We’re in the middle of a significant shift in how security teams operate and prioritize their limited budget and person-time.
Rather than investing in finding more bugs, many modern security teams are instead focusing on providing developers with frameworks and services with secure defaults (“guard rails”) so that developers can build features quickly and securely. When done correctly, combining secure defaults and lightweight checks can enable organizations to solve classes of vulnerabilities by construction, preventing bug whack-a-mole.
In this talk, we’ll present a practical step-by-step methodology for:
Choosing what to focus your AppSec resources on
How to combine secure defaults + lightweight invariant enforcement to eradicate entire vulnerability classes
How to integrate continuous code scanning into your CI/CD processes in a way that’s fast, high signal, and low friction for developers
How to use an open source, lightweight security linting tool to find bugs and anti-patterns specific to your company
Bio:
Clint Gibler (@clintgibler) is the Head of Security Research for r2c, a startup working on giving security tools directly to developers. Previously, Clint was a Research Director at NCC Group, a global security consulting firm, where he helped companies implement security automation and DevSecOps best practices as well as performed penetration tests for companies ranging from large enterprises to new startups. Clint has previously spoken at conferences including BlackHat USA, AppSec USA/EU/Cali, BSidesSF, and many DevSecCons. Clint holds a Ph.D. in Computer Science from the University of California, Davis. Want to keep up with security research? Check out *tl;dr sec*, Clint’s newsletter that contains summaries of artisanally curated, top talks and useful security links and resources from around the web. https://tldrsec.com/