Reto Kaeser
You can’t hack what you can’t see
#1about 3 minutes
The cultural shift from DevOps to DevSecOps
DevOps succeeded by fostering a culture of shared responsibility, and now security must be integrated to break down the final silo.
#2about 8 minutes
Integrating security into requirements and design phases
Proactively address security by defining abuse cases during requirements and classifying or anonymizing data during the design phase.
#3about 5 minutes
Hardening the CI/CD pipeline with automated security tools
Shift security left by integrating automated vulnerability management for dependencies and continuous penetration testing into the CI/CD process.
#4about 3 minutes
Why traditional firewalls fail against internal east-west traffic
Most network traffic occurs internally between services (east-west), bypassing perimeter firewalls and exposing a soft interior to application-level attacks.
#5about 3 minutes
Moving from perimeter defense to workload microsegmentation
Protect against internal threats by decoupling security from the network and applying logical firewalls directly to each workload through microsegmentation.
#6about 4 minutes
Applying Zero Trust principles with security as code
Implement a Zero Trust model by having developers define workload communication intentions as code, which automatically generates and enforces security policies.
#7about 2 minutes
The benefits of a modern workload-centric security architecture
Adopting a Zero Trust, workload-centric model provides benefits like increased agility, complete application-level visibility, automated compliance, and real-time forensics.
#8about 1 minute
A developer's responsibility to build secure software
Developers must take ownership of security by adopting a paranoid mindset to build more resilient software in an increasingly dangerous cloud environment.
Related jobs
Jobs that call for the skills explored in this talk.
Architekt für Cloud Security - AWS (w|m|d)

zeb consulting
Frankfurt am Main, Germany
Remote
Junior
Intermediate
Senior
Featured Partners
Related Videos
DevSecOps: Security in DevOps
Aarno Aukia
Climate vs. Weather: How Do We Sustainably Make Software More Secure?
Panel Discussion
Enabling automated 1-click customer deployments with built-in quality and security
Christoph Ruggenthaler
Security Challenges of Breaking A Monolith
Reinhard Kugler
Securing Your Web Application Pipeline From Intruders
Milecia McGregor
Getting under the skin: The Social Engineering techniques
Mauro Verderosa
Maturity assessment for technicians or how I learned to love OWASP SAMM
Mathias Tausig
Cyber Security: Small, and Large!
Martin Schmiedecker
From learning to earning
Jobs that call for the skills explored in this talk.
Senior Enterprise Security Architect (Zero Trust) - M/F/D
Akamai
Remote
Senior
Azure
Kubernetes
Microservices
Network Security
+2
(Senior) Cloud Security Architect - (m/f/x) (onsite / remote in Germany)
Scalable GmbH
München, Germany
Remote
Senior
Python
Gitlab
Jenkins
Terraform
+3
Full-Stack Developer (m/w/d) für Zero-Trust Security Tool & Awareness-Plattform
AJAT GmbH
Köln, Germany
API
Java
REST
React
Node.js
+1
Software Development Engineer-Security Automation, AWS Security OpRes
Amazon
Canton de Courbevoie-1, France
Java
Linux
NoSQL
Python
TypeScript
+2




