Pergi ke luar talian dengan aplikasi Player FM !
EP 49 — Semgrep’s Colleen Dai on Building Security Strategies and Relationships with Other Teams
Manage episode 381721298 series 3330694
In this special episode of the Future of Application Security, recorded at the Developers & Security are Friends Day, Eric speaks with Colleen Dai, Senior Security Researcher at Semgrep, an open source static analysis tool. They discuss strategies security teams can take to reduce false positives, use secure defaults to eliminate bug classes, and reduce complexity in security decision-making. They also talk about ways to build the relationships between security, developers, and engineers, which includes aligning on goals, communication, and recognition.
Topics discussed:
- Colleen's background and what her security research role at Semgrep entails.
- How to use secure defaults to eliminate bug classes and reduce the complexity in security decisions.
- How to reduce false positives by writing rules and checks, especially ones that are customized to your organization.
- How to better align the goals of security and developers by focusing on creating good software — and good software is secure software.
- How to build relationships with engineers through communication and recognition, not just talking through Jira tickets.
- Why security and developers still struggle with cross-site scripting and how it can be fixed.
60 episod
Manage episode 381721298 series 3330694
In this special episode of the Future of Application Security, recorded at the Developers & Security are Friends Day, Eric speaks with Colleen Dai, Senior Security Researcher at Semgrep, an open source static analysis tool. They discuss strategies security teams can take to reduce false positives, use secure defaults to eliminate bug classes, and reduce complexity in security decision-making. They also talk about ways to build the relationships between security, developers, and engineers, which includes aligning on goals, communication, and recognition.
Topics discussed:
- Colleen's background and what her security research role at Semgrep entails.
- How to use secure defaults to eliminate bug classes and reduce the complexity in security decisions.
- How to reduce false positives by writing rules and checks, especially ones that are customized to your organization.
- How to better align the goals of security and developers by focusing on creating good software — and good software is secure software.
- How to build relationships with engineers through communication and recognition, not just talking through Jira tickets.
- Why security and developers still struggle with cross-site scripting and how it can be fixed.
60 episod
Semua episod
×
1 EP 60 - Appian’s Abdullah Munawar on Enhancing Product Security Amid Evolving Development Trends 21:05

1 EP 59 - Nat Mokry on Advancing Application Security in the Gaming Industry 26:55

1 EP 58 — Asana's Felix Matenaar on Building Resilient Security Practices for the Future 32:45

1 EP 57 — Clari's Steve Lukose on Using SLAs as Benchmarks for Businesses 27:05

1 EP 56 — Aruneesh Salhotra on Why Security is Everyone’s Job 24:49

1 EP 55 — BlackBerry's Christine Gadsby on What's Driving Software Supplier Transparency and Accountability 26:21

1 EP 54 — LPL Financial's Chad Girouard on Improving Application Security Through Better Tools and Relationships 23:43

1 EP 53 — ReversingLabs's Dave Ferguson on Securing Your Software Supply Chains 24:24

1 EP 52 — Gen’s Curtis Koenig on Speaking the Language of Why Security Matters 27:28

1 EP 51 — Ping Identity’s Arthur Loris on How to Tell Better Stories About Your Product Security Success 27:10

1 EP 50 — DryRun Security’s James Wickett on Aligning Incentives and Speaking the Same Language with Developers and Security 31:08

1 EP 49 — Semgrep’s Colleen Dai on Building Security Strategies and Relationships with Other Teams 20:14

1 EP 48 — Chaotic Good’s Johnathan Kuskos on Testing for Functionality, Priorities, and Better Incident Response 31:10

1 EP 47 — Manicode Security’s Jim Manico on Addressing OWASP Top Ten Issues Through Better Security and Developer Partnerships 26:38

1 EP 46 — TuSimple’s Madjid Nakhjiri on the Evolving Need for Automotive Cybersecurity 24:03
Selamat datang ke Player FM
Player FM mengimbas laman-laman web bagi podcast berkualiti tinggi untuk anda nikmati sekarang. Ia merupakan aplikasi podcast terbaik dan berfungsi untuk Android, iPhone, dan web. Daftar untuk melaraskan langganan merentasi peranti.