Security Compass, a leading provider of cybersecurity solutions and advisory services, enables organizations to adopt balanced development automation for rapid and secure application development. With their flagship product, SD Elements, the company helps automate significant portions of proactive manual processes for security and compliance that improves time to market for new technology. In addition, they offer advisory services on how organizations can embrace emerging technologies like cloud to strengthen their security posture. Security Compass is the trusted solution provider to leading financial organizations, technology enablers, and renowned global brands.
Episodes
Monday Nov 16, 2020
Arun Prabhakar - The Difference Between Product and Software Security
Monday Nov 16, 2020
Monday Nov 16, 2020
Today we are joined by Altaz Valani from Security Compass and Arun Prabhakar, Security Consultant at Security Compass, to talk about product security. We start by talking about both product and software security, where there are similarities and differences. We then turn the conversation to look at quality and the categories of metrics that help make secure products. At the end of our discussion, we discuss where hardware security is headed in the future. This area of product security is an important topic in light of the growing convergence between hardware and software layers.
Friday Nov 13, 2020
DJ Schleen - Using Technology to Enhance DevSecOps
Friday Nov 13, 2020
Friday Nov 13, 2020
Today we are joined by Pranoy De and Michael Bolger from Security Compass and DJ Schleen, Senior Manager of Software Security at Rally Health, to talk about how we can leverage technology to enhance DevSecOps practices. In this podcast, we delve into the details of technology and automation tools that are essential for setting up a robust DevSecOps program, with specific emphasis on the Healthcare industry.
Monday Nov 09, 2020
Enabling Both Speed and Security
Monday Nov 09, 2020
Monday Nov 09, 2020
Today we are joined by Pranoy De, Eleonor Lee, and Altaz Valani from Security Compass, to talk about three DevSecOps challenges from a technical leader’s perspective: integrating security into DevOps pipelines; building a knowledge retention and training model that balances speed and security; and the convergence of business and IT. In all cases, security has a key role to play in enabling the business to manage risk, in a way that doesn’t slow down the business.
Monday Nov 02, 2020
Spencer Koch - An Executive Perspective on Agile Security
Monday Nov 02, 2020
Monday Nov 02, 2020
Today we are joined by Altaz Valani from Security Compass and Spencer Koch, Offensive Security Professional at Reddit, to talk about Agile Security in technology companies from an Executive’s perspective. We would start with the question — Why does the business think security gets in the way of being agile — and discuss how a security executive can start to change this perception. As with any change, there needs to be an ongoing effort from security teams to provide assurance and business value for agility. Agile is at the forefront of technology companies today, and security can be an enabler by reducing risk without getting in the way.
Friday Oct 30, 2020
Friday Oct 30, 2020
Today we are joined by Altaz Valani from Security Compass and Purnima Bihari, Product Owner at Security Compass, to talk about how managing a fast moving product delivery lifecycle while ensuring security is a challenging task. Purnima will share insights from her experience about the role a product owner plays in injecting security early into the product lifecycle and the impact being a security champion can make on ensuring product security. We will also discuss the skills required to adopt a balanced approach to speed and security.
Monday Oct 26, 2020
Monday Oct 26, 2020
Today we are joined by Rohit Sethi from Security Compass and Nicolas Chaillan, Chief Software Officer, U.S. Air Force, to gain insights into building a DevSecOps program for a large government organization. In this podcast, we will talk about the challenges, key considerations, and the need to balance security with fast delivery cycles in the defense world. We will also cover the program structures being established across the Department of Defense and understand more about the ATO process.
Friday Oct 23, 2020
Bob Aiello - Operationalizing Security in DevOps
Friday Oct 23, 2020
Friday Oct 23, 2020
Today we are joined by Altaz Valani from Security Compass and Bob Aiello, DevOps architect and trainer with decades of experience leading enterprise software process improvement initiatives. We will start by asking the question, “Why do so many organizations struggle with integrating security into DevOps?” Since automation is a key part of DevOps, we will discuss security practices that are easily automatable in DevOps, and conclude with a discussion on where DevOps is headed.
Monday Oct 19, 2020
Spencer Koch - Maintain Your Security Through Application Modernization
Monday Oct 19, 2020
Monday Oct 19, 2020
Today we are joined by Altaz Valani from Security Compass and Spencer Koch, Security Wizard at Reddit, to discuss the role of security in Application Modernization. In today’s digital world, businesses have to modernize their applications routinely. In this podcast, we will discuss current trends and security challenges around application modernization; and how security can help minimize the risk. This is important as many organizations are currently transforming their applications against a backdrop of going digital.
Friday Oct 16, 2020
Jeff Sorrell - An Industry Perspective on CMMC
Friday Oct 16, 2020
Friday Oct 16, 2020
Today we are joined by Altaz Valani from Security Compass and Jeff Sorrell, a Data Privacy and Information Security Consultant. We will discuss, at a high level, the importance of Cybersecurity Maturity Model Certification (CMMC) and its operational impact on companies that have contracts with the U.S. Department of Defense. We dive into some of the nuances of CMMC as it advocates moving away from self-attestation to third-party audit and certification. To conclude this discussion, Jeff will share thoughts on any trends based on his own experience.
Friday Oct 09, 2020
Friday Oct 09, 2020
Today we are joined by Ehsan Foroughi from Security Compass, and Andrew Wertkin, Chief Strategy Officer at BlueCat. In this podcast, we will discuss the intersection of network infrastructure and security, and how to bake security requirements from that perspective. Drawing from his experience in enterprise architecture and distributed computing networks, Andrew will also share valuable security and network health insights.