The Elephant in AppSec

Why DevSecOps isn't enough without deep cloud context with Anjali Singh Shukla

Today I’m joined by Anjali Singh Shukla, Senior Security Engineer Cloud at Flipkart. She bridges the worlds of Cloud Security and DevSecOps, having led audits and defense strategies across AWS, Azure, and GCP, with a strong focus on Kubernetes and container security.

Beyond building secure pipelines, Anjali designs training programs and speaks at global conferences like Black Hat and OWASP.

Most recently at OWASP AppSec Days Singapore, she showed how attackers exploit AWS EKS misconfigurations and how to defend against them.

In this episode, we dive into why DevSecOps alone isn’t enough without a deep understanding of cloud, and the risks that come with moving fast in modern deployments. Anjali also shares her perspective on securing multi-cloud environments and weighs in on the industry’s buzz around CNAPP and CSPM and ASPM convergence.

And with that, get ready to hear Anjali’s opinions.