CSCP S02E32 - Shasha Rosenbaum - Github does it again with CodeQL- find out cyber and dev
Episode description
Sasha Rosenbaum is a Sr. Product Manager at GitHub, former developer, and the organizer of the DevOps Days conference. Francesco and Sasha vent some the frustrations of explaining security threats to developers and engineers who are more focused on creating and coding. Sasha also explains about GitHub’s CodeQL, a semantic code analysis engine. Note FYI sasha now has migrated to redhat.
The episode is brought you by Security Phoenix Ltd with the AppSec Phoenix platform you can make Application Security and Software development finally easy. Follow the tag #appseceasy
0:38 Introducing Sasha Rosenbaum
3:10 Communicate security issues
10:32 GitHub CodeQL
15:15 Security starts with developers and engineers
19:40 Test-able code is better
26:55 Demystifying, not fear mongering
31:02 Biggest frustrations in security
36:22 Final Positive Message
37:44 Outro
Sasha Rosenbaum Twitter @DivineOps Organizer @DevOpsDaysChi Linkedin: https://www.linkedin.com/in/sasha-rosenbaum/ https://www.sasharosenbaum.com
Cyber Security and Cloud Podcast
#CSCP #cybermentoringmonday http://cybercloudpodcast.com