Nick Ritter and Marcelo Carvalho of GE discuss how they have integrated security into their development process. They focus on some of the challenges with agile / rapid development that is not going to wait for a traditional security development approach. For example, a two to four week pen test is way to long for a 4 to 6 week sprint. It can support about 48 hours of testing.
The session includes tools they have developed, techniques and lessons learned throughout the development lifecycle. They flat out say, “we didn’t get here quickly”. Doing this right is a lot of work.