EPISODE · Jan 9, 2020 · 36 MIN
Geoff Hill — AppSec, DevSecOps, and Diplomacy
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Why can a technically sound DevSecOps initiative fail before it changes how anyone works? Geoff Hill joins Chris and Robert to discuss the diplomacy behind application security transformation. He describes security as an activity throughout delivery, not a product bolted onto a pipeline, and shares lessons from tool integration and organizational resistance. The conversation moves from security champions to the managers who control their time, showing why persuasion, listening, and political capital matter. Geoff explores the fears underneath resistance, including job security and breaking working systems, and the danger of moving faster than an organization can absorb. He closes with practical starting points: understand the existing workflow, establish repeatable development and deployment practices, and introduce security through achievable improvements.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Geoff Hill:→ LinkedInMentioned in this episode:→ Veracode→ Ansible→ SplunkFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Introduction02:00 Defining DevSecOps across the lifecycle04:57 Making security native to delivery07:19 Lessons from failed integrations12:17 Security champions and management support16:34 Diplomacy, persuasion, and political capital18:54 Listening before proposing change20:16 Transformation in nonagile organizations25:44 The fears behind resistance29:46 Removing barriers through practical experiments32:59 First steps toward a working pipeline
Embed this episode
What this episode covers
Why can a technically sound DevSecOps initiative fail before it changes how anyone works? Geoff Hill joins Chris and Robert to discuss the diplomacy behind application security transformation. He describes security as an activity throughout delivery, not a product bolted onto a pipeline, and shares lessons from tool integration and organizational resistance. The conversation moves from security champions to the managers who control their time, showing why persuasion, listening, and political ...
Ready to play
Geoff Hill — AppSec, DevSecOps, and Diplomacy
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.