Event

OWASP New York Meetup

Date
October 17, 2024
Event Type
In person
Location
North America
Event Overview

We’re thrilled to feature Alex Olea, DevSecOps Engineer at Starburst, at this meetup, who will deliver an insightful session titled “Day 1 DevSecOps: Building a Program and Your Credibility."

Session Overview: Starting a DevSecOps function is an exciting opportunity to not just run a program, but build one. But whether you’re at a large enterprise or a startup, Day 1 is never total greenfield. Even if the organization doesn’t have serious technical and security debt, you’re still going to run into stuff that was spun up and abandoned or tools that aren’t what you might have chosen. So how do you get started?


In this session I’ll share my experiences with building DevSecOps programs at startups, including:

- What is DevSecOps?

- Building trust with developers

- Improving developer productivity and measuring success

- Redefining an AppSec program case study: replacing an SCA tool

Don't miss this opportunity to learn how to build an effective DevSecOps program.

Join us for the OWASP NY Meetup!

Want to stay in the loop?

Sign up for our newsletter.

Claude Fable 5: Mythos-grade hype, record cheating, and a few hall-of-fame entries
Average results with 59.8% on functional solves and just 19.0% on security solves
Read more
Recall, not reasoning: how AI coding agents cheat security benchmarks
Recall, not reasoning: how AI coding agents cheat security benchmarks
Read more
Endor Labs + Cursor: Building the security foundation for agentic coding
Endor Labs + Cursor: Building the security foundation for agentic coding
Read more
Introducing Full Stack Reachability: Container Scanning That Actually Reduces Noise
Cut container vulnerability noise by up to 90% with full-stack reachability analysis spanning application and container image OS layers.
Read more
Classic Vulnerabilities Meet AI Infrastructure: Why MCP Needs AppSec
MCP servers inherit classical vulnerabilities like command injection, path traversal, and SSRF. Here's why LLMs and MCP deserve the same security practices as traditional applications.
Read more
How Fake Font Packages Abused npm as a CDN
101 packages disguised as font files distributed 34 TiB of data via npm's infrastructure—with a total of 4.3 PiB transferred via downloads.
Read more