DevSecOps Podcast

Cássio Batista Pereira

The DevSecOps Podcast explores the intersection of software development, cybersecurity, and modern engineering, with a strong focus on Application Security and DevSecOps.Each episode brings practical conversations with security professionals, engineers, researchers, community leaders, and industry experts about the challenges of building and operating secure software at scale.We go beyond tools and vulnerability scanning to discuss secure development, security culture, threat modeling, AppSec programs, AI, automation, cloud security, security testing, maturity models, and the realities of integrating security throughout the entire software development lifecycle.Expect technical insights, real-world experiences, lessons learned, strong opinions, and honest discussions about what actually works, what does not, and where software security is heading next.If you build software, secure applications, lead engineering or security teams, or simply want to understand how modern organizations can deliver software faster without losing control of security, the DevSecOps Podcast is for you. Become a supporter of this podcast: https://www.spreaker.com/podcast/devsecops-podcast--4179006/support.

  1. 13h ago

    #08 - 11 - How Security Champions Can Transform Your Development Team's Approach to Safety

    In a digital landscape where security breaches make headlines daily, the ability to engage developers and decision-makers on security matters is more critical than ever. In this episode, Lisi Hocke unveils the secret to transforming security champions from mere titles into influential advocates who drive meaningful change across teams. Lisi, a seasoned expert with over 17 years in tech, shares her insights from the frontlines of application security. You’ll discover how to capture the attention of developers and management alike, ensuring that security conversations resonate and lead to proactive measures. Learn the art of speaking their language, building trust, and contextualizing risks to make security relevant and compelling. We break down essential strategies for establishing effective security champion programs, tackling common pitfalls that lead to failure, and exploring innovative approaches that make security an integral part of the development process. You’ll also hear about the critical importance of automation and systems that inherently promote secure practices without overwhelming teams. The stakes couldn’t be higher: neglecting to engage effectively can lead to devastating breaches and costly repercussions. This episode offers a roadmap to not only prevent harm but also foster a culture where security is everyone's responsibility. Perfect for security professionals, developers, and anyone involved in product development, this episode is your guide to creating a more secure future. Tune in to learn how to elevate your security practices and empower your teams today! Become a supporter of this podcast: https://www.spreaker.com/podcast/devsecops-podcast--4179006/support. Support: Nova8, Checkmarx, Snyk, Conviso, Gold Security, CyberSec Games and PurpleBird Security.

    #08 - 11 - How Security Champions Can Transform Your Development Team's Approach to Safety
  2. Aug 12

    #08 - 10 - How to teach kids complext topics

    In a world where AI is rapidly becoming the cornerstone of technology, understanding its intricacies is more crucial than ever. Join Rob van der Veer, a veteran in the AI field with over three decades of experience, as he unveils essential insights from his journey, including the pivotal lessons that every child—and adult—needs to grasp about artificial intelligence. Rob, the Chief AI Officer at the Software Improvement Group, shares how he transitioned from building AI systems to consulting on security measures critical for protecting our data. You’ll discover the alarming truth about AI’s limitations, the importance of human oversight, and why the next generation must be educated on these concepts. In this engaging conversation, we delve into: - The genesis of Rob's children's book, *Luna and the Magic AI Paintbrush*, designed to teach kids about AI responsibly - Key strategies for parents and educators on introducing AI concepts to children effectively - Insights into the balance between security and innovation in software development - The critical role of discipline in using AI safely and responsibly Why does this matter? As AI technology advances, so do its threats. Without proper understanding, we risk creating a generation that is overly reliant on AI, unaware of its pitfalls. Rob’s mission is to ensure that both children and professionals alike are equipped with the fundamental knowledge to navigate this complex landscape. Don't miss this vital episode that bridges the gap between technology and education, making it essential listening for parents, educators, and anyone invested in the future of AI. Tune in now to empower yourself and the next generation with the knowledge that could shape a safer, smarter world. Become a supporter of this podcast: https://www.spreaker.com/podcast/devsecops-podcast--4179006/support. Support: Nova8, Checkmarx, Snyk, Conviso, Gold Security, CyberSec Games and PurpleBird Security.

    #08 - 10 - How to teach kids complext topics
  3. Aug 5

    #08 - 09 - CyberSec Games: CyberSec conversations on the table

    In a world dominated by screens, how do we reignite the joy of face-to-face interaction? In this episode, Cássio Pereira and Marcos Santos sit down with Devika Gibbs, co-founder of Cybersec Games, to explore the transformative power of physical games in cybersecurity training. Devika reveals how her passion for board games is reshaping the way teams learn and collaborate, proving that true connection happens in person, not behind a screen. Devika shares the origin story of Cybersec Games, sparked by a simple index card idea, and explains why physical interaction is essential for building trust within teams. You'll discover: The unique benefits of playing games in a physical setting versus digital platforms.How to overcome generational shifts towards screen reliance in team training.The surprising outcomes of using games to enhance empathy and communication in professional environments.Real-life applications and success stories from organizations that have embraced this innovative approach.The stakes are high: without understanding the value of physical interaction, organizations risk losing the essence of teamwork and collaboration. Devika emphasizes that investing in physical games not only fosters deeper connections but also leads to better training outcomes compared to traditional digital methods.This episode is essential listening for cybersecurity professionals, educators, and anyone interested in enhancing team dynamics through the power of play. Dive into the world of Cybersec Games and discover how bringing people together can transform the way we learn and grow in the digital age. Don't miss out on this enlightening conversation that promises to change your perspective on training and teamwork! Become a supporter of this podcast: https://www.spreaker.com/podcast/devsecops-podcast--4179006/support. Support: Nova8, Checkmarx, Snyk, Conviso, Gold Security, CyberSec Games and PurpleBird Security.

    #08 - 09 - CyberSec Games: CyberSec conversations on the table
  4. Jul 29

    #08 - 08 - DSOMM - DevSecOps Maturity Model

    How mature is your DevSecOps program, and how do you know what to improve next? In this episode, we talk with Timo Pagel, creator of DSOOM, the DevSecOps Maturity Model, about why organizations need structured guidance to build security into software development without turning maturity into a bureaucratic checkbox exercise. We explore why many companies delay maturity assessments until their development environment becomes difficult to control, how security evaluations should reflect each organization’s actual context, and why copying a generic framework rarely produces meaningful improvement. Timo also shares how DevSecOps maturity models must evolve as AI becomes part of everyday software development. As teams increasingly rely on AI-assisted coding, maturity models need to address new risks, practices, and responsibilities associated with AI-generated code. The conversation also covers a topic that maturity models often ignore: failure. Progress does not come from pretending every initiative worked perfectly. It comes from learning what failed, adapting the approach, and using those lessons to build stronger and more resilient engineering practices. A practical conversation about DevSecOps maturity, realistic assessments, AI-assisted development, organizational growth, and the value of learning from mistakes. Become a supporter of this podcast: https://www.spreaker.com/podcast/devsecops-podcast--4179006/support. Support: Nova8, Checkmarx, Snyk, Conviso, Gold Security, CyberSec Games and PurpleBird Security.

    #08 - 08 - DSOMM - DevSecOps Maturity Model

About

The DevSecOps Podcast explores the intersection of software development, cybersecurity, and modern engineering, with a strong focus on Application Security and DevSecOps.Each episode brings practical conversations with security professionals, engineers, researchers, community leaders, and industry experts about the challenges of building and operating secure software at scale.We go beyond tools and vulnerability scanning to discuss secure development, security culture, threat modeling, AppSec programs, AI, automation, cloud security, security testing, maturity models, and the realities of integrating security throughout the entire software development lifecycle.Expect technical insights, real-world experiences, lessons learned, strong opinions, and honest discussions about what actually works, what does not, and where software security is heading next.If you build software, secure applications, lead engineering or security teams, or simply want to understand how modern organizations can deliver software faster without losing control of security, the DevSecOps Podcast is for you. Become a supporter of this podcast: https://www.spreaker.com/podcast/devsecops-podcast--4179006/support.