Reto Kaeser
You can’t hack what you can’t see
#1about 3 minutes
The cultural shift from DevOps to DevSecOps
DevOps succeeded by fostering a culture of shared responsibility, and now security must be integrated to break down the final silo.
#2about 8 minutes
Integrating security into requirements and design phases
Proactively address security by defining abuse cases during requirements and classifying or anonymizing data during the design phase.
#3about 5 minutes
Hardening the CI/CD pipeline with automated security tools
Shift security left by integrating automated vulnerability management for dependencies and continuous penetration testing into the CI/CD process.
#4about 3 minutes
Why traditional firewalls fail against internal east-west traffic
Most network traffic occurs internally between services (east-west), bypassing perimeter firewalls and exposing a soft interior to application-level attacks.
#5about 3 minutes
Moving from perimeter defense to workload microsegmentation
Protect against internal threats by decoupling security from the network and applying logical firewalls directly to each workload through microsegmentation.
#6about 4 minutes
Applying Zero Trust principles with security as code
Implement a Zero Trust model by having developers define workload communication intentions as code, which automatically generates and enforces security policies.
#7about 2 minutes
The benefits of a modern workload-centric security architecture
Adopting a Zero Trust, workload-centric model provides benefits like increased agility, complete application-level visibility, automated compliance, and real-time forensics.
#8about 1 minute
A developer's responsibility to build secure software
Developers must take ownership of security by adopting a paranoid mindset to build more resilient software in an increasingly dangerous cloud environment.
Related jobs
Jobs that call for the skills explored in this talk.
Architekt für Cloud Security - AWS (w|m|d)
zeb consulting
Frankfurt am Main, Germany
Remote
Junior
Intermediate
Senior
Matching moments
01:58 MIN
Cybersecurity is a foundational necessity not a passing trend
Decoding Trends: Strategies for Success in the Evolving Digital Domain
00:45 MIN
The expanding role of developers in security
Vulnerable VS Code extensions are now at your front door
24:17 MIN
Shifting security left with collaborative threat modeling
We adopted DevOps and are Cloud-native, Now What?
00:46 MIN
The expanding security responsibilities of developers
Vue3 practical development
27:19 MIN
Key takeaways on IDE and developer tool security
You click, you lose: a practical look at VSCode's security
02:54 MIN
Moving beyond the "it just works" developer mindset
Don't Be A Naive Developer: How To Avoid Basic Cybersecurity Mistakes
03:58 MIN
Why security must be integrated from the start
DevSecOps: Security in DevOps
14:01 MIN
Security is now a shared responsibility across all teams
The Evolving Landscape of Application Development: Insights from Three Years of Research
Featured Partners
Related Videos
Simple Steps to Kill DevSec without Giving Up on Security
Isaac Evans
DevSecOps: Security in DevOps
Aarno Aukia
Typed Security: Preventing Vulnerabilities By Design
Michael Koppmann
Why Security-First Development Helps You Ship Better Software Faster
Michael Wildpaner
Walking into the era of Supply Chain Risks
Vandana Verma
Climate vs. Weather: How Do We Sustainably Make Software More Secure?
Panel Discussion
What The Hack is Web App Sec?
Jackie
Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?
Tino Sokic
Related Articles
View all articles



From learning to earning
Jobs that call for the skills explored in this talk.

Security Solution Designer - (Network Security/Segmentation/Access Control)
DevNull Security
Sheffield, United Kingdom
Remote
£70-80K
UML
JIRA
Confluence
+1

Senior Enterprise Security Architect (Zero Trust) -
Akamai
Remote
Senior
Azure
Kubernetes
Microservices
Network Security
+2


Zero Trust Cybersecurity Engineer
Interface Recruitment
Birmingham, United Kingdom
Azure
DevOps
Python
Powershell
Google Cloud Platform
+2

Security Solution Designer - (Application/SDLC/Segmentation)
DevNull Security
Sheffield, United Kingdom
Remote
£70-80K
UML
JIRA
Confluence


DevSecOps Engineer Landing Zone Azure
Talanx AG
Hannover, Germany
API
Azure
DevOps
Terraform
Microsoft Access

ICT Security Engineer Zero Trust Swiss Government Cloud
Bundesverwaltung
Zollikofen, Switzerland
DevOps
Agile Methodologies

Application Security Consultants - Security by Design
Accenture
Municipality of Madrid, Spain
Scrum
DevOps
Agile Methodologies