Ali Yazdani

DevSecOps culture

Stop thinking about security tools. DevSecOps is a cultural transformation, not a technology problem.

DevSecOps culture
#1about 2 minutes

The evolution from traditional security to DevSecOps

Traditional security testing at the end of the pipeline creates friction and downtime, leading to the rise of DevSecOps to integrate security with development and operations.

#2about 2 minutes

DevSecOps is a culture, not just a set of tools

Implementing DevSecOps successfully requires focusing on its three core pillars—people, process and tools, and governance—rather than just adopting new technologies.

#3about 3 minutes

The people pillar and establishing shared responsibility

Breaking down traditional silos between development, security, and operations is crucial for creating a shared responsibility model where everyone contributes to security.

#4about 2 minutes

The technology pillar and automating security tests

Technology enables DevSecOps by automating repeatable security tests like secret scanning, SAST, and software composition analysis within the CI/CD pipeline.

#5about 2 minutes

The governance pillar for tracking progress and compliance

Governance provides structure through policy as code and visualization, helping teams track security posture, manage expectations, and ensure compliance.

#6about 2 minutes

Overcoming common DevSecOps implementation challenges

Successfully implementing DevSecOps involves navigating cultural resistance, ensuring seamless tool integration, and meeting complex compliance requirements like ISO 27001 and SOC 2.

#7about 2 minutes

Reducing costs by shifting security left

Shifting security practices earlier in the development lifecycle, such as with pre-commit hooks, significantly reduces the cost and effort required to find and fix vulnerabilities.

#8about 1 minute

Communication is key to a successful DevSecOps journey

Clear and consistent communication with developers about the purpose and implementation of security measures is the most critical factor in reducing friction and ensuring adoption.

Related jobs
Jobs that call for the skills explored in this talk.

Featured Partners

Related Articles

View all articles
AG
Andre Braun, GitLab
Now is the time for industrialized software development
Now is the time for industrialized software development Recently, I received a letter from my car’s manufacturer alerting me to a recall. They had discovered a defective part and wanted to replace it. It was easily fixed, and I might have forgotten a...
Now is the time for industrialized software development
DC
Daniel Cranney
Dev Digest 194: AI vs. Version Control, Password Louvre & Cursed Webdev
Inside last week’s Dev Digest 194 . 🧠 Learn how to become an AI-native software engineer 🤷‍♂️ How can you stand out when anyone can build anything? 👂 Whisper Leak allows listening to encrypted chats 🐝 What’s new the OWASP2025 Top Ten List 🙅‍♀️ Curse...
Dev Digest 194: AI vs. Version Control, Password Louvre & Cursed Webdev

From learning to earning

Jobs that call for the skills explored in this talk.

DevOps Engineer

DevOps Engineer

The Devops
Canterbury, United Kingdom

£50-55K
.NET
Bash
MySQL
DevOps
+5
DevSecOps Engineer

DevSecOps Engineer

Accenture
Municipality of Bilbao, Spain

API
Scrum
DevOps
Docker
Kubernetes
+1
DevSecOps Engineer

DevSecOps Engineer

Accenture
Municipality of Madrid, Spain

API
Scrum
DevOps
Docker
Kubernetes
+1
DevSecOps

DevSecOps

Robert Half
Frankfurt am Main, Germany

DevOps
Docker
Kubernetes
Agile Methodologies
Amazon Web Services (AWS)
DevOps

DevOps

UnderDefense

Remote
Bash
Azure
React
Kafka
+16
DevSecOps

DevSecOps

Accenture
Municipality of Madrid, Spain

Senior
Go
API
C++
HTML
Java
+16