EP 42 — Snowflake’s Jacob Salassi on the Science of Product Security

EP 42 — Snowflake’s Jacob Salassi on the Science of Product Security

In this episode of the Future of Application Security, Harshil speaks with Jacob Salassi, Director, Product Security at Snowflake, a cloud computing and data management company. They discuss how Snowflake approaches product security — from what they expect engineers and developers to do, to their risk-based reporting — and why Jacob takes a scientific approach to it. They also discuss how Jacob's team creates property graphs to better understand risk flows and what to prioritize, automated threat detection, how they're writing more intelligent detections at scale, and the challenges of big data to product security.

Topics discussed:

  • How Snowflake approaches product security, including:
    • How they build autonomy for engineers through repeatable processes
    • How they optimize for business value and not just security outcomes, and
    • Why they take a quantitative risk-based reporting approach
  • Why Jacob takes a "science, not art" approach to product security, and why he defines product security as anything related to the security posture of the service.
  • The ways in which data- at- scale and disparate data sources prove to be a challenge for threat detection, and why security teams can benefit from pulling together those sources so they can uniformly analyze data across systems.
  • How Jacob's team created and scaled a repeatable and structured method to risk assess every new feature that's being shipped.
  • How this method of risk assessment and scoring helps uncover dynamics in their environment, gives developers better prioritization of their work, and enables automated threat detection.
  • Challenges to the observability problem of who can own and access data, how many people are ingesting APIs, how much it's costing, and other access concerns.
  • The ways in which they're communicating KPIs and risk posture through live dashboards, and how they're thinking about powering quantitative risk analysis and forecasting through those dashboards.

Avsnitt(60)

EP 60 - Appian’s Abdullah Munawar on Enhancing Product Security Amid Evolving Development Trends

EP 60 - Appian’s Abdullah Munawar on Enhancing Product Security Amid Evolving Development Trends

In this episode of the Future of Application Security podcast, Harshil speaks with Abdullah Munawar, Director of Product Security at Appian. Abdullah shares valuable insights into his journey from sec...

22 Maj 202421min

EP 59 - Nat Mokry on Advancing Application Security in the Gaming Industry

EP 59 - Nat Mokry on Advancing Application Security in the Gaming Industry

In our latest episode of the Future of Application Security podcast, Nat Mokry, VP of Application & Product Security at Xbox (formerly of Activision Blizzard at the time of recording), shares valuable...

24 Apr 202426min

EP 58 — Asana's Felix Matenaar on Building Resilient Security Practices for the Future

EP 58 — Asana's Felix Matenaar on Building Resilient Security Practices for the Future

In this episode of the Future of Application Security podcast, Harshil interviews Felix Matenaar, Head of Product Security at Asana. Felix shares insights into his journey from Germany to Silicon Vall...

10 Apr 202432min

EP 57 —  Clari's Steve Lukose on Using SLAs as Benchmarks for Businesses

EP 57 — Clari's Steve Lukose on Using SLAs as Benchmarks for Businesses

In this episode of the Future of Application Security, Harshil speaks with Steve Lukose, Vice President of Security at Clari, about how security is becoming a business enabler rather than just an orga...

27 Mars 202427min

EP 56 — Aruneesh Salhotra on Why Security is Everyone’s Job

EP 56 — Aruneesh Salhotra on Why Security is Everyone’s Job

In this episode of the Future of Application Security, Harshil speaks with Aruneesh Salhotra, CEO and Fractional CISO, SNM Consulting Inc. They discuss the unique challenges and opportunities of appli...

28 Feb 202424min

EP 55 — BlackBerry's Christine Gadsby on What's Driving Software Supplier Transparency and Accountability

EP 55 — BlackBerry's Christine Gadsby on What's Driving Software Supplier Transparency and Accountability

In this episode of the Future of Application Security, Harshil speaks with Christine Gadsby, VP, Product Security at BlackBerry, a software company specializing in cybersecurity. They discuss the new ...

14 Feb 202426min

EP 54 — LPL Financial's Chad Girouard on Improving Application Security Through Better Tools and Relationships

EP 54 — LPL Financial's Chad Girouard on Improving Application Security Through Better Tools and Relationships

In this episode of the Future of Application Security, Harshil speaks with Chad Girouard, AVP Application Security at LPL Financial, a provider of investment and business solutions. They discuss how s...

31 Jan 202423min

EP 53 — ReversingLabs's Dave Ferguson on Securing Your Software Supply Chains

EP 53 — ReversingLabs's Dave Ferguson on Securing Your Software Supply Chains

In this episode of the Future of Application Security, Harshil speaks with Dave Ferguson, Director of Technical Product Management, Software Supply Chain Security at ReversingLabs, which offers softwa...

17 Jan 202424min

Populärt inom Business & ekonomi

framgangspodden
varvet
rss-jossan-nina
rss-svart-marknad
rss-borsens-finest
badfluence
avanzapodden
uppgang-och-fall
svd-tech-brief
bathina-en-podcast
fill-or-kill
lastbilspodden
rss-dagen-med-di
rss-kort-lang-analyspodden-fran-di
tabberaset
rss-inga-dumma-fragor-om-pengar
24fragor
kapitalet-en-podd-om-ekonomi
rikatillsammans-om-privatekonomi-rikedom-i-livet
borsmorgon