EPISODE · Aug 14, 2018 · 34 MIN
Julien Vehent -- Securing DevOps
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Can security become a normal part of DevOps without turning every release into an audit? Julien Vehent, author of Securing DevOps, shares what his team learned protecting Firefox services at Mozilla. He explains why security engineers belong inside product teams, how short checklists translate large security requirements into work developers can actually complete, and where creativity still matters. Julien challenges the idea that everything must be automated, showing how automation frees specialists to investigate the problems that require judgment. The conversation follows real examples involving Content Security Policy, bug bounties, website security grades, and testing in delivery pipelines. He closes by describing continuous security as a feedback loop that turns operational lessons into better requirements, controls, and engineering practices.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Julien Vehent:→ Julien Vehent’s websiteMentioned in this episode:→ Securing DevOps by Julien Vehent→ Mozilla HTTP Observatory→ ZAP→ SSL Labs Server TestFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Securing DevOps with Julien Vehent01:54 Julien’s security origin story04:51 Defining DevOps as engineering practices06:33 The practical story behind Securing DevOps07:32 Making security a natural part of building software10:28 Putting security inside the product team13:11 Turning security requirements into checklists16:11 Leaving developers room for creativity17:15 Where manual security work still belongs21:23 Mozilla’s experience with CSP and bug bounties25:12 Observatory, SSL Labs, and pipeline testing26:35 Continuous security as a feedback loop30:31 Learning security by building real systems32:39 Room to improve DevOps security
Embed this episode
What this episode covers
Can security become a normal part of DevOps without turning every release into an audit? Julien Vehent, author of Securing DevOps, shares what his team learned protecting Firefox services at Mozilla. He explains why security engineers belong inside product teams, how short checklists translate large security requirements into work developers can actually complete, and where creativity still matters. Julien challenges the idea that everything must be automated, showing how automation frees spe...
Ready to play
Julien Vehent -- Securing DevOps
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.