Presentation: 7 Strategies for Scaling Product Security
This presentation is now available to view on InfoQ.com
Watch videoAbstract
Product Security and Application Security Engineering teams are tasked with fixing and preventing security vulnerabilities, developing security controls, building meaningful security automation, maintaining security review processes, building security capabilities into existing products and leveraging the collective skills of the research community, whilst being the guardians of customer data.
Beyond Penetration Testing – In this presentation, we will cover seven different high-ROI strategies for resource-constrained Product Security teams that need to scale to support thousands of developers. We will dig deep into different tenets that help build and grow a high-functioning security engineering practice, including secret management, automation services, vulnerability management, reporting and operational excellence, bug bounty programs, training, engagement and product defense strategies.
Attendees will be provided with actionable technical strategies and time-tested lessons to build a comprehensive Secure SDL program and increase their organization's product security maturity in just a few months.
Similar Talks
From Developer to Security: How I Broke into Infosec
Senior Security Advocate @Microsoft
Rey Bango
Robot Social Engineering: Social Engineering Using Physical Robots
Computer Security and Privacy / Human-Robot Interaction Researcher
Brittany Postnikoff
Modern WAF Bypass Scripting Techniques for Autonomous Attacks
Blade Runner & Director of Field Engineering (NA / EU) @kasada_io
Johnny Xmas
Privacy Tools and Techniques for Developers
Privacy Technical Lead at Schellman & Company, LLC
Amber Welch
How Much Does It Cost to Attack You?
Software Engineer @ShapeSecurity
Jarrod Overson
Security Delusions (Not a Sales Pitch!)
VP of Product Strategy @capsule8