DJ Schleen — DevOps: The Sec is Silent episode artwork

EPISODE · Jan 30, 2020 · 37 MIN

DJ Schleen — DevOps: The Sec is Silent

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

What changes when security becomes part of delivering software instead of a separate gate? DJ Schleen joins Chris and Robert to explain why he prefers DevOps with a silent Sec, drawing on his journey from early programming and hacking to building delivery pipelines. They discuss the difference between genuine transformation and automating an existing process, why governance and compliance belong in the conversation, and how teams can grow their capabilities without adopting every tool at once. DJ walks through his DevSecOps reference architecture as an assembly line from idea to customer value. The conversation closes with learning Kubernetes through K3s, the tradeoffs of managed platforms, and the security thinking that matters more than a particular product.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with DJ Schleen:→ LinkedIn→ GitHubMentioned in this episode:→ DevSecOps reference architecture→ K3s→ DevOpsDays→ The Unicorn ProjectFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Introduction02:12 DJ's programming and hacking roots06:33 What DevOps is trying to accomplish09:44 Adoption beyond automating the old process12:20 Will DevOps become ordinary software delivery?15:15 Bringing compliance and governance along18:17 Observers, stakeholders, and participants19:48 Growing the team with the work20:34 Why the Sec is silent24:43 The DevSecOps reference architecture28:54 Starting small and adding capabilities31:23 Learning Kubernetes with K3s33:49 Managed platforms and security tradeoffs35:53 Closing thoughts

Episode metadata supplied by the publisher feed · Published Jan 30, 2020

Embed this episode

What changes when security becomes part of delivering software instead of a separate gate? DJ Schleen joins Chris and Robert to explain why he prefers DevOps with a silent Sec, drawing on his journey from early programming and hacking to building delivery pipelines. They discuss the difference between genuine transformation and automating an existing process, why governance and compliance belong in the conversation, and how teams can grow their capabilities without adopting every tool at once...

Distinct summary based on available episode metadata or transcript content.

Ready to play

DJ Schleen — DevOps: The Sec is Silent

0:00 37:35

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 37 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on January 30, 2020.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!