התחל במצב לא מקוון עם האפליקציה Player FM !
פודקאסטים ששווה להאזין
בחסות
GitLab’s CISO Josh Lemos on the pros and cons of making security practices public
Manage episode 479754779 series 3610934
In this week’s episode of The Future of Security Operations podcast, Thomas is joined by Josh Lemos, CISO at GitLab.
Throughout his 15-year career in security, Josh has led teams at ServiceNow, Cylance, and Square. Known for his expertise in AI-driven security strategies, Josh is also a board member with HiddenLayer. He drives innovation at GitLab with a relentless focus on offensive security, identity management, and automation.
In this episode:
[02:05] His early career path from mechanic to electrical engineer to security leader
[03:35] Josh’s philosophy on hiring and mentoring, plus his tips for creating networking opportunities
[05:30] How he applies technical foundations from his practitioner days to his work as CISO
[07:40] Building product security at ServiceNow from the ground up
[10:40] “Down and in” versus “up and out” - adopting a new leadership style as CISO at Square
[12:17] Josh’s experience as an early AI and security researcher at Cylance
[16:15] What’s surprised Josh most about the evolution of AI
[18:50] Why Josh calls today’s models “AI version 1.0” - and what he thinks it will take to upgrade to version 2.0
[22:45] The LLM security threats Josh is most worried about, as a board member with Hidden Layer
[26:30] “Expressing exponential value” - what excited Josh most about becoming CISO at GitLab
[27:45] Why GitLab prioritizes “intentional transparency”
[32:45] How GitLab automates and orchestrates its Tier 1 and Tier 2 security processes
[34:10] How GitLab’s security team uses GitLab internally
[37:35] The secret to recruiting, hiring, and managing a remote, global team
[39:45] The importance of in-person collaboration for building trust and connection
[41:45] Downsizing, bootstrapping, and problem-solving: Josh’s predictions for the future of SecOps
[46:10] Connect with Josh
Where to find Josh:
Where to find Thomas Kinsella:
Resources mentioned:
44 פרקים
Manage episode 479754779 series 3610934
In this week’s episode of The Future of Security Operations podcast, Thomas is joined by Josh Lemos, CISO at GitLab.
Throughout his 15-year career in security, Josh has led teams at ServiceNow, Cylance, and Square. Known for his expertise in AI-driven security strategies, Josh is also a board member with HiddenLayer. He drives innovation at GitLab with a relentless focus on offensive security, identity management, and automation.
In this episode:
[02:05] His early career path from mechanic to electrical engineer to security leader
[03:35] Josh’s philosophy on hiring and mentoring, plus his tips for creating networking opportunities
[05:30] How he applies technical foundations from his practitioner days to his work as CISO
[07:40] Building product security at ServiceNow from the ground up
[10:40] “Down and in” versus “up and out” - adopting a new leadership style as CISO at Square
[12:17] Josh’s experience as an early AI and security researcher at Cylance
[16:15] What’s surprised Josh most about the evolution of AI
[18:50] Why Josh calls today’s models “AI version 1.0” - and what he thinks it will take to upgrade to version 2.0
[22:45] The LLM security threats Josh is most worried about, as a board member with Hidden Layer
[26:30] “Expressing exponential value” - what excited Josh most about becoming CISO at GitLab
[27:45] Why GitLab prioritizes “intentional transparency”
[32:45] How GitLab automates and orchestrates its Tier 1 and Tier 2 security processes
[34:10] How GitLab’s security team uses GitLab internally
[37:35] The secret to recruiting, hiring, and managing a remote, global team
[39:45] The importance of in-person collaboration for building trust and connection
[41:45] Downsizing, bootstrapping, and problem-solving: Josh’s predictions for the future of SecOps
[46:10] Connect with Josh
Where to find Josh:
Where to find Thomas Kinsella:
Resources mentioned:
44 פרקים
כל הפרקים
×
1 Huntabil.IT’s Raymond Schippers on scaling IR during Canva’s hypergrowth 48:01

1 Circle’s Dane VandenBerg on the future of security copilots and the evolution of threat intel 42:47

1 GitLab’s CISO Josh Lemos on the pros and cons of making security practices public 47:50

1 Brex's CISO Mark Hillick on avoiding tool bloat and learning from high-severity incidents 42:05

1 Ofgem’s Mollie Chard on driving resilience through diverse hiring practices 43:58

1 The Trade Desk's Joe McCallister on salary negotiation and leading without micromanaging 46:08

1 LastPass's Christofer Hoff on navigating incidents while rebuilding the security org from scratch 55:59

1 Afni's Brent Deterding on deploying MFA for 10,000 employees and becoming "the Happy CISO" 44:14

1 Ask Sage's Nicolas Chaillan on moving the DOD to zero trust and deploying Kubernetes in space 48:06

1 The NFL's George Griesler on securing the Super Bowl and reducing risk through collaboration 44:34

1 Barracuda's Adam Khan on AI-driven XDR and plugging the cybersecurity skills gap 36:57

1 Reddit’s Matt Johansen on renouncing superhero culture and what comes next after “shift left” 56:59

1 Twilio's Prima Virani on democratizing security and tackling burnout through automation 45:29

1 Fastly’s Andrew Santell on going from the Navy to Netflix and breaking free of bad processes 48:45

1 Elastic’s Mandy Andress on switching from a tech-first to people-first approach to security 46:05

1 Dmitriy Sokolovskiy: How SecOps teams can measure and communicate their ROI to senior leadership 43:30

1 Robinhood’s David Seidman: The tradeoff between technical mastery and strong management 43:29

1 Incode Technologies’ Jeff Moss: Scaling security for startups and defending against the ever-growing attack surface 35:29

1 Quickbase’s Rebecca Harness: Securely engaging with technology partners and third-party vendors and overcoming the inevitability of human error 38:51

1 Sublime Security’s Josh Kamdjou: The state of today’s email threat landscape and how to defend without reinventing the wheel 40:37

1 Wiz’s Yinon Costica: Using a self-serve model to better equip organizations and improve security posture 42:32

1 BeyondTrust’s Morey Haber: The challenges for security operations teams due to identity-based risks in a remote working world 41:44

1 Oracle’s Arthur Barnes: The evolution of cybersecurity & solving the challenge of hiring the right team 42:49

1 Material Security’s Ryan Noon: Building & marketing a differentiated cybersecurity solution without spreading FUD 35:43

1 Cybrize’s Diana Kelley: Why compliance is more than a checkbox exercise, and how to integrate it into your security toolkit 42:40

1 Lacework’s Andreas Schneider: How to adapt as a CISO and the value of security failures 40:31

1 GitHub’s Jacob DePriest: How to attract and retain more diverse security talent 37:12

1 Expel’s Jon Hencinski: How to Reduce Risk Through Better Security Strategy 41:59

1 Madhav Gopal: Security Operations at Fortune 30 Scale 30:15

1 Pipedrive’s Kristian Kivimägi: How to Scale Security Teams While Taking Care of Your People 31:58
ברוכים הבאים אל Player FM!
Player FM סורק את האינטרנט עבור פודקאסטים באיכות גבוהה בשבילכם כדי שתהנו מהם כרגע. זה יישום הפודקאסט הטוב ביותר והוא עובד על אנדרואיד, iPhone ואינטרנט. הירשמו לסנכרון מנויים במכשירים שונים.