> Markdown version of [/videos/36-devsecops-security-in-devops?t=831](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops?t=831). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # DevSecOps: Security in DevOps Integrating security into your CI pipeline transforms final-stage gatekeepers into proactive guardrails. Automate governance to ship secure, compliant code without sacrificing engineering velocity. - **Speakers:** Aarno Aukia - **Event:** WeAreDevelopers LIVE - **Published:** October 12, 2020 - **Duration:** 33:20 - **URL:** https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops ## Summary The transition from rigid waterfall methodologies to agile DevOps resolved many operational bottlenecks, but it frequently left security as a final-stage gatekeeper that blocked releases. Integrating security earlier in the software development lifecycle—moving toward DevSecOps—transforms these barriers into proactive, non-functional requirements. By fostering trust and transparency, security professionals can embed themselves within product backlogs, empowering development teams to iterate quickly while maintaining safe compliance guardrails. Practical DevSecOps implementation relies heavily on continuous integration pipeline automation. Integrating static code analysis and dependency management directly into commit workflows enables developers to resolve vulnerabilities natively. Furthermore, implementing automated container image scanning ensures that standardized, third-party software remains current without manual oversight. This creates a resilient framework around developer self-service tooling, allowing continuous monitoring and automated audit trails to govern systems without slowing down collaborative engineering velocity. Layered abstraction through containerization and orchestration fundamentally scales security efforts. Cloud-native technologies like Docker and Kubernetes do more than package applications; they standardize deployment patterns, centralize logging workflows, and decouple authentication from backend application code. By managing infrastructure as code and relying on version control as the single source of truth, software teams successfully eliminate manual configuration drift and enforce security by default across entire application fleets. Ultimately, cloud-native governance drastically shrinks the scope of security audits. As demonstrated by a highly regulated Swiss banking software provider, certifying base infrastructure platforms means IT risk auditors only need to review application code and environmental configurations. When paired with workflow routing tools to handle regulatory sign-offs visually, organizations can reconcile the rapid pace of continuous delivery with the strictest financial compliance controls. **Keywords:** devsecops implementation, continuous delivery pipeline, static code analysis, dependency management automation, container image scanning, cloud-native governance, non-functional requirements, infrastructure abstraction layers, configuration drift prevention, agile financial compliance, developer self-service tools, container orchestration security, automated audit trails, incident event management, immutable infrastructure patterns, access authentication management ## Chapters 1. **Evolution from waterfall to agile and DevOps** (00:54) — How software development methodologies shifted from reactive waterfall and agile models to proactive DevOps practices. 1. **Shifting security left using the DevSecOps approach** (03:58) — Why security must be integrated as early non-functional requirements rather than a final gatekeeping step. 1. **Defining application, pipeline, and security operations roles** (06:07) — Breaking down the security journey into application security, pipeline deployment security, and incident response operations. 1. **Core principles for implementing DevSecOps in teams** (07:00) — Essential concepts including team transparency, incremental risk management, supply chain governance, and automated audit trails. 1. **Integrating automated security tooling into build pipelines** (11:00) — How to automate static code analysis, dependency tracking, and container baseline scanning for faster validation. 1. **Eliminating operational errors with containerized application deployments** (13:51) — Using containerization and atomic rollbacks to enforce immutable infrastructure and remove manual production access. 1. **Abstracting infrastructure complexity with container orchestration platforms** (16:51) — Leveraging Kubernetes to handle service discovery and standardize operational abstraction across on-premise and cloud hardware. 1. **Utilizing pre-integrated observability and authentication platform tools** (19:54) — Plugging into the Kubernetes ecosystem to standardize container logging, metrics, TLS certificates, and centralized authentication. 1. **Implementing automated DevSecOps governance in banking software** (24:06) — How Enova uses platform abstraction and business process frameworks to automate deployment approvals under strict regulatory constraints. 1. **Replacing full-stack audits with cloud-native iterative governance** (29:19) — Reducing auditing scopes by validating underlying container platforms once and preventing configuration drift via declarative deployments. ## Related Moments - [Embracing DevSecOps and automating the software development lifecycle](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) (from "Maturity assessment for technicians or how I learned to love OWASP SAMM") - [Integrating security and financial disciplines into DevOps models](https://www.wearedevelopers.com/videos/104-cloud-chaos-and-microservices-mayhem) (from "Cloud Chaos and Microservices Mayhem") - [Integrating security into the DevOps lifecycle](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) (from "You can’t hack what you can’t see") - [Securing team and management buy-in for DevSecOps adoption](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) (from "DevSecOps: Injecting Security into Mobile CI/CD Pipelines") - [Integrating security practices for devsecops adoption](https://www.wearedevelopers.com/videos/332-hosting-a-modern-justice-system) (from "Hosting a modern justice system") - [Transitioning team culture from standard DevOps to DevSecOps](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) (from "DevSecOps: Injecting Security into Mobile CI/CD Pipelines") ## Related Articles - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Exploring AI: Opportunities and Risks for Developers](https://www.wearedevelopers.com/magazine/522-exploring-ai-opportunities-and-risks-for-developers) ## Related Jobs - [Devops Engineer](https://www.wearedevelopers.com/jobs/ext/1940926-devops-engineer) at **Bitpanda** - [DevSecOps Architect - Healthcare](https://www.wearedevelopers.com/jobs/ext/1658539-devsecops-architect-healthcare) at **BWI GmbH** - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/1921051-staff-developer-advocate-github-security-lab) at **GitHub** - [Lead Cloud DevSecOps Engineer - Kubernetes](https://www.wearedevelopers.com/jobs/ext/1659167-lead-cloud-devsecops-engineer-kubernetes) at **BWI GmbH** - [DevSecOps Architect - Healthcare](https://www.wearedevelopers.com/jobs/ext/1906032-devsecops-architect-healthcare) at **BWI GmbH** - [DevSecOps Architekt - Cloud Plattform](https://www.wearedevelopers.com/jobs/ext/1378455-devsecops-architekt-cloud-plattform) at **BWI GmbH**