EPISODE · Sep 18, 2018 · 26 MIN
Mohammed Imran -- Back to the Lab Again with a DevOps
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Learning DevSecOps is hard when setting up the lab becomes a project of its own. Mohammed Imran introduces DevSecOps Studio, an environment designed to help people practice an automated delivery workflow and add security to it. He shares his transition from offensive security toward building defenses, explains why security practitioners need to understand developers’ tools, and describes the roles of Git, GitLab, containers, and automation. Chris asks how static and dynamic testing fit into the pipeline and how the lab connects with DevSlop. Their discussion keeps returning to hands-on experience: give learners working pieces they can inspect, change, and reconnect. The episode offers a route from knowing security concepts to understanding how those concepts operate inside a real development process.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Mohammed Imran:→ Mohammed Imran on LinkedIn→ DevSecOps StudioMentioned in this episode:→ OWASP DevSlop→ GitLab→ Docker→ BanditFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Learning DevSecOps with Mohammed Imran01:23 An offensive-security origin story03:07 Moving from breaking systems to defending them04:50 What a DevSecOps course needs to teach06:30 Learning from established DevOps practices10:15 Dynamic testing and vulnerability scanning12:07 Bridging operations, coding, and security skills14:40 Learning Git and CI/CD fundamentals14:58 Why GitLab is a useful starting point19:02 What the DevSecOps Studio lab provides20:20 Teaching with a working environment23:12 Cloud reference architectures and DevSlop24:41 How to get started and find the documentation
Embed this episode
What this episode covers
Learning DevSecOps is hard when setting up the lab becomes a project of its own. Mohammed Imran introduces DevSecOps Studio, an environment designed to help people practice an automated delivery workflow and add security to it. He shares his transition from offensive security toward building defenses, explains why security practitioners need to understand developers’ tools, and describes the roles of Git, GitLab, containers, and automation. Chris asks how static and dynamic testing fit into t...
Ready to play
Mohammed Imran -- Back to the Lab Again with a DevOps
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.