: threat modeling during user-story development, reusable reference architectures, an...
Ready to play
Alyssa Miller — Experiences with DevOps + Automation and beyond
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.