Story of a Cloud Architect & Blurry Lines of Control with AWS

Story of a Cloud Architect & Blurry Lines of Control with AWS

In this episode of the Virtual Coffee with Ashish edition, we spoke with Ashish Desai (Ashish Desai's Linkedin) about how much of the on-premise can work in Cloud, what the online world is saying versus the reality of what businesses are experiencing.

--Announcing Cloud Security Villains Project--

We are always looking to find creative ways to educate folks in Cloud Security and the Cloud Security Villains is part of this education pieces. Cloud Security Villains are coming, you can learn how to defeat them in this YouTube Playlist link

Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv

Host Twitter: Ashish Rajan (@hashishrajan)

Guest Twitter: Ashish Desai (@ashishlogmaster)

Podcast Twitter - @CloudSecPod @CloudSecureNews

If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:

- Cloud Security News

- Cloud Security Academy

Spotify TimeStamp for Interview Questions

(00:00) Intro
(05:50) Ashish Desai's Professional Background
(06:21) Academic Freedom and no firewall
(07:12) What are the roles and responsibilities of an AWS cloud security architect?
(09:27) Difference between managing permissions between onpremise vs Cloud service provider
(13:02) Running Windows 2003 on AWS EC2 Bare Metal
(13:28) Running Old Virtual Servers on AWS
(14:13) Cloud is secure by default
(14:54) CI/CD with Github and Terraform is not common
(15:28) Do people use CI/CD?
(15:37) Traditional on-premise staff is your new cloud engineer
(16:50) Business are not fully advanced
(17:47) Failed Kubernetes Deployment in production example
(18:45) Managed and Bare Metal Kubernetes can only maintain 1 replica
(19:10) What is 1 replica in Kubernetes?
(20:36) Problem with stateful app running on Kubernetes
(21:35) Change Management in Cloud
(21:57) Deployment phases in Cloud
(22:34) Why was ServiceNow required?
(24:39) Why ServiceNow couldn't keep up?
(26:33) Native Solutions bypass Change Management
(28:43) Role of Security Architect in a New Cloud World
(29:53) DevExperience is holding Cloud Adoption success
(32:08) CyberProfessionals to know atleast 1 language to be succesful
(32:27) Do Architect need to know how to code in Enterprise context?
(33:24) Knowing Code to understand the lay of the land
(35:22) Has the Architecture Frameworks changed in the Cloud world?
(37:15) What other skillsets outside of coding is required to be successful in Cloud
(39:54) Should we care about being Cloud agnostic?
(40:41) Architecture for Operational side of Cloud Security?
(43:51) Practical things for advancing Cloud skills?
(48:36) Can anyone come out of uni and become a Cloud Security Architect
(50:32) Resources for education on Cloud security architects
(51:36) Fun Section

Episoder(344)

AI Vulnerability Management: Why You Can't Patch a Neural Network

AI Vulnerability Management: Why You Can't Patch a Neural Network

Traditional vulnerability management is simple: find the flaw, patch it, and verify the fix. But what happens when the "asset" is a neural network that has learned something ethically wrong? In this e...

13 Jan 41min

Why Backups Aren't Enough & Identity Recovery is Key against Ransomware

Why Backups Aren't Enough & Identity Recovery is Key against Ransomware

Think your cloud backups will save you from a ransomware attack? Think again. In this episode, Matt Castriotta (Field CTO at Rubrik) explains why the traditional "I have backups" mindset is dangerous....

16 Des 202537min

How to secure your AI Agents: A CISOs Journey

How to secure your AI Agents: A CISOs Journey

Transitioning a mature organization from an API-first model to an AI-first model is no small feat. In this episode, Yash Kosaraju, CISO of Sendbird, shares the story of how they pivoted from a traditi...

9 Des 202554min

AI-First Vulnerability Management: Should CISOs Build or Buy?

AI-First Vulnerability Management: Should CISOs Build or Buy?

Thinking of building your own AI security tool? In this episode, Santiago Castiñeira, CTO of Maze, breaks down the realities of the "Build vs. Buy" debate for AI-first vulnerability management.While b...

4 Des 20251h 1min

SIEM vs. Data Lake: Why We Ditched Traditional Logging?

SIEM vs. Data Lake: Why We Ditched Traditional Logging?

In this episode, Cliff Crosland, CEO & co-founder of Scanner.dev, shares his candid journey of trying (and initially failing) to build an in-house security data lake to replace an expensive traditiona...

2 Des 202546min

How to Build Trust in an AI SOC for Regulated Environments

How to Build Trust in an AI SOC for Regulated Environments

How do you establish trust in an AI SOC, especially in a regulated environment? Grant Oviatt, Head of SOC at Prophet Security and a former SOC leader at Mandiant and Red Canary, tackles this head-on a...

18 Nov 202542min

Threat Modeling the AI Agent: Architecture, Threats & Monitoring

Threat Modeling the AI Agent: Architecture, Threats & Monitoring

Are we underestimating how the agentic world is impacting cybersecurity? We spoke to Mohan Kumar, who did production security at Box for a deep dive into the threats of true autonomous AI agents.The c...

11 Nov 202547min

AI is already breaking the Silos Between AppSec & CloudSec

AI is already breaking the Silos Between AppSec & CloudSec

The silos between Application Security and Cloud Security are officially breaking down, and AI is the primary catalyst. In this episode, Tejas Dakve, Senior Manager, Application Security, Bloomberg In...

4 Nov 20251h 11min

Populært innen Teknologi

lydartikler-fra-aftenposten
romkapsel
teknisk-sett
tomprat-med-gunnar-tjomlid
rss-impressions-2
shifter
rss-ki-praten
fornybaren
rss-alt-vi-kan
smart-forklart
teknologi-og-mennesker
rss-praktisk-proptech
nasjonal-sikkerhetsmyndighet-nsm
elektropodden
rss-ai-forklart
energi-og-klima
rss-teknologioptimistene-energibransjens-it-podcast
pedagogisk-intelligens
rss-for-alarmen-gar
rss-startup