התחל במצב לא מקוון עם האפליקציה Player FM !
EP 32 — Leading with Context - Where Institutional Knowledge Cannot Scale
Manage episode 364251696 series 3330694
In the ever-evolving landscape of application security, organizations face the challenge of effectively scaling and growing their AppSec programs. On this episode of the Future of Application Security podcast, Harshil Parikh interviews Ty Sbano, the CISO of Vercel, who brings years of experience and expertise in the field of cybersecurity. During their conversation, Ty and Harshil shared their valuable experiences and learnings from scaling AppSec programs in small and large organizations. They also address topics such as gaining visibility into software artifacts, asset ownership and responsibility, and identifying critical tools for the business.
Topics discussed:
- The importance of having a comprehensive understanding of software artifacts to ensure their security
- How collaboration between development teams, security teams, and asset owners can help foster a proactive approach to addressing vulnerabilities and mitigating risks.
- The shift from first-party code to third-party code
- Who owns the code and how are they taking accountability for what is shipped
- How organizations can conduct regular assessments and evaluations to identify which tools are truly important to the business and prioritize their investments accordingly
To learn more about scaling and growing AppSec programs, we highly recommend listening to the full episode.
60 פרקים
Manage episode 364251696 series 3330694
In the ever-evolving landscape of application security, organizations face the challenge of effectively scaling and growing their AppSec programs. On this episode of the Future of Application Security podcast, Harshil Parikh interviews Ty Sbano, the CISO of Vercel, who brings years of experience and expertise in the field of cybersecurity. During their conversation, Ty and Harshil shared their valuable experiences and learnings from scaling AppSec programs in small and large organizations. They also address topics such as gaining visibility into software artifacts, asset ownership and responsibility, and identifying critical tools for the business.
Topics discussed:
- The importance of having a comprehensive understanding of software artifacts to ensure their security
- How collaboration between development teams, security teams, and asset owners can help foster a proactive approach to addressing vulnerabilities and mitigating risks.
- The shift from first-party code to third-party code
- Who owns the code and how are they taking accountability for what is shipped
- How organizations can conduct regular assessments and evaluations to identify which tools are truly important to the business and prioritize their investments accordingly
To learn more about scaling and growing AppSec programs, we highly recommend listening to the full episode.
60 פרקים
כל הפרקים
×
1 EP 60 - Appian’s Abdullah Munawar on Enhancing Product Security Amid Evolving Development Trends 21:05

1 EP 59 - Nat Mokry on Advancing Application Security in the Gaming Industry 26:55

1 EP 58 — Asana's Felix Matenaar on Building Resilient Security Practices for the Future 32:45

1 EP 57 — Clari's Steve Lukose on Using SLAs as Benchmarks for Businesses 27:05

1 EP 56 — Aruneesh Salhotra on Why Security is Everyone’s Job 24:49

1 EP 55 — BlackBerry's Christine Gadsby on What's Driving Software Supplier Transparency and Accountability 26:21

1 EP 54 — LPL Financial's Chad Girouard on Improving Application Security Through Better Tools and Relationships 23:43

1 EP 53 — ReversingLabs's Dave Ferguson on Securing Your Software Supply Chains 24:24

1 EP 52 — Gen’s Curtis Koenig on Speaking the Language of Why Security Matters 27:28

1 EP 51 — Ping Identity’s Arthur Loris on How to Tell Better Stories About Your Product Security Success 27:10

1 EP 50 — DryRun Security’s James Wickett on Aligning Incentives and Speaking the Same Language with Developers and Security 31:08

1 EP 49 — Semgrep’s Colleen Dai on Building Security Strategies and Relationships with Other Teams 20:14

1 EP 48 — Chaotic Good’s Johnathan Kuskos on Testing for Functionality, Priorities, and Better Incident Response 31:10

1 EP 47 — Manicode Security’s Jim Manico on Addressing OWASP Top Ten Issues Through Better Security and Developer Partnerships 26:38

1 EP 46 — TuSimple’s Madjid Nakhjiri on the Evolving Need for Automotive Cybersecurity 24:03
ברוכים הבאים אל Player FM!
Player FM סורק את האינטרנט עבור פודקאסטים באיכות גבוהה בשבילכם כדי שתהנו מהם כרגע. זה יישום הפודקאסט הטוב ביותר והוא עובד על אנדרואיד, iPhone ואינטרנט. הירשמו לסנכרון מנויים במכשירים שונים.