joneno wrote: » Hi Lebroke - Check out this link from OWASP.https://www.owasp.org/index.php/OWASP_AppSec_Pipeline#tab=Pipeline_Tools Don't overthink it, just tell him I said devops is more than just automation...it's a cultural shift for an organization. Lol Seriously, for DevSecOps a security professional simply have to be part of the paradigm to "shift-left". It's the easiest job out there that doesn't require all the certs techexams folks are crazy about. PM me if you need guidance.
TechGuru80 wrote: » Definitely agree that OWASP is likely to come up in the discussion...could also see the different types SaaS / PaaS / IaaS coming up...maybe even the traditional question "is it more expensive to consider security during development, or after its in production?" After its in production is the answer. Culture could definitely come up too...the smaller companies, especially in SF tend to rely heavily on culture of the company.
TechGuru80 wrote: » There is a lot of research on the subject on the cost benefit...or if you read any credible InfoSec publication on implementing security during dev or after you will see it’s less expensive during dev...Carbon Black is NOT what the references are towards...those are aftermarket COTS products where it’s more of building mechanisms into the product. OWASP will help you with the types of security but things like input validation and encryption are a few. Of course in real life, security may or may not get implemented in dev...but if you get asked specifically which is less expensive and you say after it’s in production, you are gonna get some puzzled looks if they know what they are talking about...I think it’s covered in Security+ level.