Travis McPeak -- SecOps Makes Developers Lives Easier episode artwork

EPISODE · Dec 18, 2018 · 21 MIN

Travis McPeak -- SecOps Makes Developers Lives Easier

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

What if a security team measured success partly by making developers’ work easier? Travis McPeak explains that approach to SecOps through concrete examples from Netflix’s cloud environment. RepoKid removes unused AWS permissions, Lemur simplifies certificate provisioning, and Security Monkey provides visibility into assets and configuration changes. Chris asks how those capabilities fit with the secure development lifecycle, incident response, and traditional application testing. Travis describes finding repetitive work or problems that cannot scale manually, then deciding whether to use an existing solution or build automation. They also discuss learning paths, books, and OWASP involvement. The conversation makes the operational side of security tangible: give teams dependable controls and useful context while reducing the everyday friction of doing the right thing.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Travis McPeak:→ Travis McPeak on LinkedInMentioned in this episode:→ RepoKid→ Lemur→ Security Monkey (archived project)→ Bandit→ The Tangled WebFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 SecOps that helps developers with Travis McPeak01:17 Travis’s security origin story03:25 A security book worth sharing04:05 Defining SecOps and introducing RepoKid05:16 Removing permissions and managing exceptions06:20 Security signals and incident response08:20 Making certificate provisioning easier with Lemur10:29 Language-specific tools and broader controls11:52 Asset visibility with Security Monkey13:02 Automatically correcting cloud permissions14:32 How an operational problem becomes a tool15:51 Where application security testing fits17:22 Learning SecOps through community and practice

Episode metadata supplied by the publisher feed · Published Dec 18, 2018

Embed this episode

What if a security team measured success partly by making developers’ work easier? Travis McPeak explains that approach to SecOps through concrete examples from Netflix’s cloud environment. RepoKid removes unused AWS permissions, Lemur simplifies certificate provisioning, and Security Monkey provides visibility into assets and configuration changes. Chris asks how those capabilities fit with the secure development lifecycle, incident response, and traditional application testing. Travis descr...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Travis McPeak -- SecOps Makes Developers Lives Easier

0:00 21:55

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 21 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on December 18, 2018.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!