Julien Vehent -- Securing DevOps episode artwork

EPISODE · Aug 14, 2018 · 34 MIN

Julien Vehent -- Securing DevOps

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Can security become a normal part of DevOps without turning every release into an audit? Julien Vehent, author of Securing DevOps, shares what his team learned protecting Firefox services at Mozilla. He explains why security engineers belong inside product teams, how short checklists translate large security requirements into work developers can actually complete, and where creativity still matters. Julien challenges the idea that everything must be automated, showing how automation frees specialists to investigate the problems that require judgment. The conversation follows real examples involving Content Security Policy, bug bounties, website security grades, and testing in delivery pipelines. He closes by describing continuous security as a feedback loop that turns operational lessons into better requirements, controls, and engineering practices.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Julien Vehent:→ Julien Vehent’s websiteMentioned in this episode:→ Securing DevOps by Julien Vehent→ Mozilla HTTP Observatory→ ZAP→ SSL Labs Server TestFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Securing DevOps with Julien Vehent01:54 Julien’s security origin story04:51 Defining DevOps as engineering practices06:33 The practical story behind Securing DevOps07:32 Making security a natural part of building software10:28 Putting security inside the product team13:11 Turning security requirements into checklists16:11 Leaving developers room for creativity17:15 Where manual security work still belongs21:23 Mozilla’s experience with CSP and bug bounties25:12 Observatory, SSL Labs, and pipeline testing26:35 Continuous security as a feedback loop30:31 Learning security by building real systems32:39 Room to improve DevOps security

Episode metadata supplied by the publisher feed · Published Aug 14, 2018

Embed this episode

Can security become a normal part of DevOps without turning every release into an audit? Julien Vehent, author of Securing DevOps, shares what his team learned protecting Firefox services at Mozilla. He explains why security engineers belong inside product teams, how short checklists translate large security requirements into work developers can actually complete, and where creativity still matters. Julien challenges the idea that everything must be automated, showing how automation frees spe...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Julien Vehent -- Securing DevOps

0:00 34:15

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 34 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on August 14, 2018.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!