Application Security AppSec 101 - Tanya Janca

Application Security AppSec 101 - Tanya Janca

In this episode of the Virtual Coffee with Ashish edition, we spoke with Tanya Janca, Founder, SheHacksPurple & WeHackPurple.

Tanya & Ashish spoke about

  • Who is Tanya Janca? :)
  • What was your path into CyberSecurity or your current role?
  • What has professional life been after leaving Microsoft?
  • What does Cloud Security mean for you?
  • What is Application Security or AppSec?
  • Tanya Janca’s Book - “Alice and Bob learn Application Security”
  • How can someone start in Application Security, specially if they are trying to move laterally?
  • What is Static Code Analysis?
  • What is DevSecOps
  • What is CI/CD Pipeline?
  • Loss of AppSec knowledge when people move on? How do you find the motivation to continue?
  • What is an AppSec Program and how can one make it successful?
  • What does a Mature AppSec Program look like?
  • Are there any tools used for Threat Modelling or is it conducted separately?
  • What’s the most difficult piece of AppSec discipline to explain to others again and again?
  • How do I get buy in from management?
  • How do you do Threat Modelling in CI/CD Pipeline or automate it?
  • What soft skills do you need to be an Application Security person?
  • How do you merge AppSec risk in the infrastructure risk to get a wholistic view?

ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv

Twitter - @kaizenteq @hashishrajan

If you want to watch videos of this and previous episodes:

- Twitch Channel: https://lnkd.in/gxhFrqw

- Youtube Channel: https://lnkd.in/gUHqSai

Jaksot(344)

WHAT IS INFRASTRUCTURE AS CODE SECURITY? - Barak Schoster

WHAT IS INFRASTRUCTURE AS CODE SECURITY? - Barak Schoster

In this episode of the Virtual Coffee with Ashish edition, we spoke with Barak Schoster Goihman (@barakschoster) is the Co-Founder and CTO of Bridgecrew (@Bridgecrewio). Host: Ashish Rajan - Twitter...

14 Maalis 202138min

INCIDENT RESPONSE IN AWS CLOUD

INCIDENT RESPONSE IN AWS CLOUD

In this episode of the Virtual Coffee with Ashish edition, we spoke with Toni de la Fuente (@toniblyx) is the Senior Security Consultant at AWS (@AWSCloud) and author of Prowler - AWS Security Tool. ...

7 Maalis 202145min

How to become a CLOUD SECURITY ENGINEER IN 2021?

How to become a CLOUD SECURITY ENGINEER IN 2021?

In this episode of the Virtual Coffee with Ashish edition, we spoke with Nicholas McLaren (Linkedin - nmclarencys) is the Cloud Security Engineer, ByteChek(@Bytechek). Host: Ashish Rajan - Twitter @...

28 Helmi 202147min

Kubernetes Security at Scale in A CI/CD Pipeline - Michael Fraser

Kubernetes Security at Scale in A CI/CD Pipeline - Michael Fraser

In this episode of the Virtual Coffee with Ashish edition, we spoke with Michael Fraser (@itascode) is the Chief Architect, Co-Founder at refactr (@RefactrIT). Host: Ashish Rajan - Twitter @hashishr...

21 Helmi 202156min

Container Security in AWS at Scale - Ben Tomhave

Container Security in AWS at Scale - Ben Tomhave

In this episode of the Virtual Coffee with Ashish edition, we spoke with Ben Tomhave (Linkedin - @btomhave) is the Principal, Falcon’s View Consulting (@FalconsView). Host: Ashish Rajan - Twitter @h...

14 Helmi 202153min

CISO Challenges in 2021 - Zane Lackey Signal Sciences, Fastly

CISO Challenges in 2021 - Zane Lackey Signal Sciences, Fastly

In this episode of the Virtual Coffee with Ashish edition, we spoke with Zane Lackey, CISO & Co-Founder Signal Sciences, which is now owned by Fastly. Host: Ashish Rajan - Twitter @hashishrajan Gue...

10 Helmi 202151min

Cloud Security in $25 Billion dollar Company - Siemens USA

Cloud Security in $25 Billion dollar Company - Siemens USA

In this episode of the Virtual Coffee with Ashish edition, we spoke with Kurt John, Chief CyberSecurity Officer CISO at Siemens USA Host: Ashish Rajan - Twitter @hashishrajan Guest: Kurt John - Lin...

7 Helmi 202154min

Security Chaos Engineering Experiments for Beginners

Security Chaos Engineering Experiments for Beginners

In this episode of the Virtual Coffee with Ashish edition, we spoke with David Lavezzo, Director of Security Chaos Engineering at Capital One Host: Ashish Rajan - Twitter @hashishrajan Guest: David...

31 Tammi 202135min