Threat Modeling - A Disaster Story with Edwin Kwan

Threat Modeling - A Disaster Story with Edwin Kwan

We continue the "Epic Failures in DevSecOps" series by speaking with Edwin Kwan on his chapter, "Threat Modeling - A Disaster Story". Edwin is Application and Software Security Team Lead at Tyro Payments. In our discussion, we talk about the three things he learned through his "Epic Failure": -- Demonstrate value at the buy-in -- Get early feedback -- Automate as much as possible During our discussion, we talk at length about the role of security and how to begin implementing automation at the earliest stages of the development process. About Edwin Kwan Edwin Kwan is the Application and Software Security Team Lead for a bank. His approach toward application and software security is to raise security awareness, provide light touch controls to the software development life cycle to increase visibility of security issues and work closely with engineering teams to quickly develop secure applications. Edwin started out as a software engineer and transitioned into the application security role to lead a range of security initiatives when the company was working towards obtaining an unrestricted banking licence. As a Software Engineer, he has over a decade of experience developing large scale; real-time; high performance; high reliability software applications for major telecommunication vendors. He is also experienced in working with stakeholders from small to large organisations to design and develop innovation solutions to help manage and grow their business.

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(191)

ep2024-12 Tanya Janca: Happy Holidays are Secure Code

ep2024-12 Tanya Janca: Happy Holidays are Secure Code

Some production issues caused this one to slip to December so the intro is a bit off but this is still a great episode. So, learn some lessons on creating secure code from one of my favorite guests: T...

23 Des 20241h

ep2024-10 Don't be Scared, It's just a Pen Test with Brad Causey

ep2024-10 Don't be Scared, It's just a Pen Test with Brad Causey

There's no reason to be scared about a pen test - especially when it's run by a professional like Brad Causey. I catch up with Brad in this episode to discuss what's recently changed in pen testing in...

31 Okt 202437min

ep2024-09 Threat Modeling with Takaharu

ep2024-09 Threat Modeling with Takaharu

What happens when you get interested in Threat Modeling and you want to share. For some, that means you do one work shop, then another, then another. What happens when you start down this path. Takaha...

25 Sep 202436min

ep2024-08 OWASP Projects Roundup

ep2024-08 OWASP Projects Roundup

The August episode is a review of projects from a recent OWASP project showcase. We talk to the leaders of the OWASP pytm, OWASP Developer Guide, OWASP State of AppSec Survey Project. Get up on the la...

30 Aug 202436min

ep2024-07 Safety belts for AppSec with Lisa Plaggemier

ep2024-07 Safety belts for AppSec with Lisa Plaggemier

After a long and unplanned pause, the OWASP podast is back with a home run of an episode. We have Lisa Plaggemier as our guest who reprises her eloquent keynote topic from AppSec DC. All hope isn't lo...

12 Jul 202432min

ep2023-09  Vulnerable Data Gathering for AI with Arturo Buanzo Busleiman

ep2023-09 Vulnerable Data Gathering for AI with Arturo Buanzo Busleiman

After getting a ping from an old friend about a potential new OWASP project, I had to bring him on as a guest. He's got an interesting idea around potential vulnerabilities in web crawlers which just ...

2 Okt 202332min

ep2023-08 Finding Next Gen Cybersecurity Professionals with Brad Causey

ep2023-08 Finding Next Gen Cybersecurity Professionals with Brad Causey

For years we've heard talk about a shortage of cybersecurity professionals so what can be done about that? In this episode, I speak to Brad Causey who has taken one approach he's found successful. We ...

31 Aug 202332min

ep2023-07 What's Audit got to do with IT

ep2023-07 What's Audit got to do with IT

In this episode we talk with Zain Haq and take a leap and bound over the first and second line to discover more about the third line - internal audit. We discover answers to a number of questions: Wha...

31 Jul 202333min

Populært innen Teknologi

lydartikler-fra-aftenposten
teknisk-sett
tomprat-med-gunnar-tjomlid
rss-ki-praten
shifter
elektropodden
rss-ai-forklart
rss-alt-som-gar-pa-strom
pedagogisk-intelligens
nasjonal-sikkerhetsmyndighet-nsm
smart-forklart
rss-polypod
rss-fish-ships
fornybaren
rss-bouvet-bobler
rss-kunstig-intelligens-med-elisabeth-maren-og-morten
hans-petter-og-co
rss-fisketimen
teknologi-og-mennesker
rss-digitaliseringspadden