Geoff Hill — AppSec, DevSecOps, and Diplomacy episode artwork

EPISODE · Jan 9, 2020 · 36 MIN

Geoff Hill — AppSec, DevSecOps, and Diplomacy

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Why can a technically sound DevSecOps initiative fail before it changes how anyone works? Geoff Hill joins Chris and Robert to discuss the diplomacy behind application security transformation. He describes security as an activity throughout delivery, not a product bolted onto a pipeline, and shares lessons from tool integration and organizational resistance. The conversation moves from security champions to the managers who control their time, showing why persuasion, listening, and political capital matter. Geoff explores the fears underneath resistance, including job security and breaking working systems, and the danger of moving faster than an organization can absorb. He closes with practical starting points: understand the existing workflow, establish repeatable development and deployment practices, and introduce security through achievable improvements.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Geoff Hill:→ LinkedInMentioned in this episode:→ Veracode→ Ansible→ SplunkFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Introduction02:00 Defining DevSecOps across the lifecycle04:57 Making security native to delivery07:19 Lessons from failed integrations12:17 Security champions and management support16:34 Diplomacy, persuasion, and political capital18:54 Listening before proposing change20:16 Transformation in nonagile organizations25:44 The fears behind resistance29:46 Removing barriers through practical experiments32:59 First steps toward a working pipeline

Episode metadata supplied by the publisher feed · Published Jan 9, 2020

Embed this episode

Why can a technically sound DevSecOps initiative fail before it changes how anyone works? Geoff Hill joins Chris and Robert to discuss the diplomacy behind application security transformation. He describes security as an activity throughout delivery, not a product bolted onto a pipeline, and shares lessons from tool integration and organizational resistance. The conversation moves from security champions to the managers who control their time, showing why persuasion, listening, and political ...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Geoff Hill — AppSec, DevSecOps, and Diplomacy

0:00 36:53

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 36 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on January 9, 2020.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!