70 episodes

A Podcast dedicated to forging iron clad relationships between developers, engineers, operations, and security practitioners by discussing hot topics in the world of DevSecOps. This podcast aims to air out some of the common gripes, misconceptions, and hardships that these teams face in the real world every day.

Relating to DevSecOps Ken Toler and Mike McCabe

    • Technology
    • 4.8 • 8 Ratings

A Podcast dedicated to forging iron clad relationships between developers, engineers, operations, and security practitioners by discussing hot topics in the world of DevSecOps. This podcast aims to air out some of the common gripes, misconceptions, and hardships that these teams face in the real world every day.

    Episode #069: Your SaaS is Grass

    Episode #069: Your SaaS is Grass

    In this episode Mike and Ken dive into the wild world of SaaS products in DevSecOps. From vendors to security tooling hygiene they cover an often overlooked ecosystem of cloud and software services that may be rotting in the sky of your workloads. Join up for a listen on SaaS Security!

    • 32 min
    Episode #068: Data Breaches and DevSecOps

    Episode #068: Data Breaches and DevSecOps

    With pep and full youtube energy Ken and Mike discuss the findings of the IBM "Cost of a Data Breach" report and its implications for DevSecOps. They highlight the importance of integrating security into every phase of the software development life cycle and the positive impact it can have on reducing the cost of a data breach.

    • 34 min
    Episode #067: Welcome to 2024! AppSec Resolutions and A Smhoocon Recap

    Episode #067: Welcome to 2024! AppSec Resolutions and A Smhoocon Recap

    Ken and Mike discuss their new year's resolutions related to application security. They also reflect on the impact of AI and its adoption in the industry. The hosts share their experiences attending conferences and highlight interesting talks on topics such as zero-day vulnerabilities and fuzzing LLM models. They discuss the OWASP LLM Top 10 and the evolving perception of AI in the industry. The conversation concludes with a discussion on the definition of DevSecOps and how it has evolved over time, as well as their predictions for DevSecOps in 2024.

    • 35 min
    Episode #066: Exploration of the Shifting Definition of Shifting Left

    Episode #066: Exploration of the Shifting Definition of Shifting Left

    We are joined by incredible guests Mikhail Chechik and Marcus Hallberg as they help us define DevSecOps and emphasize the importance of a security mindset throughout the development process. These two incredible folks explore common misconceptions about shifting left and discuss the challenges of triaging and validating vulnerabilities early in the development lifecycle. We enter in the wild world of this wonderful shifting buzzword and how it applies to incident response, design, people, and the general development process.

    • 42 min
    Episode #065: LASCON 2023 Recap - AI, a Misunderstood Menace or Magic Bullet

    Episode #065: LASCON 2023 Recap - AI, a Misunderstood Menace or Magic Bullet

    On this episode of R2DSO Mike and Ken dive into their takeaways and experiences from LASCON 2023 in Austin, TX where AI was both a problem child and praised bringer of salvation in security. Vendors and companies alike are embracing AI with wide eyes and there was no shortage of talks, presentations, and hallway conversations about the topic. Beyond that security is fast accepting that they can't be the department of "No" a consistent theme here on the podcast. The team had a fantastic time at LASCON and we're happy to see where the industry is going!

    • 33 min
    Episode #064: Don't Instigate, Mitigate!

    Episode #064: Don't Instigate, Mitigate!

    In this episode Ken and Mike dive directly into the meat with solutioning and mitigation. All too often security professionals finding themselves falling into the trap of focusing on vulnerability counts, evangelizing findings, and playing the age old game of red, yellow, green. We jump straight into the why of this focus in the industry and offer some ideas on how to get out of it successfully. If you're interested in a conversation about solving problems rather than just identifying them, hop on in!

    • 31 min

Customer Reviews

4.8 out of 5
8 Ratings

8 Ratings

IndianConnection ,

Great info, entertaining and kind!

Love the humility that comes across in your exchanges.
You guys are very informative too. I’m a product owner now, after spending over a decade and a half in devops.
I started with episode 31 I think. That was enough to hook me. I’m now on episode 2 - cause I intend to listen to em all!

Top Podcasts In Technology

Lex Fridman Podcast
Lex Fridman
All-In with Chamath, Jason, Sacks & Friedberg
All-In Podcast, LLC
Acquired
Ben Gilbert and David Rosenthal
BG2Pod with Brad Gerstner and Bill Gurley
BG2Pod
The Neuron: AI Explained
The Neuron
TED Radio Hour
NPR

You Might Also Like

DevOps and Docker Talk: Cloud Native Interviews and Tooling
Bret Fisher
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
Cyber Security Headlines
CISO Series
Security Now (Audio)
TWiT
Darknet Diaries
Jack Rhysider
Radiolab
WNYC Studios