Alyssa Miller — Experiences with DevOps + Automation and beyond episode artwork

EPISODE · Feb 13, 2020 · 44 MIN

Alyssa Miller — Experiences with DevOps + Automation and beyond

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Automating security tests is useful, but it does not by itself make a development team secure. Alyssa Miller, a former developer and application security practitioner, explains how DevOps changes the way security work should happen. She begins with her path into hacking and a striking penetration-test story in which a web application exposed domain-level privileges. The discussion then moves toward prevention: threat modeling during user-story development, reusable reference architectures, and feedback that helps engineers make better decisions early. Alyssa shares lessons about organizational change, realistic starting points, and the limits of adopting tools without changing habits. She also offers career advice for newcomers, emphasizing curiosity, clear interests, and the many paths that can lead into security.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Alyssa Miller:→ Alyssa Miller’s websiteMentioned in this episode:→ Threat Modeling: Designing for Security — first edition→ Jenkins→ BSides Las VegasFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 DevOps, automation, and Alyssa Miller02:30 Alyssa’s path from development into security07:06 What makes application security compelling08:19 Reaching domain admin through a web application12:39 Defining DevOps through practical experience15:21 Where security fits in DevOps16:43 Threat modeling early in development22:41 Asking security questions within user stories25:46 Moving beyond automated scanning30:35 Reference architectures that help developers31:06 Organizational challenges in adopting DevOps33:41 Choosing a realistic starting point36:55 Career advice and finding your interests41:27 The Blue Team Con community

Episode metadata supplied by the publisher feed · Published Feb 13, 2020

Embed this episode

Automating security tests is useful, but it does not by itself make a development team secure. Alyssa Miller, a former developer and application security practitioner, explains how DevOps changes the way security work should happen. She begins with her path into hacking and a striking penetration-test story in which a web application exposed domain-level privileges. The discussion then moves toward prevention: threat modeling during user-story development, reusable reference architectures, an...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Alyssa Miller — Experiences with DevOps + Automation and beyond

0:00 44:07

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 44 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on February 13, 2020.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!