You are viewing content from a past/completed QCon

Presentation: Can We Shift-Left Security in a CD Pipeline?

Track: Solutions Track I

Location: Mountbatten, 6th flr.

Duration: 4:10pm - 5:00pm

Day of week: Monday

Share this on:

Abstract

Implementing DevOps and Continuous Delivery should speed up your software delivery. But in practice the results can be disappointing because teams still spend a lot of time on manual work that is often related to risk & security. Especially in a highly regulated world, like the Financial sector, rules and regulations can be perceived as a huge burden. 

 

In this talk I will discuss how this can be turned around by doing shift-left on security. Risk&Security: From burden to benefit.

Speaker: Taco Bakker

Team Manager @ING_news (ING Bank)

Taco Bakker studied Computer Science at the University of Amsterdam. After his graduation he started as an IT engineer, but quickly became a Project Manager for large IT projects. He discovered first-hand the challenges of the traditional IT approaches such as Prince2. 

He joined ING to become a team manager for both development and operations departments. In this role he spent a lot of time closing the gap between OPS and DEV. About 8 years ago he became a LEAN six sigma black belt and started to improve the traditional IT way of working. He quickly adopted Agile Scrum, helped to implement DevOps within ING and co-founded the ING IT Academy. Today he and his team are implementing the standard continuous delivery pipeline for ING worldwide.

Find Taco Bakker at

Tracks

  • Architectures You've Always Wondered About

    Hard-earned lessons from the names you know on scalability, reliability, security, and performance.

  • Machine Learning: The Latest Innovations

    AI and machine learning is more approachable than ever. Discover how ML, deep learning, and other modern approaches are being used in practice.

  • Kubernetes and Cloud Architectures

    Practical approaches and lessons learned for deploying systems into Kubernetes, cloud, and FaaS platforms.

  • Evolving Java

    JVM futures, JIT directions and improvements to the runtimes stack is the theme of this year’s JVM track.

  • Next Generation Microservices: Building Distributed Systems the Right Way

    Microservice-based applications are everywhere, but well-built distributed systems are not so common. Early adopters of microservices share their insights on how to design systems the right way.

  • Chaos and Resilience: Architecting for Success

    Making systems resilient involves people and tech. Learn about strategies being used, from cognitive systems engineering to chaos engineering.

  • The Future of the API: REST, gRPC, GraphQL and More

    The humble web-based API is evolving. This track provides the what, how, and why of future APIs.

  • Streaming Data Architectures

    Today's systems move huge volumes of data. Hear how the innovators in this space are designing systems and leveraging modern data stream processing platforms.

  • Modern Compilation Targets

    Learn about the innovation happening in the compilation target space. WebAssembly is only the tip of the iceberg.

  • Leaving the Ivory Tower: Modern CS Research in the Real World

    Thoughts pushing software forward, including consensus, CRDT's, formal methods & probabilistic programming.

  • Bare Knuckle Performance

    Crushing latency and getting the most out of your hardware.

  • Leading Distributed Teams

    Remote and distributed working are increasing in popularity, but many organisations underestimate the leadership challenges. Learn from those who are doing this effectively.

  • Full Cycle Developers: Lead the People, Manage the Process & Systems

    "Full cycle developers" is not just another catch phrase; it's about engineers taking ownership and delivering value, and doing so with the support of their entire organisation. Learn more from the pioneers.

  • JavaScript: Pushing the Client Beyond the Browser

    JavaScript is not just the language of the web. Join this track to learn how the innovators are pushing the boundaries of this classic language and ecosystem.

  • When Things Go Wrong: GDPR, Ethics, & Politics

    Privacy, confidentiality, safety and security: learning from the frontlines, from both good and bad experiences

  • Growing Unicorns in the EU: Building, Leading and Scaling Financial Tech Start Ups

    Learn how EU FinTech innovators have designed, built, and led both their technologies and organisations.

  • Building High Performing Teams

    To have a high-performing team, everybody on it has to feel and act like an owner. Learn about cultivating culture, creating psychological safety, sharing the vision effectively, and more

  • Scaling Security, from Device to Cloud

    Implementing effective security is vitally important, regardless of where you are deploying software applications.