Some Nerd · @darrenpmeyer
322 followers · 106 posts · Server infosec.exchange

While I’m looking for the right fit for my next role, I’ve started a consulting practice. If you need an independent voice for infosec—especially for or programs—drop me a line! I’ve been working with software teams in QA, SDET, engineering, and R&D for over 20 years. I’ve been an AppSec practitioner, researcher, and manager for 15. I’ve built and accelerated AppSec programs from startup to Fortune 50.

If you think you or someone you know could use me, please let me know!

#appsec #ProdSec

Last updated 2 years ago

Cross-Platform Cyber Pathogen · @jgoguen
257 followers · 994 posts · Server infosec.exchange

@JessTheUnstill @hacks4pancakes If there’s anyone hiring for jobs that pays reasonably and gives annual cost-of-living increases at least close to inflation, I would be very much interested in learning more about what open positions they have available. Or even someone that just pays well.

I focus on client security, but I can also talk about infrastructure and . 🙂

#infosec #security #ProdSec

Last updated 2 years ago

@SheHacksPurple @wilander @manicode I deliver training through @manicode as well as through my employer but I also see a variety of environments through consulting.

I think that the scope of potential / risks is so large now that it is hard for anyone to get a real handle on it.

Secure coding is one small part of it which I think training helps with a lot but consider the fact that there is no one place where you can find secure coding guidance for a variety of languages other than maybe a @owasp cheatsheets.

However, I think there are a bunch of more organizational level concerns related to how organizations normalize and get buy-in for software security activities and keep these processes going long-term without everyone hating security.

I also think that many of the loudest AppSec voices right now (in mainstream information security spaces) are vendors or breakers who have a specific perspective on things and are mostly talking about tools, automation and testing.

I would argue that the focus on those topics distracts organizations from more fundamental issues of scaling the processes and activities which cannot be automated away such as training, developer engagement, threat modelling and vulnerability triage.

I am not sure we will see significant improvement until these things are addressed at a strategic level within organizations...

#appsec #ProdSec

Last updated 2 years ago

Kas shares their journey into & from a non-technical background at @ComfyConAU

Lots of good lessons
youtube.com/watch?v=cyoIisr8mL

#appsec #ProdSec #comfyconau2022too

Last updated 2 years ago

Vincent Danen · @vdanen
2 followers · 2 posts · Server infosec.exchange

Woke up this morning and jumped on my soapbox. Started the day blogging, spent most of it writing some code to gather data, totally forgot that was waiting (sorry Kratos!). PTO days are great when python is involved. annvix.com/blog/risk-based-vul

#ragnarok #ProdSec #risks

Last updated 2 years ago

Vincent Danen · @vdanen
2 followers · 2 posts · Server infosec.exchange

Do all vulnerabilities REALLY matter? Sometimes we determine the answer based on feelings rather than facts. If it sounds scary maybe it is! But then again, maybe it isn't. I take a look at some facts that inform RedHat's approach. redhat.com/en/blog/do-all-vuln

#ProdSec #infosec

Last updated 2 years ago