Artwork

محتوای ارائه شده توسط Tromzo. تمام محتوای پادکست شامل قسمت‌ها، گرافیک‌ها و توضیحات پادکست مستقیماً توسط Tromzo یا شریک پلتفرم پادکست آن‌ها آپلود و ارائه می‌شوند. اگر فکر می‌کنید شخصی بدون اجازه شما از اثر دارای حق نسخه‌برداری شما استفاده می‌کند، می‌توانید روندی که در اینجا شرح داده شده است را دنبال کنید.https://fa.player.fm/legal
Player FM - برنامه پادکست
با برنامه Player FM !

EP 43 — Avalara’s Derek Samford on Building a Security Culture with Data, Collaboration, Education, and Empathy

35:56
 
اشتراک گذاری
 

Manage episode 374456705 series 3330694
محتوای ارائه شده توسط Tromzo. تمام محتوای پادکست شامل قسمت‌ها، گرافیک‌ها و توضیحات پادکست مستقیماً توسط Tromzo یا شریک پلتفرم پادکست آن‌ها آپلود و ارائه می‌شوند. اگر فکر می‌کنید شخصی بدون اجازه شما از اثر دارای حق نسخه‌برداری شما استفاده می‌کند، می‌توانید روندی که در اینجا شرح داده شده است را دنبال کنید.https://fa.player.fm/legal

In this episode of the Future of Application Security, Harshil speaks with Derek Samford, Senior Director of Product Security at Avalara, a company that builds cloud-based tax compliance solutions. They discuss Derek's approach to product security, including how his team uses data to drive visibility, how feedback loops can build maturity, and how they create application grade cards that inform remediation efforts. They also discuss how everyone is invited to contribute to product security solutions, how they create custom training for each new process, and the importance of empathy.

Topics discussed:

  • How Derek's varied background brought him from network engineering to scalability and performance testing, to field support, to building a security validation team, to today building applications at Avalara from the ground up.
  • Why empathy is the most important skill you can have in security, and why it allows you to help others do their best work.
  • How Derek's team practically approaches security, from running the same tools developers do, to having a strong security champions program, to encouraging open feedback.
  • How Alavara builds collaboration by inviting anyone who wants to contribute to security solutions to be part of the working group.
  • How Alavara uses data to help them understand what they're protecting, to gain greater visibility, and to unify their processes.
  • How standardized processes and feedback loops create maturity over time.
  • The importance of education, and why they create training specific for the organization that focus on "our tools, our processes, and our recommendations around security."
  continue reading

60 قسمت

Artwork
iconاشتراک گذاری
 
Manage episode 374456705 series 3330694
محتوای ارائه شده توسط Tromzo. تمام محتوای پادکست شامل قسمت‌ها، گرافیک‌ها و توضیحات پادکست مستقیماً توسط Tromzo یا شریک پلتفرم پادکست آن‌ها آپلود و ارائه می‌شوند. اگر فکر می‌کنید شخصی بدون اجازه شما از اثر دارای حق نسخه‌برداری شما استفاده می‌کند، می‌توانید روندی که در اینجا شرح داده شده است را دنبال کنید.https://fa.player.fm/legal

In this episode of the Future of Application Security, Harshil speaks with Derek Samford, Senior Director of Product Security at Avalara, a company that builds cloud-based tax compliance solutions. They discuss Derek's approach to product security, including how his team uses data to drive visibility, how feedback loops can build maturity, and how they create application grade cards that inform remediation efforts. They also discuss how everyone is invited to contribute to product security solutions, how they create custom training for each new process, and the importance of empathy.

Topics discussed:

  • How Derek's varied background brought him from network engineering to scalability and performance testing, to field support, to building a security validation team, to today building applications at Avalara from the ground up.
  • Why empathy is the most important skill you can have in security, and why it allows you to help others do their best work.
  • How Derek's team practically approaches security, from running the same tools developers do, to having a strong security champions program, to encouraging open feedback.
  • How Alavara builds collaboration by inviting anyone who wants to contribute to security solutions to be part of the working group.
  • How Alavara uses data to help them understand what they're protecting, to gain greater visibility, and to unify their processes.
  • How standardized processes and feedback loops create maturity over time.
  • The importance of education, and why they create training specific for the organization that focus on "our tools, our processes, and our recommendations around security."
  continue reading

60 قسمت

همه قسمت ها

×
 
Loading …

به Player FM خوش آمدید!

Player FM در سراسر وب را برای یافتن پادکست های با کیفیت اسکن می کند تا همین الان لذت ببرید. این بهترین برنامه ی پادکست است که در اندروید، آیفون و وب کار می کند. ثبت نام کنید تا اشتراک های شما در بین دستگاه های مختلف همگام سازی شود.

 

راهنمای مرجع سریع