EPISODE · Dec 18, 2018 · 21 MIN
Travis McPeak -- SecOps Makes Developers Lives Easier
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
What if a security team measured success partly by making developers’ work easier? Travis McPeak explains that approach to SecOps through concrete examples from Netflix’s cloud environment. RepoKid removes unused AWS permissions, Lemur simplifies certificate provisioning, and Security Monkey provides visibility into assets and configuration changes. Chris asks how those capabilities fit with the secure development lifecycle, incident response, and traditional application testing. Travis describes finding repetitive work or problems that cannot scale manually, then deciding whether to use an existing solution or build automation. They also discuss learning paths, books, and OWASP involvement. The conversation makes the operational side of security tangible: give teams dependable controls and useful context while reducing the everyday friction of doing the right thing.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Travis McPeak:→ Travis McPeak on LinkedInMentioned in this episode:→ RepoKid→ Lemur→ Security Monkey (archived project)→ Bandit→ The Tangled WebFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 SecOps that helps developers with Travis McPeak01:17 Travis’s security origin story03:25 A security book worth sharing04:05 Defining SecOps and introducing RepoKid05:16 Removing permissions and managing exceptions06:20 Security signals and incident response08:20 Making certificate provisioning easier with Lemur10:29 Language-specific tools and broader controls11:52 Asset visibility with Security Monkey13:02 Automatically correcting cloud permissions14:32 How an operational problem becomes a tool15:51 Where application security testing fits17:22 Learning SecOps through community and practice
Embed this episode
What this episode covers
What if a security team measured success partly by making developers’ work easier? Travis McPeak explains that approach to SecOps through concrete examples from Netflix’s cloud environment. RepoKid removes unused AWS permissions, Lemur simplifies certificate provisioning, and Security Monkey provides visibility into assets and configuration changes. Chris asks how those capabilities fit with the secure development lifecycle, incident response, and traditional application testing. Travis descr...
Ready to play
Travis McPeak -- SecOps Makes Developers Lives Easier
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.