World Congress 2023 Oct 23, 2023

DevSecOps culture

Ali Yazdani

Technology alone won’t solve your security problems. Discover how to build a DevSecOps culture that transforms isolated security bottlenecks into true development enablers.

Pause
Mute Enter Fullscreen
#1 about 3 min

Transitioning from late production testing to continuous integrated security

Testing applications exclusively in production causes operational downtime and creates friction between developers and engineers.

#2 about 2 min

Relying on collaborative culture rather than single security tools

Integrating shared responsibilities and team collaboration solves security problems better than just buying new automation software.

#3 about 2 min

Breaking organizational silos to balance delivery speed and stability

Distributing the workload equally across teams ensures faster software delivery without sacrificing application stability.

#4 about 2 min

Revising internal processes to improve transparency and team communication

Creating security champions across different departments prevents teams from secretly bypassing established test pipelines.

#5 about 3 min

Deploying automated security analysis tools directly into application pipelines

Integrating software component analysis and secret scanning prevents expensive credential leaks in public repositories.

#6 about 2 min

Using visualization and policy code to govern pipeline execution

Monitoring scan logs visually helps managers identify and address developers who skip essential run-time analysis.

#7 about 3 min

Overcoming cultural resistance to achieve international security compliance standards

Combining cross-functional communication with seamless tooling integration allows small teams to secure major regulatory certifications.

#8 about 2 min

Evaluating security culture transformation as a long-term resource investment

Catching software vulnerabilities earlier in the development cycle aggressively reduces the total cost of remediation.

#9 about 2 min

Moving security scanning into local environments via pre-commit conditions

Running automated tests locally before code is merged completely eliminates the accidental publishing of system secrets.

Matching moments

2:57 min

Securing team and management buy-in for DevSecOps adoption

Moataz Nabil Moataz Nabil · LIVE

2:34 min

Transitioning team culture from standard DevOps to DevSecOps

Moataz Nabil Moataz Nabil · LIVE

6:32 min

Embracing DevSecOps and automating the software development lifecycle

Mathias Tausig · LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

4:00 min

Core principles for implementing DevSecOps in teams

Aarno Aukia · LIVE

17:55 min

Overcoming cultural friction and scaling DevOps team practices

Jacob Duijzer · LIVE

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 25, 2026 · 15:00–17:00

Stage 12

Secure development from pull request to production with GitHub

Sam Jarvinen

Senior Solutions Engineer, GitHub

Sam Jarvinen
Open session

World Congress 2026 North America

September 23, 2026 · 15:45–17:45

Stage 10

Securing the Agentic Stack: Docker Hardened Images and Supply Chain Security

Ajeet Raina

Developer Advocate, Docker

Ajeet Raina
Open session

World Congress 2026 North America

September 25, 2026 · 09:00–09:30

Stage 4

Don’t kill my Vibes - Simple Steps to Stay Secure when Vibe Coding

Isaac Evans

Co-founder & CEO of Semgrep

Isaac Evans
Open session

World Congress 2026 North America

September 25, 2026 · 13:30–14:00

Stage 9

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

September 25, 2026 · 11:40–12:10

Stage 3

Culture Doesn't Scale Itself: Leading Engineering Teams Through Hypergrowth and the AI Transition

Thanos Baskous

VP of Engineering and Co-founder of Cogent Security

Thanos Baskous
Open session

World Congress 2026 North America

September 23, 2026 · 14:00–14:30

Stage 1

Supply Chain Security When Agents Write the Code

Ajeet Raina

Developer Advocate, Docker

Ajeet Raina