Building an Engineering Security Culture - Failure stories included - Edwin Kwan, Tyro Payments

Building an Engineering Security Culture - Failure stories included - Edwin Kwan, Tyro Payments

In this episode of the Virtual Coffee with Ashish edition, we spoke with Edwin Kwan, Head of Application and Software Security at Tyro payments.

Edwin & Ashish spoke about

  • What was Edwin’s path into CyberSecurity?
  • What is AppSec for people who don't know?
  • What is the difference between Application Security and Software Security?
  • Is being a developer an advantage going into Application Security?
  • Is AppSec any different between cloud compared so an application deployed on-premise?
  • Enabling an engineering security culture - What does this mean for those who don't know?
  • Engineering Security Culture - How has it evolved to now most of the code developed is using open source libraries
  • Enabling an engineering security culture - Where can one start and what should be avoided?
  • What is DevSecOps for you?
  • Edwin’s book - Failure of DevSecOps

ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv

Twitter - @kaizenteq @hashishrajan

If you want to watch the previous episodes:

- Twitch Channel: https://lnkd.in/gxhFrqw

- Youtube Channel: https://lnkd.in/gUHqSai

Jaksot(345)

Remote Access Trojans target Public Cloud Infrastructure

Remote Access Trojans target Public Cloud Infrastructure

Cloud Security News this week 19 Jan 2022 Cisco Talos Researchers have shared in a blog last week that a trio of remote access Trojans (RATs)—Nanocore, Netwire and AsyncRAT—are being spread in a ca...

19 Tammi 20227min

Secret Management for Modern Apps Explained

Secret Management for Modern Apps Explained

In this episode of the Virtual Coffee with Ashish edition, we spoke with Dylan Ayrey (@insecurenature) is a Professional Hacker and Co-Founder of Truffle Security (@trufflesec) Episode ShowNotes, Link...

16 Tammi 202248min

CISO in a Cloud World in 2022 - Stu Hirst

CISO in a Cloud World in 2022 - Stu Hirst

In this episode of the Virtual Coffee with Ashish edition, we spoke with Stu Hirst (Linkedin-Stu Hirst) is the Chief Information Security Officer (CISO) of Trustpilot (@Trustpilot). Episode ShowNotes,...

12 Tammi 202239min

UK Financial Regulators monitoring Cloud Providers Closely

UK Financial Regulators monitoring Cloud Providers Closely

Cloud Security News this week 12 Jan 2022 UK’s financial regulators - The Prudential Regulation Authority is looking to increase it’s monitoring of Cloud providers like AWS, Azure and Google Cloud. ...

12 Tammi 20224min

Building Modern Identity (IAM) Roadmap for Cloud

Building Modern Identity (IAM) Roadmap for Cloud

In this episode of the Virtual Coffee with Ashish edition, we spoke with Fred Wilmot (@fewdisc) is an ex-Veteran and Chief Information Security Officer (CISO) of JumpCloud (@JumpCloud). Episode ShowNo...

9 Tammi 202248min

Google invests in Security + Microsoft's Log4Shell Update

Google invests in Security + Microsoft's Log4Shell Update

Cloud Security News this week 5 Jan 2022 Google has acquired security orchestration, automation and response (SOAR) provider, Siemplify. Neither company has disclosed any amounts however sources in...

5 Tammi 20225min

Building Scalable Authorization in Cloud Native Apps

Building Scalable Authorization in Cloud Native Apps

In this episode of the Virtual Coffee with Ashish edition, we spoke with Or Weis (@OrWeis) co-founder and CEO of Permit.io (@permit_io). Episode ShowNotes, Links and Transcript on Cloud Security Podca...

2 Tammi 202250min

The Latest with Log4J

The Latest with Log4J

Cloud Security News this week 22 December 2021 Most folks in cybersecurity have been consumed with all things Log4shell with a CVSS score of 10, since last week. Check out last week’s episode or our...

22 Joulu 20213min