Podcast appearances and mentions of james wickett

  • 14PODCASTS
  • 38EPISODES
  • 41mAVG DURATION
  • ?INFREQUENT EPISODES
  • Aug 27, 2024LATEST

POPULARITY

20172018201920202021202220232024


Best podcasts about james wickett

Latest podcast episodes about james wickett

The RSnake Show
Demo Day - DryRun

The RSnake Show

Play Episode Listen Later Aug 27, 2024 57:06


Today we sat down with James Wickett from DryRun, and Trey and get to see how this innovative startup is using LLMs and deep integrations with Github to automatically find issues.

Future of Application Security
EP 50 — DryRun Security's James Wickett on Aligning Incentives and Speaking the Same Language with Developers and Security

Future of Application Security

Play Episode Listen Later Nov 8, 2023 31:08


In this special episode of the Future of Application Security, recorded at the Developers & Security are Friends Day, Eric speaks with James Wickett, co-founder and CEO of DryRun Security, a company that provides security products for developers. They discuss the misaligned incentives between developers and security and how teams can learn how to speak the same language to increase value. They also talk about how the SLIDE Model helps with context analysis, why you should focus less on control and more on context and composition in your security, and how organizations can close their knowledge gaps. Topics discussed: Some of the frictions between security and developers, including how incentives are often misaligned and how each team has a different focus. How to talk the same language so that security and developers can build relationships that bring value to their organizations. What the SLIDE Model is and how it can help you better understand the context of your security actions and your priorities. How organizations can fill in their knowledge gaps and why it's key to return to first principles in a world of automation and tooling. How security impacts an organization through control, composition, and context, and why organizations should lessen their dependence on control. How security is like barbeque, and why Oklahoma is a great analogy for a DevSec model.

Absolute AppSec
Episode 209 - James Wickett, Contextual Security Analysis

Absolute AppSec

Play Episode Listen Later Jun 6, 2023


Join us for a special episode of Absolute AppSec with James Wickett (@wickett on twitter), the co-founder of DryRun Security (dryrun.security), creator of the Lonestar Application Security Conference, and all around infosec industry veteran.

GOTO - Today, Tomorrow and the Future
Getting Started with Chaos Engineering • Nora Jones, Casey Rosenthal & James Wickett

GOTO - Today, Tomorrow and the Future

Play Episode Listen Later Jul 16, 2021 24:29


This interview was recorded for the GOTO Book Club.http://gotopia.tech/bookclubNora Jones - Co-Author of "Chaos Engineering"Casey Rosenthal - Co-Author of "Chaos Engineering"James Wickett - Founder of Open Source Project GauntltDESCRIPTIONToday we have the authors of the Chaos Engineering book sharing key takeaways from the book and from their experience working on chaos projects. This Book Club episode is an expansion of a recent interview between Nora Jones and Casey Rosenthal on the comedic Chaos Community Broadcast [https://chaos.community].  We now include expanded conversation, including discussion about Nora's work with the Learning from Incidents community.Chaos engineering is much more than just hype. Get the map and compass that you need to navigate the stormy waters of distributed systems while optimizing to meet business goals. Casey Rosenthal and Nora Jones, authors of “Chaos Engineering,” highlight some of the best practices that famous companies like Netflix and Capital One use to break (or not break) their systems in productions, so that you can get a taste of it.The interview is based on Nora Jones's and Casey Rosenthal's new book "Chaos Engineering": https://www.verica.io/bookRead the full transcription of the interview here:https://gotopia.tech/bookclub/episodes/getting-started-with-chaos-engineeringRECOMMENDED BOOKSAaron Rinehart • Security Chaos Engineering • https://www.verica.io/sce-bookNora Jones & Casey Rosenthal • Chaos Engineering • https://www.verica.io/bookNora Jones & Casey Rosenthal • Chaos Engineering • https://amzn.to/3hUmuAHMikolaj Pawlikowski • Chaos Engineering • https://amzn.to/2SQ5OlfRuss Miles • Learning Chaos Engineering • https://amzn.to/3hCiUe8Murphy, Beyer, Jones & Petoff • Site Reliability Engineering • https://amzn.to/2Vg6Mbrhttps://twitter.com/GOTOconhttps://www.linkedin.com/company/goto-https://www.facebook.com/GOTOConferencesLooking for a unique learning experience?Attend the next GOTO conference near you! Get your ticket at http://gotopia.techSUBSCRIBE TO OUR YOUTUBE CHANNEL - new videos posted almost daily.https://www.youtube.com/user/GotoConferences/?sub_confirmation=1

Absolute AppSec
Episode 59: James Wickett on DevOps

Absolute AppSec

Play Episode Listen Later May 14, 2019


Seth and Ken discuss Minecraft mod hacking and applying AppSec tools to the practice. Joined by James Wickett (@wickett) to talk about the history of DevOps, why software security people should learn to code, and current trends in the DevOps space.

Absolute AppSec
Episode 59: James Wickett on DevOps

Absolute AppSec

Play Episode Listen Later May 14, 2019


Seth and Ken discuss Minecraft mod hacking and applying AppSec tools to the practice. Joined by James Wickett (@wickett) to talk about the history of DevOps, why software security people should learn to code, and current trends in the DevOps space.

DevOps Chat
DevSecOps @ RSA Conference with James Wickett and Shannon Lietz

DevOps Chat

Play Episode Listen Later Feb 7, 2019 17:08


The RSA Conference is just a month away. Once again RSAC promises to be the place where the world gathers around security. With upwards of 50,000 people attending, it is big by anyone's standard. If you haven't already registered, here is a code for $100 dollars off a full conference pass (all sessions), 1U9DEVOPSFD or get a free expo pass, 1U9DEVOPSXP DevSecOps will be center stage this year, literally. Shannon Lietz, the found of DevSecOps.org will be keynoting as well as leading a week long track on DevSecOps. Appearing with Shannon, is another leader of the DevSecOps community, James Wickett. James is the founder of the Rugged DevOps movement and a key member of the Signal Science team. Both James and Shannon are our guests in this DevOps Chat. Part 1 of this chat where with just Shannon is also available. In addition to the DevSecOps track all week, there is also the 5th annual DevOps Connect: DevSecOps Days on Monday, March 4th at Moscone, as part of RSAC. www.devopsconnect.com/event/devops-c…ays-rsac-2019/ www.devsecopsdays.com/2019-devsecops…s-sanfrancisco

appearing devsecops rsa conference rsac moscone both james shannon lietz james wickett rugged devops
DevOps Chat
The DevSecOps Scene at RSA Conference 2019 w/ Shannon Lietz

DevOps Chat

Play Episode Listen Later Feb 5, 2019 18:06


The RSA Conference is just a month away. Once again RSAC promises to be the place where the world gathers around security. With upwards of 50,000 people attending, it is big by anyone's standard. If you haven't already registered, here is a code for $100 dollars off a full conference pass (all sessions), 1U9DEVOPSFD a free expo pass, 1U9DEVOPSXP DevSecOps will be center stage this year, literally. Shannon Lietz, the found of DevSecOps.org will be keynoting as well as leading a week long track on DevSecOps. Shannon is our guest in this DevOps Chat. Part 2 of this chat where we are joined by Rugged DevOps founder, James Wickett will follow this chat next. In addition to the DevSecOps track, there is also the 5th annual DevOps Connect: DevSecOps Days on Monday, March 4th at Moscone, as part of RSAC. https://www.devopsconnect.com/event/devops-connect-devsecops-days-rsac-2019/ https://www.devsecopsdays.com/2019-devsecopsdays-sanfrancisco

devsecops rsa conference rsac moscone shannon lietz james wickett rugged devops
Paul's Security Weekly TV
The Human Element of Application Security - Application Security Weekly #47

Paul's Security Weekly TV

Play Episode Listen Later Jan 24, 2019 22:24


This week on Application Security Weekly, Matt Alderman is joined by James Wickett, who is the Head of Research at Signal Sciences. They talk about the human element of application security training and testing. Full Show Notes: https://wiki.securityweekly.com/ASW_Episode47 Follow us on Twitter: https://www.twitter.com/securityweekly

head research human element asw security weekly signal sciences matt alderman james wickett technicalsegment application security weekly
Application Security Weekly (Video)
The Human Element of Application Security - Application Security Weekly #47

Application Security Weekly (Video)

Play Episode Listen Later Jan 23, 2019 22:24


This week on Application Security Weekly, Matt Alderman is joined by James Wickett, who is the Head of Research at Signal Sciences. They talk about the human element of application security training and testing. Full Show Notes: https://wiki.securityweekly.com/ASW_Episode47 Follow us on Twitter: https://www.twitter.com/securityweekly

head research human element asw security weekly signal sciences matt alderman james wickett technicalsegment application security weekly
Paul's Security Weekly
Different Checkpoints - Application Security Weekly #47

Paul's Security Weekly

Play Episode Listen Later Jan 23, 2019 52:14


This week on Application Security Weekly, Matt Alderman takes the reigns and is joined by Co-Host James Wickett, who is the Head of Research at Signal Sciences! They talk about the human element of application security training and testing! In the Application Security News, Oracle patches 284 vulnerabilities, a bug in Twitter Android app exposed protected tweets, four tips for better API Security in 2019, and more!   Full Show Notes: https://wiki.securityweekly.com/ASW_Episode47 Visit https://www.securityweekly.com/asw for all the latest episodes!   Visit our website: https://www.securityweekly.com Follow us on Twitter: https://www.twitter.com/securityweekly Like us on Facebook: https://www.facebook.com/secweekly

Application Security Weekly (Audio)
Different Checkpoints - Application Security Weekly #47

Application Security Weekly (Audio)

Play Episode Listen Later Jan 23, 2019 52:14


This week on Application Security Weekly, Matt Alderman takes the reigns and is joined by Co-Host James Wickett, who is the Head of Research at Signal Sciences! They talk about the human element of application security training and testing! In the Application Security News, Oracle patches 284 vulnerabilities, a bug in Twitter Android app exposed protected tweets, four tips for better API Security in 2019, and more!   Full Show Notes: https://wiki.securityweekly.com/ASW_Episode47 Visit https://www.securityweekly.com/asw for all the latest episodes!   Visit our website: https://www.securityweekly.com Follow us on Twitter: https://www.twitter.com/securityweekly Like us on Facebook: https://www.facebook.com/secweekly

DevOps Chat
James Wickett, Signal Sciences, DevSecOps 2019

DevOps Chat

Play Episode Listen Later Nov 29, 2018 33:59


James Wickett is the man to go to for DevSecOps. The founder of the Rugged DevOps movement which has merged into the DevSecOps group, James is one of the most knowledgeable people on the subject of DevSecOps. In this DevOps Chat James shares his views on what is on the horizon for DevSecOps and what are the most important things we can do to make our teams more secure. Have a listen as James gives us his take. Also look for the video of this interview on DevOps.com

devops devsecops signal sciences james wickett rugged devops
Paul's Security Weekly
Buffet Overflow - Application Security Weekly #40

Paul's Security Weekly

Play Episode Listen Later Nov 21, 2018 64:57


This week, Keith and Paul interview John Kinsella, Vice President of Container Security at Qualys! John discusses Qualys’ Container Security, continuous discovery, and tracking for containers and images! In the Application Security News, Instagram leaks passwords to the public, Clickjacking on Google MyAccount Worth $7,500, James Wickett's thread on Open Source SAST options, an advanced search tool for sensitive information stored in GitHub repos, and more!   Full Show Notes: https://wiki.securityweekly.com/ASW_Episode40 Visit https://www.securityweekly.com/asw for all the latest episodes! Visit https://www.activecountermeasures/asw to sign up for a demo or buy our AI Hunter!   Visit our website: https://www.securityweekly.com Follow us on Twitter: https://www.twitter.com/securityweekly Like us on Facebook: https://www.facebook.com/secweekly

interview vice president security applications kraken open source buffet github overflow containers docker infosec appsec sast qualys container security john kinsella paul asadoorian clickjacking james wickett keithhoodlet ai hunter application security weekly layered insight application security news google myaccount worth open source sast gitminer googlemyaccount
Application Security Weekly (Audio)
Buffet Overflow - Application Security Weekly #40

Application Security Weekly (Audio)

Play Episode Listen Later Nov 21, 2018 64:57


This week, Keith and Paul interview John Kinsella, Vice President of Container Security at Qualys! John discusses Qualys’ Container Security, continuous discovery, and tracking for containers and images! In the Application Security News, Instagram leaks passwords to the public, Clickjacking on Google MyAccount Worth $7,500, James Wickett's thread on Open Source SAST options, an advanced search tool for sensitive information stored in GitHub repos, and more!   Full Show Notes: https://wiki.securityweekly.com/ASW_Episode40 Visit https://www.securityweekly.com/asw for all the latest episodes! Visit https://www.activecountermeasures/asw to sign up for a demo or buy our AI Hunter!   Visit our website: https://www.securityweekly.com Follow us on Twitter: https://www.twitter.com/securityweekly Like us on Facebook: https://www.facebook.com/secweekly

interview vice president security applications kraken open source buffet github overflow containers docker infosec appsec sast qualys container security john kinsella paul asadoorian clickjacking james wickett keithhoodlet ai hunter application security weekly layered insight application security news google myaccount worth open source sast gitminer googlemyaccount
Paul's Security Weekly TV
Instagram, Kraken, GitMiner - Application Security Weekly #40

Paul's Security Weekly TV

Play Episode Listen Later Nov 20, 2018 29:08


Instagram leaks passwords to the public, Clickjacking on Google MyAccount Worth $7,500, James Wickett's thread on Open Source SAST options, an advanced search tool for sensitive information stored in GitHub repos, and more! Full Show Notes: https://wiki.securityweekly.com/ASW_Episode40 Follow us on Twitter: https://www.twitter.com/securityweekl  

kraken open source github sast clickjacking james wickett application security weekly google myaccount worth open source sast gitminer googlemyaccount
Application Security Weekly (Video)
Instagram, Kraken, GitMiner - Application Security Weekly #40

Application Security Weekly (Video)

Play Episode Listen Later Nov 19, 2018 29:08


Instagram leaks passwords to the public, Clickjacking on Google MyAccount Worth $7,500, James Wickett's thread on Open Source SAST options, an advanced search tool for sensitive information stored in GitHub repos, and more! Full Show Notes: https://wiki.securityweekly.com/ASW_Episode40 Follow us on Twitter: https://www.twitter.com/securityweekly

kraken open source github sast clickjacking james wickett application security weekly google myaccount worth open source sast gitminer googlemyaccount
Enterprise Security Weekly (Audio)
A Picture of the World - Enterprise Security Weekly #115

Enterprise Security Weekly (Audio)

Play Episode Listen Later Nov 15, 2018 64:45


This week, Paul and Matt Alderman interview James Wickett, Head of Research at Signal Sciences! James talks about how security is moving to the application space and web applications! In the Enterprise News this week, AlgoSec delivers Native Cloud Security Management for Azure, HP Reinvents customer experience with Ping Identity, what mid market security budgets will look like in 2019, and we have some acquisition & funding updates from ForeScout, Dragos, Netskope, Duality, and more!   Full Show Notes: https://wiki.securityweekly.com/ES_Episode115 To learn more about Signal Sciences, go to: www.signalsciences.com/psw   Visit https://www.securityweekly.com/esw for all the latest episodes! Visit https://www.activecountermeasures/esw to sign up for a demo or buy our AI Hunter!   Follow us on Twitter: https://www.twitter.com/securityweekly Like us on Facebook: https://www.facebook.com/secweekly

head research security picture developers enterprise hp azure duality microsoft azure dragos waf netskope ping identity psw forescout signal sciences esw wafs paul asadoorian enterprise security weekly matt alderman james wickett algosec ai hunter enterprise news techseg headofresearch applicationspace native cloud security management es episode115 to
Enterprise Security Weekly (Video)
James Wickett, Signal Sciences - Enterprise Security Weekly #115

Enterprise Security Weekly (Video)

Play Episode Listen Later Nov 15, 2018 32:50


James Wickett is the Head of Research at Signal Sciences. James talks about how security is moving to the application space and web applications. WAFs may seem tedious but they are necessary to allow developers to focus on other things. Full Show Notes: https://wiki.securityweekly.com/ES_Episode115 To learn more about Signal Sciences, go to: www.signalsciences.com/psw Visit http://securityweekly.com/esw for all the latest episodes!

head research developers waf signal sciences wafs enterprise security weekly james wickett techseg es episode115 to headofresearch applicationspace
Paul's Security Weekly
A Picture of the World - Enterprise Security Weekly #115

Paul's Security Weekly

Play Episode Listen Later Nov 15, 2018 64:45


This week, Paul and Matt Alderman interview James Wickett, Head of Research at Signal Sciences! James talks about how security is moving to the application space and web applications! In the Enterprise News this week, AlgoSec delivers Native Cloud Security Management for Azure, HP Reinvents customer experience with Ping Identity, what mid market security budgets will look like in 2019, and we have some acquisition & funding updates from ForeScout, Dragos, Netskope, Duality, and more!   Full Show Notes: https://wiki.securityweekly.com/ES_Episode115 To learn more about Signal Sciences, go to: www.signalsciences.com/psw   Visit https://www.securityweekly.com/esw for all the latest episodes! Visit https://www.activecountermeasures/esw to sign up for a demo or buy our AI Hunter!   Follow us on Twitter: https://www.twitter.com/securityweekly Like us on Facebook: https://www.facebook.com/secweekly

head research security picture developers enterprise hp azure duality microsoft azure dragos waf netskope ping identity psw forescout signal sciences esw wafs paul asadoorian enterprise security weekly matt alderman james wickett algosec ai hunter enterprise news techseg headofresearch applicationspace native cloud security management es episode115 to
Paul's Security Weekly TV
James Wickett, Signal Sciences - Enterprise Security Weekly #115

Paul's Security Weekly TV

Play Episode Listen Later Nov 15, 2018 32:50


James Wickett is the Head of Research at Signal Sciences. James talks about how security is moving to the application space and web applications. WAFs may seem tedious but they are necessary to allow developers to focus on other things. Full Show Notes: https://wiki.securityweekly.com/ES_Episode115 To learn more about Signal Sciences, go to: www.signalsciences.com/psw Visit http://securityweekly.com/esw for all the latest episodes!

head research developers waf signal sciences wafs enterprise security weekly james wickett techseg es episode115 to headofresearch applicationspace
DevSecOps Podcast Series
Spy vs Spy in Application Security: Harvesting Adversaries

DevSecOps Podcast Series

Play Episode Listen Later Nov 2, 2018 16:13


"The guy who wrote wifi software with SSID never imagined that someone could use that SSID to transmit data by writing two smaller applications to leverage it. We are constantly going to be in this [type of] battle. Ultimately we've got to find a way to stay ahead of it by understanding the mechanisms by which we're writing the abuse case possibilities." -- Shannon Lietz Following their session at DevOps Enterprise Summit 2018, I sat down and talked with Shannon Lietz and James Wickett to talk about who the real adversaries are when it comes to application security, what you can do to expose those adversaries and steps to get started in your own, internal adversary program. About Shannon Lietz DevSecOps Leader for Intuit Shannon Lietz is an award winning innovator with over two decades of experience pursuing advanced security defenses and next generation security solutions. Ms. Lietz is currently the DevSecOps Leader for Intuit where she is responsible for setting and driving the company’s DevSecOps and cloud security strategy, roadmap and implementation in support of corporate innovation. She operates a 24x7 DevSecOps team that specializes in Adversary Management. Prior to joining Intuit, Ms. Lietz worked for ServiceNow where she was responsible for the cloud security engineering efforts and Sony where she drove the implementation of a new secure data center. Ms. Lietz has significant experience leading crisis management large-scale security breaches and restoration of services for several Fortune 500 companies. She has previous experience as a founder a metrics company, leading major initiatives for hosting providers as a Master Security Architect, developing security software and consulting for many Fortune 500 companies globally. Ms. Lietz is an IANS faculty member and holds a Bachelors of Science degree in Biological Sciences from Mount St. Mary’s College. About James Wickett Head of Research, Signal Sciences James spends a lot of time at the intersection of the DevOps and Security communities. He works as Head of Research at Signal Sciences and is a supporter of the Rugged Software and DevSecOps movements. Seeing the gap in software testing, James founded an open source project, Gauntlt, to serve as a Rugged Testing Framework. He is the author of several security and DevOps courses onLinkedIn Learning, including: DevOps Foundations, Infrastructure as Code, DevSecOps: Automated Security Testing, Continuous Delivery (CI/CD), and Site Reliability Engineering. He got his start in technology when he founded a startup as a student at the University of Oklahoma and has since worked in environments ranging from large, web-scale enterprises to small, rapid-growth startups. He is a dynamic speaker on topics in DevOps, AppSec, InfoSec, cloud security, automated security testing, DevSecOps and serverless. James is the creator and founder of the Lonestar Application Security Conference which is the largest annual security conference in Austin, TX. He also runs DevOps Days Austin and previously served on the global DevOps Days board. He also bears several security certifications including CISSP and GWAPT.

CISO-Security Vendor Relationship Podcast
Our Latest Product Release Includes Shiny New Security Vulnerabilities

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later Sep 10, 2018 31:30


We have an exciting announcement. Our latest version of the podcast is packed with new features and they're riddled with security holes. We know you wanted the features. The security vulnerabilities are just a bonus. On this episode of the CISO/Security Vendor Relationship Podcast, we discuss: Cybersecurity burnout: How bad is it? What can be done to mitigate it? And what are the warning signs? All tech professionals have burnout issues, but InfoSec has it toughest because it's very hard for them to get a sense of accomplishment for their work. CISO/Security Vendor Relationship Podcast is making an impact in the vendor community: We hear multiple stories from vendors how the advice from Mike and the guests is really changing the way they reach out to security professionals. Are you willing to release a product with known security vulnerabilities? What if the customer really demands the new feature next week and they're expecting it, but remediation may take much longer. Do you give the customer what they want, or are there other solutions? What's Worse?! We play a round of picking the worse of two evils. This one is all about training your staff. We unleash another pitch on the security professionals: Their response will surprise you as will the outcome of this pitch. Dumb CISO mistakes: This one actually may not be so dumb. It could actually be good advice when it comes to product testing. Ten-second security tip: This one offers up a more holistic view of security that you may have not considered, but definitely should. Special thanks to Signal Sciences for sponsoring this episode. If you’re using WAFs, make sure you read “Three Ways Legacy WAFs Fail,” by their head of research, James Wickett. As always, the show is hosted by me, David Spark (@dspark), founder, Spark Media Solutions and Mike Johnson, CISO, Lyft. Our guest is Anne Marie Zettlemoyer, a security strategist and independent researcher who is also on the board of directors for SSH.  

CISO-Security Vendor Relationship Podcast
Security Made the Mess. They Should Clean It Up.

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later Aug 27, 2018 29:53


Security is suffering from a serious Rodney Dangerfield "I get no respect" problem. What has often been seen as the department of "no" is struggling under that brand image. That's probably because security is often seen as an inhibitor rather than an enabler. If InfoSec wants to fix that perception, it'll be their responsibility to dig themselves out. Here's what you'll hear on the latest episode of the CISO/Security Vendor Relationship Podcast: Nobody thinks security is their friend: How can security rid itself of this highly negative branding? Be problem solvers vs. problem creators. Techniques to integrate AppSec into the DevOps process: It comes down to measurement, respecting an engineer's time, and learning from the success of one process and putting it into another. Read more great insight by Chris Steipp of Lyft. We play "What's Worse?!" In this episode of the game we question the worst scenario of an encrypted or unencrypted laptop, but with qualifications. Uggh, WAFs are NOT magical boxes: In a round of "Please, Enough. No, More." we challenge the way web application firewalls (WAFs) are being sold. WAFs need to be more friendly and flexible. No one believes you if you sell them as magical boxes that stop all attacks. How can you be a great customer? We turn the tables from "Ask a CISO" to "Ask a Vendor" and ask what it takes to be a great customer. Vendors would like you to ttop kicking the tires and talk about solving real problems. Plus a ten-second security tip: It may be cliche, but if security departments want to be more effective, they should be moving away from blocking to enabling. Special thanks to Signal Sciences for sponsoring this episode. If you’re using WAFs, make sure you read “Three Ways Legacy WAFs Fail,” by their head of research, James Wickett. As always, the show is hosted by me, David Spark (@dspark), founder, Spark Media Solutions and Mike Johnson, CISO, Lyft. Our guest this week is Zane Lackey (@zanelackey), co-founder and CSO for Signal Sciences and author of the new book from O'Reilly, "Building a Modern Security Program." Sponsor the Podcast If you'd like to sponsor the podcast, contact David Spark at Spark Media Solutions.

Application Security Weekly (Audio)
We Do Not Discriminate - Application Security Weekly #27

Application Security Weekly (Audio)

Play Episode Listen Later Aug 8, 2018 62:23


This week, Keith and James Wickett interview Galen Hunt, Distinguished Engineer and Director at Microsoft! In the news, hackers automate the laundering of money via Clash of Clans, Epic Games sidesteps the Play Store with Fortnite for Android launch, the most exciting game, and more on this episode of Application Security Weekly!   Full Show Notes: https://wiki.securityweekly.com/ASW_Episode27   Visit https://www.securityweekly.com/asw for all the latest episodes!   Visit https://www.activecountermeasures/asw to sign up for a demo or buy our AI Hunter!   →Visit our website: https://www.securityweekly.com →Follow us on Twitter: https://www.twitter.com/securityweekly →Like us on Facebook: https://www.facebook.com/secweekly

Paul's Security Weekly
We Do Not Discriminate - Application Security Weekly #27

Paul's Security Weekly

Play Episode Listen Later Aug 8, 2018 62:23


This week, Keith and James Wickett interview Galen Hunt, Distinguished Engineer and Director at Microsoft! In the news, hackers automate the laundering of money via Clash of Clans, Epic Games sidesteps the Play Store with Fortnite for Android launch, the most exciting game, and more on this episode of Application Security Weekly!   Full Show Notes: https://wiki.securityweekly.com/ASW_Episode27   Visit https://www.securityweekly.com/asw for all the latest episodes!   Visit https://www.activecountermeasures/asw to sign up for a demo or buy our AI Hunter!   →Visit our website: https://www.securityweekly.com →Follow us on Twitter: https://www.twitter.com/securityweekly →Like us on Facebook: https://www.facebook.com/secweekly

CISO-Security Vendor Relationship Podcast
Ultra Enhanced Deluxe AI with a Drop of Retsyn

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later Jul 31, 2018 29:44


Just like so many security products are infused with artificial intelligence, we've also got plenty of meaningless modifiers to describe this podcast. On this episode we've got: First 90 Days of a CISO. How do you assess talent already there, and how do you prioritize the new hires you need? Please, Enough! No, More! We delve into the overexposure of AI (artificial intelligence) and machine learning. Are they the same thing? And what do CISOs actually want to hear more about on both of these topics? "What's Worse?!" This is a brand new game where I ask the CISOs to determine which of two really bad security practices is worse. What Do You Think of This Pitch? We've got another vendor pitch that the CISOs critique. Ask a CISO. How are CISOs involved in purchase decisions that are not security related (e.g., cloud, networking, infrastructure). Special thanks to Signal Sciences for sponsoring this episode. If you're using web application firewalls (WAFs), make sure you read "Three Ways Legacy WAFs Fail" by their head of research, James Wickett. As always, the show is hosted by me, David Spark (@dspark), founder, Spark Media Solutions and Mike Johnson, CISO, Lyft. Our guest this week is Dennis Leber (@dennisleber), CISO, Cabinet for Health and Family Services, Commonwealth of Kentucky and the self proclaimed "Most Interesting Man in Information Security." We Want More of "What's Worse?!" In this episode, I introduced a new segment, a game called "What's Worse?!" where I introduce two comparably bad security practices and ask the CISOs to debate on which is worse, and why. Fortunately in this episode the CISOs disagreed on both comparisons posed. I'm eager to challenge CISOs with more "What's Worse?!" questions. So if you've got a good one, please contact me here or on LinkedIn. I'm also interested in: “Ask a CISO” questions. A vendor pitch you want us to critique. A hot security discussion (please provide a link). A quick security tip. A big industry story and what it means to security professionals. In all cases, we can mention you and your company name or keep you anonymous. Just let me know which you prefer. Listen and Subscribe to the CISO/Security Vendor Relationship Podcast So many ways to connect and listen to the podcast. iTunes Google Play Stitcher RSS Feed Sponsor the Podcast If your company would like to sponsor this podcast, please contact David Spark at Spark Media Solutions.

Application Security Weekly (Audio)
A Bunch Of Robots - Application Security Weekly #23

Application Security Weekly (Audio)

Play Episode Listen Later Jul 6, 2018 68:11


This week, Keith is joined by James Wickett from Signal Sciences to interview Thomas GX, CEO of Yelda and Founder of CommitStrip! In the news, Keith and James talk GitHub Hackers, Ticketmaster breach, Sniffing network traffic, and more on this episode of Application Security Weekly!   Full Show Notes: https://wiki.securityweekly.com/ASW_Episode22   Visit https://www.securityweekly.com/asw for all the latest episodes!   →Visit our website: https://www.securityweekly.com →Follow us on Twitter: https://www.twitter.com/securityweekly →Like us on Facebook: https://www.facebook.com/secweekly

Paul's Security Weekly
A Bunch Of Robots - Application Security Weekly #22

Paul's Security Weekly

Play Episode Listen Later Jul 6, 2018 68:11


This week, Keith is joined by James Wickett from Signal Sciences to interview Thomas GX, CEO of Yelda and Founder of CommitStrip! In the news, Keith and James talk GitHub Hackers, Ticketmaster breach, Sniffing network traffic, and more on this episode of Application Security Weekly!   Full Show Notes: https://wiki.securityweekly.com/ASW_Episode22   Visit https://www.securityweekly.com/asw for all the latest episodes!   →Visit our website: https://www.securityweekly.com →Follow us on Twitter: https://www.twitter.com/securityweekly →Like us on Facebook: https://www.facebook.com/secweekly

Paul's Security Weekly TV
PHPMyAdmin, GitHub, and VS Code - Application Security Weekly #22

Paul's Security Weekly TV

Play Episode Listen Later Jul 5, 2018 35:16


'GDPR-Lite', Testing Firefox, refactoring in VS Code, sniff network traffic from our iOS device, Gentoo GitHub organization is hacked, and what does it mean to experience fulfillment? All that and more, here on Application Security Weekly! Full Show Notes: https://wiki.securityweekly.com/ASW_Episode22 Follow us on Twitter: https://www.twitter.com/securityweekly

ios github vs code phpmyadmin keithhoodlet james wickett application security weekly
Application Security Weekly (Video)
PHPMyAdmin, GitHub, and VS Code - Application Security Weekly #22

Application Security Weekly (Video)

Play Episode Listen Later Jul 5, 2018 35:16


'GDPR-Lite', Testing Firefox, refactoring in VS Code, sniff network traffic from our iOS device, Gentoo GitHub organization is hacked, and what does it mean to experience fulfillment? All that and more, here on Application Security Weekly!Full Show Notes: https://wiki.securityweekly.com/ASW_Episode22 Follow us on Twitter: https://www.twitter.com/securityweekly

ios github vs code phpmyadmin keithhoodlet james wickett application security weekly
Paul's Security Weekly TV
Thomas GX, Yelda - Application Security Weekly #22

Paul's Security Weekly TV

Play Episode Listen Later Jul 3, 2018 33:00


Thomas GX is a French entrepreneur specialized in Automation, AI, Assistants & Bots, handling creation and development as well as project management processes. Full Show Notes: https://wiki.securityweekly.com/ASW_Episode22 Follow us on Twitter: https://www.twitter.com/securityweekly

interview ai french automation yelda frenchentrepreneur keithhoodlet james wickett application security weekly
Application Security Weekly (Video)
Thomas GX, Yelda - Application Security Weekly #22

Application Security Weekly (Video)

Play Episode Listen Later Jul 3, 2018 33:00


Thomas GX is a French entrepreneur specialized in Automation, AI, Assistants & Bots, handling creation and development as well as project management processes. Full Show Notes: https://wiki.securityweekly.com/ASW_Episode22 Follow us on Twitter: https://www.twitter.com/securityweekly

interview ai french automation yelda frenchentrepreneur keithhoodlet james wickett application security weekly
Application Security Weekly (Video)
James Wickett, Signal Sciences - Application Security Weekly #17

Application Security Weekly (Video)

Play Episode Listen Later May 23, 2018 35:23


James is the creator and founder of the Lonestar Application Security Conference which is the largest annual security conference in Austin, TX. He also runs DevOps Days Austin and is on the global DevOps Days board. He also holds several security certifications including CISSP and GWAPT. He joins Keith and Paul this week for an interview! Full Show Notes: https://wiki.securityweekly.com/ASW_Episode17 Visit our website: http://securityweekly.com Follow us on Twitter: https://www.twitter.comsecurityweekly

interview tx app application devops cissp appsec devopsdays signal sciences james wickett keithhoodlet application security weekly
Paul's Security Weekly
Just Go With It - Application Security Weekly #17

Paul's Security Weekly

Play Episode Listen Later May 23, 2018 63:44


This week, Keith and Paul interview James Wickett, Head of Research at Signal Sciences! In the news, we have updates from Nest, Node.js, Google, F.Secure, and more on this episode of Application Security Weekly!   Full Show Notes: https://wiki.securityweekly.com/ASW_Episode17   Visit https://www.securityweekly.com/asw for all the latest episodes!

Paul's Security Weekly TV
James Wickett, Signal Sciences - Application Security Weekly #17

Paul's Security Weekly TV

Play Episode Listen Later May 23, 2018 35:23


James is the creator and founder of the Lonestar Application Security Conference which is the largest annual security conference in Austin, TX. He also runs DevOps Days Austin and is on the global DevOps Days board. He also holds several security certifications including CISSP and GWAPT. He joins Keith and Paul this week for an interview! Full Show Notes: https://wiki.securityweekly.com/ASW_Episode1 Visit our website: http://securityweekly.com Follow us on Twitter: https://www.twitter.comsecurityweekly

interview tx app application devops cissp appsec devopsdays signal sciences james wickett keithhoodlet application security weekly
Application Security Weekly (Audio)
Just Go With It - Application Security Weekly #17

Application Security Weekly (Audio)

Play Episode Listen Later May 23, 2018 63:44


This week, Keith and Paul interview James Wickett, Head of Research at Signal Sciences! In the news, we have updates from Nest, Node.js, Google, F.Secure, and more on this episode of Application Security Weekly!   Full Show Notes: https://wiki.securityweekly.com/ASW_Episode17   Visit https://www.securityweekly.com/asw for all the latest episodes!

Down the Security Rabbithole Podcast
DtR Episode 20 - Guest: Gene Kim - DevOps live from HP Discover Las Vegas

Down the Security Rabbithole Podcast

Play Episode Listen Later Aug 6, 2012


Synopsis This episode was recorded in June '12, live from the show floor at HP Discover Las Vegas, 2012 and the talk of the town was once again DevOps.  Gene and I have had 2 prior conversations on the topic, but we're once again tackling the impact of DevOps on the IT and security relationship and overall business value.  We tip our hats to several people including Josh Corman (Rugged DevOps), David Mortman, James Wickett, Nick Galbreath and Mr. Daniel Blander for their prior contributions and supporting work on the topic.  Gene talks about some of the mechanisms we have available to us to bridge that IT Security-to-developer-to-operations gap that's holding us back from true business value.  Fun fact- studies have found that when you wake up a developer at 2am to solve an issue, problem resolution times plummet! Enjoy the podcast, and go grab Gene's books when they're available... comments are welcome! Guest Gene Kim - Gene is finishing up the third and fourth books, "When IT Fails: The Novel" and "The DevOps Cookbook," [highly recommended reads for any IT professional who aspires to high performance] scheduled to be published in August 2012. Both are the culmination of over 13 years of researching both high-performing and low-performing IT organizations, as well as benchmarking over 1500 IT organizations to help inform what behaviors simultaneously advance business and information security objectives.  LinkedIn profile, just in case you have never had the pleasure -http://realgenekim.me. Links Gene Kim's publisher website (mentioned in the podcast) - ITRevolution.com