Speaker
Abstract
Software security is an essential aspect of any digital product, yet it is often neglected until the late stages of the development lifecycle. This approach leaves organizations vulnerable to cyberattacks, which can result in costly data breaches, reputational damage, and legal liabilities.
In this panel, we will discuss the importance of building security earlier into the software development process and breaking down the silos between security and development teams. By doing so, organizations can integrate security practices seamlessly into their software development lifecycle and make it easier for developers to write secure code.
We will examine various techniques and tools that can be used to build security earlier into the software development process, such as secure coding guidelines, and automated security testing. We will also explore how to establish a culture of security within development teams and encourage collaboration between security and development professionals.
By attending this talk, you will learn how to:
- Incorporate security practices into the software development process from the outset
- Identify and mitigate potential security risks before they become major issues
- Foster collaboration between security and development teams to build a culture of security
- Make security an integral part of your organization's software development process
Join us to learn how to build secure software from the beginning, and protect your organization from costly security breaches.
QCon London 2023 is a three day conference for senior software engineers, architects and team leads. An international program committee of working engineers selects every session. Patterns and practices, not products and pitches.
Part of the track
Building Security in Earlier Hosted by Stefania Chaplin Founder & CEO @DevStefOps, Previously Solutions Architect @GitLab, AWS Certified Security - SpecialityFrom the same track
Monday 27 March
10:35 Windsor (5th Fl.) Session security Security Checks Simplified: How to Implement Best Practices with Ease Varun Sharma CEO and Co-Founder @Step_Security Many organizations are confronted with multiple issues flagged by security tools; are you struggling with security remediation? If so, this talk is for you. 11:50 Mountbatten (6th Fl.) Session cloud How to Build a Successful Cloud Capability on a Heavy Regulated Organization Ana Sirvent Principal DevOps Engineer @KPMG UK On KPMG, working in a highly regulated industry ourselves, we know and feel the pain of enabling innovation and teams to do what they do best. 13:40 Windsor (5th Fl.) Session security Sustainable Security Requirements with the ASVS Josh Grossman Application Security Consultant & CTO @BounceSecurity Shift left? Spread left? Regardless of terminology, we want to be thinking about security earlier on in the development lifecycle. Ideally whilst we are still gathering the business requirements. 14:55 Rutherford (4th Fl.) Unconference Unconference: Building Security in Earlier Shane Hastie Global Delivery Lead @SoftEd, Lead Editor for Culture & Methods @InfoQ What is an unconference? An unconference is a participant-driven meeting. Attendees come together, bringing their challenges and relying on the experience and know-how of their peers for solutions. 16:10 Westminster (4th Fl.) Panel Panel: Building Security in Earlier Ana Sirvent, Josh Grossman, Varun Sharma, Henry Tze Software security is an essential aspect of any digital product, yet it is often neglected until the late stages of the development lifecycle. This approach leaves organizations vulnerable to cyberattacks, which can result in costly data breaches, reputational damage, and legal liabilities. 17:25 Whittle (3rd Fl.) Session automation Getting Developers into F1 Driver Seats with Security? Henry Tze Lead Cloud Security Engineer @Virgin Media O2 At Virgin Media O2, we are in a race of digital transformation which requires many different types of skillsets and people. This resulted in waves of hiring new blood, contractors and skilling up existing engineers/developers.