Bridging the Gap Between DevOps and Security – DevSecOps: Cracking the Code EP1
DevOps was always meant to include security, but in reality, the cultures didn’t align—leaving many organizations without a mature DevSecOps strategy. So how do you complete the DevSecOps journey? Join Techstrong and Checkmarx for DevSecOps: Cracking the Code, a new series packed with expert insights and actionable advice to help you successfully evolve from DevOps to DevSecOps. Hosted by Alan Shimel and Jonathan Singer, you won’t want to miss it!
Transcript
Hey everyone. I'm Alan Shimel, and this is Jonathan Singer, and you are watching The DevSecOps Show Cracking the Code. You've never heard of that show.
Well, for good reason. This is the very first episode of it. We're just starting it.
And thanks for joining in. Um, we're going to take today's show to just kinda give you a what to expect and what's coming here and introduce a whole concept to you. Uh, DevSecOps Show Cracking the code is a joint production between us here at Techstrong Group, tech Strong tv, as well as check marks, our partners check marks.
We partnered with check marks for many, many years. They've been a leader in the AppSec space. DevSecOps coming now into platform engineering as well.
So I'm thrilled to have check marks co-producing this with us. And my co-host I mentioned, his name is Jonathan c Jonathan's with check marks. Hey, Jonathan, nice to have you co-host you with us.
Welcome. Um, thank you. You know, you are the new guy on the block.
Tell people a little bit about you. Sure. So, uh, it's nice to virtually get my face out in front of everyone, and thanks again for the warm welcome.
I am very much looking forward to doing this series with you. Uh, my background, I've been with check marks for a couple years now, and, uh, I've spent a lot of the last 20 plus years, sadly, but yeah, it's been, it's been a long time. You don't look adult.
Uh, well, uh, you know, I'll, I'll take it, I'll take it, but yeah, no Good living. Uh, yeah, what can I say? Good skincare.
It's, it's great. Mm-hmm. Uh, but I've been in cybersecurity and, and some adjacents work in telecom for the last 20 plus years.
Uh, and I, uh, I'm current in my current role at Check marks. I'm doing a lot to help the organization shift our focus into the realm of developers. And we've done a lot of work, uh, as a company over the last four years, like really making our platform developer friendly, good for developer teams, good for huge like development organizations.
And so we wanna take an opportunity to sort of get the word out, uh, as a company. Um, and I am, I'm sort of leading that effort, so that's why I'm here. We've got a lot of fun topics to talk about.
I've been talking a lot recently about DevSecOps maturity and, uh, about what that really looks like and, and how you advance as an organization. So, lots, lots to dig into. Absolutely.
I want to dig into some of those topics, kinda pre-announce them here today. I'd like to go into a little bit more about check marks in their history, though. You know, like you, I've been in security, well, probably longer than you, to tell you the truth.
I've been in security now about 30 years, and, um, you, I've seen a lot of water under that bridge, right? I've seen us move from a predominantly network security type of world where we put big boxes, you know, at the, at the drawbridge with the moats surrounding the castle to the advent of the cloud, to the advent of DevOps, ai now platform engineering, SRE, so many, you know, subsequent waves. And each wave has brought new innovation, new techniques, new best practices.
So over that time, I would say one of the biggest Innova, not innovations, but shifts in security, was the shift to AppSec, right? Even before DevSecOps, the shift to AppSec, the idea of we are going to secure the applications, whether they're in the cloud or in a data center, or on your phone. We need to make sure our application code is secure.
It's free of buffer overflows and cross site scripting and SQL errors, and, you know, all of those kind, kind of common things. You know, obviously, uh, OAS top 20 kind of, you know, uh, of, of, uh, vulnerabilities. And that's when I first became aware of check marks, right?
Check marks was a pioneer in AppSec, right? And we, you know, the idea of, of static code analysis, dynamic code analysis. Then of course, later on came, um, uh, open source scanning, and I always forget what we call it now.
Secure code analysis, SCA, right? Basically scanning our open source code. Uh, all of these things really, I think they made a huge difference in the quality of the code that gets released.
And, you know, that's in our applications. At the same time, things like DevOps and agile man change the way we develop software. The biggest change is what, you know, I call the shift to a software factory, right?
Where it, it's not, I used to think of software as like, you know, like mid 18 or mid 18 hundreds Germans, craftsmen, fine craftsmen making furniture or iron metal workers or, you know, the guild where you had apprentices and, and lifelong, you know, that real craftsman kind of role. But I think we saw a shift to the factory, right? Much like we did in automobile production, right?
From bespoke automobiles to assembly line. And we saw the same shift in software. Uh, we also saw the advent of repos and open source software where people, I, I, you know, it's like Frankenstein software.
People stitch together a whole bunch of different components right? From different places. And that's 85% of the code in today's applications.
Um, these are all big changes. And then of course, the biggest one for us here on this show is the whole start of dev SecOps, right? All of a sudden it became cool to say, Hey, did you know, hey, developer, we know you want to develop quality code, even though we're not those old, you know, mid 1800 craftsmen anymore.
We still have pride in our work. We still have pride in the code. We're publishing.
We want no one raises their hand and says, Hey, I feel like putting out some crappy coat today. No, everybody likes good code. And, and so that was a revelation for security people, Jonathan, right?
We, we, we spent 20 years, we always said, nah, no one cares about security but us, we're the only people. But no, they care about security. Let's give them the tools to do it.
And, and again, check Marks led the way there, I think, right? With, uh, well, the most recent is the advent of check marks one, that whole platform. So that was a long-winded intro for you to discuss check marks one and what that is.
Well, uh, there were a lot of things in there that I'd love to address, but since you asked me ahead directly about what check marks one is, I mean, uh, you know, I I think check marks one is our response to everything that you said. And yeah, like, I mean, we can go back to the Toyota production system and, uh, and, and, and, you know, K Bond and, and how that's, you know, grown up and influenced agile development and, and the kind of march from DevOps to somewhat argue back to DevSecOps. Um, and, and I'll say that I was, I was talking to someone recently and he said, you know, I spent years as a DevOps leader, and I always thought DevSecOps was just a marketing term by security vendors, because we always knew that DevOps had to, it was, it was supposed to be everything, and security was a part of it.
Yeah. So, you know, as, as a guy who's out there now talking about DevSecOps, I think I'll, I'll at least, uh, say, yeah, like we're, we're, we know. But, uh, check marks one is still the response to this, right?
It's the response to that need that, uh, maybe security folks felt like, uh, well that's nice that you included it, but we're not talking about it enough. Um, and you know, your reference to, you know, coders as, and developers as originally kind of craftspeople, I, I think they still are. And I think that what all the open source stuff and the kind of Franken code that people put together is because we're trying to refactor people's time on doing the craftsman stuff, where it's really, really important.
Uh, and we want security to still be a part of that, right? So we want security to be a part of your software supply chain. So everything that you pull down from the internet, we wanna make sure that, you know, that code is secured when you build new code and you get time to do that.
Craftsman, like work, we wanna be there. Uh, you know, doing the analysis of that code before it gets into production and, and check marks. One is the response to those needs of taking all of these different types of analysis, right?
Fast, SCA das, API security, uh, container security, and, and building those engines, not separately, but so that they work together and that they can fit into your production pipelines, right? Because if you're gonna do this effectively at scale, which is, which is really what large businesses need, they're trying to get all these developers, all these craftsmen who, you know, work on these little individual things to really, to make a big outsized impact. Um, we wanna fit into all of those production lines, integrate with everything that you need, and make sure that we're securing as much early as possible so that when things get to production, there are, you know, there are as few critical vulnerabilities as, as there need to be.
So that's check marks one, is the response to that need for that to happen in the cloud for that, to make it easy for everyone. Love it. So you open this can of worms.
Let's go back to the birth of Jeff SecOps. com in, uh, when we first published it in March of 2014. We started in 2013, you know, planning and getting everything done like September, October, 2013.
And, um, let's be clear back then. So I came from the security world. I thought, what a tremendous opportunity DevOps represents for security.
There wasn't a thing called DevSecOps. There was, there were proto like proto humans, you know, not Neanderthal, but Africans, Andal, but Africa and some of the proto humans. There were things like rugged DevOps.
My friend James Wickett, who is now a runtime or drive run securities, this new company, uh, he started something called the Rugged DevOps Movement, right? And there was, you know, ruggedized DevOps, making it resilient. org.
Maybe we'll have Shannon on a show going forward. I, good friend of mine, um, and she actually wrote the Manifesto for DevSecOps, right? 10 years ago, this May was the very first DevOps DevSecOps Connect that I did at the RSA conference in partnership with my friends at RSA.
Um, and the idea then was when we first did this 10 years ago, again, DevSecOps, it was funny, the security people thought it was full of crap. John Jonathan, right? 'cause they said, oh, nonsense, no one cares about security.
And the, and the developers thought it was full of crap too, which is a marketing term, the true DevOps people like my friend John Willis and, and Patrick dubois, who coined the term DevOps and, you know, uh, uh, Andrew Clay Schafer, and, you know, the Damon Edwards, the, the, the founders of DevOps. They felt, of course, security was part of DevOps. DevOps encompassed all of that.
But what kind of needy, whiny individuals or security people that they feel it necessary to stick check right in the middle of the dev and the ops, and they resisted it, right? And when we first started doing these events at RSAI, that was my mission, to bring the security community to the, and the DevOps tribe together. It's kind of mixing peanut butter and chocolate.
And there was a lot of resistance. Go ahead. I, yeah, and I mean, let's, let's be honest.
'cause we're, we're gonna talk, we're gonna have a whole conversation on culture later, but like, yep. From my perspective, that what you just said, oh, well, everyone thought it was, everyone thought it was bs. Like both sides kind of.
That's, that's kind of part of the problem, right? And that's why we needed to have it in there in the first place is because you can say DevOps always included security, okay? But DevOps started in 2009.
It is 2025, and there is still a massive culture clash between security organizations and development organizations. I was talking to my friend who, uh, you know, she was recently a senior staff engineer at an Amazon based company. And, and, and now she's often a, um, uh, in a, in a startup again, uh, you know, but, but they were saying like, you know, the security people want it so secure that like, well, we're just gonna unplug everything, right?
Right. And developers like, well, I still need to do my work. And that requires things to be turned off, right?
And, and if we're still there where we have this, this big culture clash, which is fine. And again, and I say this all the time, like, developers move fast and break things. Security people don't ever let anything break.
And if we can't start coming together as, as distinct disciplines and working towards the goals of the business, not just our own individual metrics of like, I've tracked this many vulnerabilities so that I can buy more of this software and secure this, right? And developers saying, well, I'm not meeting my development milestones, so I'm gonna skip this step and I'm gonna meet my development milestones. If, if we can't work together and have the business a align us on goals of what producing secure software at a rapid pace looks like, then we still need to be talking about DevSecOps and talking about DevSecOps maturity and where you are.
'cause like that the, the cultures have to find a way to come together. We can't just have security being the department of no. And we can't have developers being like, oh, they're all 20-year-old yahoos.
And it's like, they're not like, these people have been doing this 30 years. Like, come on. So absolutely.
So let me, let me give, let me spread the good news today. Like it's Sunday and I'm selling Watchtower or something. Um, the good news is we've made a t tremendous amount of progress Agreed over The 10 years I'm doing this thing in RSA, which we're doing again this year at RSA in May.
Check Marks is a sponsor of it. They'll be there, I think they're on one of the panels even, uh, uh, uh, Toby, the chief product officer at Check Marks is, is on one of the panels, um, co. But anyway, people recognize that DevSecOps is a real thing that you need.
The second DevSecOps even more than that, when you look at the leading DevOps platforms in the world today, companies like GitLab and Jfr and Harness and CloudBees to name a few, they don't even call themselves DevOps platforms. They call themselves DevSecOps platforms because they recognize how important security is. So we have made progress, I have a more nuanced view of it today than maybe you, Jonathan, or what you've said so far in that I think what we're seeing is under the maturation of DevSecOps, we've learned some lessons.
Developers are not against developing quality code, but they're never gonna be security professionals. A hundred percent agree. Yep.
And I think one of the mistakes that our DevSecOps industry has made is giving security tools to developers. We need to give developer tools to developers that help them do better security, right? Because they're never gonna truly understand the, the nuances of the CVSS rating system or something like, you know what I mean?
One of these kinds of things. And that, so again, we talk about Check Mark Swan, bringing it back to that. That's one of the beautiful things about that is, right, creating a, a platform that developers can use and feel comfortable in without having to be a security pro, but also having an aspect of it that the Security pro can use to get their job done as well.
And again, these are things we're gonna explore. I wanna explore shift left. Have we over shifted?
I want to explore how platform engineering has kind of come in on top here and said, Hey, let us work with security to set up the guardrails so that those developers can just go faster. We, we do do the platform engineering show, right? With which you, you've been a guest on there and Check Mark's sponsor.
We'll be discussing more of that on there. But we, you know, we'd be wrong if we didn't include it in, in here too. Um, and I think, here's the other thing.
This whole, uh, software pipeline security, right? Software and supply chain security, that's part of DevSecOps too, right? It's a huge part.
The SBOs, everything else. And here's another thing I'm seeing, John, and I'm wondering if you see this too. We're starting to see people say, Hey, we gotta extend, extend DevSecOps SecOps past the deployment horizon, right up till now.
DevSecOps, it, it was like it hit a black hole when we deployed, right? No light escaped to the other side. Well, no, there's life after deployment, right?
For AppSec, and there's security after deployment, and that has to be tied into your DevSecOps too. So I, another thing that I'd like to see us discuss, what else would you like, think we're gonna cover, Sean? Well, um, let's see.
We're gonna talk about culture. We're gonna talk a lot about security education, because, you know, while you said that, so look, everything you said about making security tools into developer tools, I completely agree with you. I think I even said it at Techstrong Predict, uh, that, you know, that's, that's the goal.
Um, but I wanna talk about security education. I wanna talk about how it's working, uh, because it is, we just did a survey of 1500 developers Yeah, sure. Working or not, but at least the developers who are out there seem to feel like it's working and maybe security needs to change the way that it speaks to the market.
And stop complaining that they don't teach security and secure coding in as part of, you know, a university degree and say, okay, well we're, we're, we're doing it. So let's start speaking differently to developers about security. Right?
I agree a hundred Percent again, that, that ties back to culture. So like, I think that the overarching conversation that we're gonna have across every single one of these meetings is the culture. And it's gonna be like the culture around integrating properly, around metrics, around security education, around matching the velocity of security to the velocity of development.
Um, you know, about security champions programs, all of these things that we're gonna wanna talk about throughout the course of this show. Uh, I, I think it's, it's all gonna tie back into culture and how we learn to continue working together and, and agreed, you know, security goes beyond deployment. That's why check Marks one partners with, uh, with folks like Wiz and, and, and with Cystic right Runtime partners.
So agree. Like we need to be looking at the whole software life lifecycle as developers look at the software lifecycle. Agreed.
Agreed. Hey, you know, what else though, for people watching this, are you a dev set ops person? Are you a DevOps person?
Are you a developer? Are you a security? Would you like to be involved?
Perhaps be a guest? You have a point of view. It's not just going to be you and I talking every week, Jonathan.
We're gonna have hopefully a panel every week of at least 3, 4, 5 people. Not every week, every other week. I think we do this.
Um, but every show, and we're looking for people. So if you have some thoughts and opinions, everybody has an opinion, uh, uh, DevSecOps and DevOps write to us. com or reach out on LinkedIn or wherever you can reach me.
I'm pretty accessible. So you could reach out to us there and we'll, we'll entertain any and everyone who'd like to come on here and, you know, have a thought on, on what we're gonna say. You know, what else John?
I'm really proud of us. We're on now. Oh, a good 15 0, 25 minutes.
We haven't mentioned ai. What about ai DevSecOps? Well, we'll talk about ai.
And you met, you mentioned, uh, Patrick Debar earlier, but he and I had a, had a long conversation about AI that you can find somewhere online, probably on our website, uh, as well. Um, but yeah, you know, ai, uh, we're gonna talk about AI in a bunch of different ways, right? 'cause there are, there are lots of different ways of looking at, which is like, how does it help developers code faster?
How does it help them do security faster? How does it help se security engineers to, you know, tune their products faster? Um, and then what does it mean for the software supply chain?
You, earlier you were talking about, uh, code and, um, and, and downloading other people's code and how that needs to be scanned. Well, but now there's HuggingFace and there are all these LLM models and you know, we've got a guy on at our company, ez, who's one of our lead researchers, and he's done a demo of like, here's how you poison an AI model and here's what it looks like, right? Gimme a recipe for, you know, pasta Alfredo and one of the ingredients that gives you a rat poison, right?
When he, when he does that right, poison this model. So there's, you know, if, if, if companies are building their own LLM or they're looking to build off of an open source, LLM, what's the security of that? Who's gonna scan that?
Who's gonna know whether or not your model is poisoned? So like, there's, and, and I don't mean to ramp up the fear factor 'cause that's obviously what security folks typically are, are known for doing, or at least accused of doing. But it's, it's a concern.
AI is now a supply chain concern in addition to all of the ways that it can be helpful. So we'll totally talk. I like everything else.
It's the duality, right? Light and darkness. Uh, it's always there, man.
Every technology, you, you get it, it's new. It does something cool, and there are risks, and that's just life. I always say this is why we can't have nice things on the internet.
Um, but we do have nice things on the internet in spite of all. And, and, and you know, again, I I I want to take a positive view of this as a result of DevSecOps, our code today is much more secure, like the AppSec you're using today. And even though you may be updating them daily, weekly, monthly, whatever, they're much more secure today than they were before DevSecOps.
I, I think we have made, made tremendous strides in, in releasing much more secure code. Yeah, So, Agreed. That agreed?
Mm-hmm. Alright. Hey, that's gonna wrap up our very first version here of the DevSecOps Show.
Cracking the code. We're gonna be back in two weeks with a full on panel. Jonathan, let's tackle culture right outta the bat and talk about the DevSecOps culture on that show.
Um, you can catch this show on Tech Drunk TV and the Tech Drunk TV network. So it'll play on Tech drunk tv. It'll be streamed to LinkedIn and Facebook and x and YouTube to our Techstrong TV, YouTube channel.
It'll be available on the Techstrong TV website. com, security Boulevard, cloud native now, tech Strong, AI tech, strong it, and digital CXL. Um, additionally, audio versions of this will be available on Apple Podcast, uh, uh, Spotify podcast, Stitcher, and all of your favorite podcast platforms.
So if you prefer listening to audio while you're running, exercising, whatever, driving, you'll be there for you too. Um, Jonathan, I'm, I'm pumped. I can't wait to get cooking with this.
Yeah, I'm, I'm excited too. I think it's gonna be a great series and I appreciate you and the organization for hosting it. Looking forward to It.
Absolutely. Absolutely. All right, until next time, then that's a wrap on episode one of the DevSecOps episode, DevSecOps Show.
Little tongue twisted there. DevSecOps Show cracking the code. We're out everyone.
Thanks very much. Thank you.
