GitHub and Application Security
Github is the largest code hosting collaboration platform for software engineers, programmers, and developers to build code. With version control and a focus on file content, GitHub makes it easy for developers to rename, split, and reorganize project files without restrictions. They can simply keep adding new files to the repository, and revisit a particular version of the project code almost immediately. The main reasons developers LOVE GitHub:
  • Streamlines the development process
  • Allows for easier collaboration
  • Enables external parties to see these changes and contribute to the code
  • Version control - allowing for monitoring of the latest revisions
Read more
Eliminating the Friction Between Development and Security Teams with Tromzo
Developers ignore security issues. But can we really blame them? After all, us security folks bombard them with an endless stream of issues that need to be addressed with no way for them to separate what’s actually critical from all the noise, all while they are expected to release software more frequently and faster than ever before. It makes sense why developers view security as something that just gets in their way and slows them down. I experienced this first hand throughout my security career. Our AppSec team would work with developers to build secure code and find security bugs, then the majority of those issues would simply be ignored. This created major tension between these two teams. The developers were frustrated with alerts that were unactionable while security was frustrated their requests were ignored. On many occasions, the tension got bad enough that the relationship between a few development teams and security completely broke down. This friction between developers and security exists in most modern teams. This lack of collaboration and alignment leaves applications vulnerable to security breaches and it leaves security practitioners feeling underappreciated, undervalued, and questioning their career choice. Earlier this year, Harshit Chitalia, a former engineering lead at Juniper Networks and I began discussing this problem. With my experience leading teams struggling with these challenges and Harshit’s experience from an engineering perspective, we realized we were in the perfect position to solve this problem. Today, we’re excited to officially announce our solution.
Read more

Ready to Scale Your Application Security Program?

Sign up for a personalized one-on-one walkthrough.

Request a demo

[email protected]

Request a demo