[September 2018] Embedding Security into DevOps (DevSecOps) by Zane Lackey, Founder & CSO at Signal Sciences

ISSA-NOVA Chapter Meeting

Embedding Security into DevOps (DevSecOps)

Presented by   Zane Lackey

Founder & CSO at Signal Sciences, Advisor for the U.S. OTF & Internet Bug Bounty

Thursday, September 20, 2018  5:30 PM – Networking & Dinner, 6:00 PM – ISSA-NOVA Program

The standard approach for web application security over the last decade and beyond has focused heavily on slow gatekeeping controls like static analysis and dynamic scanning. However, these controls were originally designed in a world of Waterfall development and their heavy weight nature often cause more problems than they solve in today’s world of agile, DevOps, and CI/CD.

This talk will share practical lessons learned at Etsy, which sells handmade or unique items online, on the most effective application security techniques in today’s increasingly rapid world of application creation and delivery. Specifically, it will cover how to:

1) Adapt traditionally heavyweight controls like static analysis and dynamic scanning to lightweight efforts that work in modern development and deployment practices

2) Obtain visibility to enable, rather than hinder, development and DevOps teams’ ability to iterate quickly

3) Measure maturity of your organizations security efforts in a non-theoretical way

Zane Lackey is the Founder/Chief Security Officer at Signal Sciences and serves on multiple Advisory Boards including the National Technology Security Coalition, the Internet Bug Bounty Program, and the US State Department-backed Open Technology Fund. Prior to Signal Sciences, Zane was the Director of Security Engineering at Etsy and a Senior Security Consultant at iSEC Partners.

He has been featured in notable media outlets such as the BBC, Wall Street Journal, Associated Press, Forbes, Wired, and CNET. A frequent speaker at top industry conferences, he has presented at BlackHat, RSA, USENIX, Velocity, Microsoft BlueHat, SANS, OWASP, DevOpsDays, and has given invited lectures at Facebook, Goldman Sachs, IBM, Microsoft, Carnegie Mellon University, and the Federal Trade Commission. See: www.signalsciences.com

Location: Atomicorp, 15049 Conference Center Drive, Suite 180, Chantilly, VA 20151

https://atomicorp.com

Parking: Attendees may park for free in front of the building.

Registration: https://tinyurl.com/issa-nova-2018SEP20

Actual link is https://app.smartsheet.com/b/form/da73cbac80f5487ba999ee49bab2eb42