Kayra Otaner -- DevSecOps episode artwork

EPISODE · Oct 29, 2024 · 32 MIN

Kayra Otaner -- DevSecOps

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Kayra Otaner joins the podcast today to discuss DevSecOps and answer the question, is it dead? Kayra is the Director of DevSecOps at Roche and is highly involved in the DevSecOps community. Kayra states that DevSecOps in its traditional form is “dead” and that each organization should approach its needs based on their size. Otaner introduces the concept of "security as code" and "policy as code" as more effective approaches, where security functions are codified rather than relying on traditional documentation and checklists. Finally, they discuss the emergence of Application Security Posture Management (ASPM) tools as the "SIM for AppSec," suggesting these tools, especially when enhanced with AI, could help manage the overwhelming number of security alerts and issues that currently plague development teams.The Application Security Podcast is brought to you by Security Journey.About Security JourneyWe provide diverse training content and easy-to-digest lessons to meet individual learner needs.→ Learn more about Security JourneyConnect with Kayra Otaner:→ Books by Yuval Noah Harari→ RocheMentioned in this episode:→ Books by Yuval Noah Harari→ Roche→ CISA Zero Trust Maturity Model→ The Phoenix Project→ OWASP DefectDojo→ OWASP Dependency-Track→ Phoenix SecurityFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Kayra Otaner: DevSecOps01:47 I like to be controversial about our discipline. And there was03:59 All right. Well, Kayra, I think we're going to dive right09:28 Right12:29 No, I agree with you there. I mean, there's definitely not16:17 Can you gimme an example of a problem in which security19:58 Makes sense. So what about zero trust23:12 Yeah, so lightning round are 3 questions that we typically ask25:34 Kero, what would be a key takeaway or a call to27:09 Yeah. And Defect Dojo is a commercial entity now. So I30:32 I'm going to disagree with you to some regard. I'm an

Episode metadata supplied by the publisher feed · Published Oct 29, 2024

Embed this episode

Kayra Otaner joins the podcast today to discuss DevSecOps and answer the question, is it dead? Kayra is the Director of DevSecOps at Roche and is highly involved in the DevSecOps community. Kayra states that DevSecOps in its traditional form is “dead” and that each organization should approach its needs based on their size. Otaner introduces the concept of "security as code" and "policy as code" as more effective approaches, where security functions are codified rather than relying on traditi...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Kayra Otaner -- DevSecOps

0:00 32:46

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 32 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on October 29, 2024.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!