In recent years DevOps has 'shifted left' to become DevSecOps, as most high-performing organisations have recognised the critical importance of continuously integrating security from the start of the development process.
Teams that fail to adapt are likely to be left behind — outdated security practices will hamper even the most efficient DevOps initiatives and see a return to long development cycles.
With an estimated 75%* of US and UK companies 'shifting left' in 2020, it is clear that continuously integrating and automating security into your practice is no longer an option.
Join us for 5 keynotes exploring some of the most popular techniques, tools and thinking around integrating security throughout the entire software development lifecycle — and ensuring "Sec" is a shared responsibility of everyone.
In this half-day of keynote sessions, we'll explore the latest thinking behind DevSecOps, including:
How to "Shift Left"
Learn to implement a successful DevSecOps culture
Security as Code
Strategies and tools to ensure that security isn't an afterthought.
Keeping Delivery Continuous
How to set up a DevSecOps initiative that doesn't compromise flow
DevSecOps + Architecture
Explore practical ways to work as an architect with a DevSecOps team.
DevSecOps eXchange Forum features keynotes from
-
Dave Farley
Pioneer of Continuous Delivery & DevOps
"Is DevSecOps the Wrong Name?"
Learn More
Erik Dörnenburg
Head of Technology, Thoughtworks
"DevSecOps: A Practitioner's Perspective"
Learn More
Matt Saunders
Head of DevOps, Adaptavist
"DevSecOps and the Fight Against Friction"
Learn More
Bert Jan Schrijver
CTO, OpenValue
"Software Architecture in a DevOps World"
Learn More
Nancy Gariché
Senior Developer Advocate, GitHub Security Lab
"Security as Code: A DevSecOps Approach"
Learn More
The DevSecOps eXchange Forum will be an online conference.
This event begins at 12:00 UTC
CONVENIENT FOR ATTENDEES AROUND THE GLOBE
Ticket holders will also receive exclusive access to recordings of all sessions. These recordings will be available shortly after the event, allowing you to watch the conference at your convenience.
Who should attend?Software Developers and Engineers
Software Architects
Site Reliability Engineer
Quality Analysts and Testers
Team Leads and Engineering Managers/Directors
CIOs and CTOsThis is an exclusive event for Skills Matter Premium Members.
If you'd like attend but aren't yet a Premium Member, it's not too late.
Become a Premium Member
Simply sign up as a Premium Member and you'll gain instant access to the DevSecOps eXchange Forum.Plus, as a Premium Member you'll enjoy a suite of benefits including free online conferences, discounts and our Members‑Only Slack workspace.
Excited? Share it!
Day 1: eXchange Forum
DevSecOps
Track | Main Track | |||
12:00
Invalid Time
Invalid Time
|
Welcome & Opening Remarks |
|||
12:05
Invalid Time
Invalid Time
|
Our systems are under attack on a number of fronts. That may sound alarmist, but it's also true. By some estimates 90% of firms are likely to have suffered an attack of some kind in the last 12 months. Some may not even know it yet. So how should we best deal with the security of our systems in a world of agile development and Continuous Delivery. The answer is to build security into our systems from the outset, rather than treat it as an afterthought. So what are the things that we should worry about, and how should we deal with them? This approach is sometimes called DevSecOps, but a better term might be “Continuous Security”.
devsecops
continuous-delivery
continuous-security
security
About the speaker...Dave FarleyDave Farley is a pioneer of Continuous Delivery, thought-leader and expert practitioner in CD, DevOps, TDD and software development in general. Dave has been a programmer, software engineer, systems architect and leader of successful teams, for many years, from the early days of modern computing, taking those fundamental principles of how computers and software work, and shaping ground-breaking, innovative approaches that have changed how we approach modern software development. Dave has challenged conventional thinking and lead teams to build world class software. Dave is co-author of the Jolt-award winning book "Continuous Delivery", a popular conference speaker and runs a YouTube channel with over 100k subscribers on the topic of Software Engineering. Dave built one of the world’s fastest financial exchanges, is a pioneer of BDD, an author of the Reactive Manifesto, and a winner of the Duke award for open source software with the LMAX Disruptor. Dave is passionate about helping development teams around the world improve the design, quality and reliability of their software, by sharing his expertise through his consultancy, YouTube channel, and training courses. Follow Dave on Twitter @davefarley77 or LinkedIn @dave-farley-a67927. |
|||
13:00
Invalid Time
Invalid Time
|
Closer collaboration between developers and operations people brought businesses many benefits. It is also fair to say, though, that it created new headaches. Some practices, especially continuous deployments, forced us to rethink the traditional security sandwich, with conceptual work up-front and a pen test at the end. It was easy to sneak a “Sec” into DevOps, it was reasonably obvious to call for security to be “shifted left”, but in practice this raised even more questions. Based on his experience working as a consultant Erik will address these questions. He will discuss practices like container security scanning, binary attestation, and chaos engineering, alongside examples of concrete tooling to support these practices. In addition Erik will show how the concept of fitness functions, which have become popular in evolutionary approaches architecture, can be applied in the security domain.
security
devops
container-security-scanning
chaos-engineering
binary-attestation
security-scanning
evolutionary-architecture
fitness-functions
devsecops
About the speaker...Erik DörnenburgErik Dörnenburg is a software engineer and passionate technologist. As Head of Technology at Thoughtworks he helps clients solve their business challenges using modern technologies, platforms, and practices. On his 25 year journey through the tech industry Erik encountered an abundance of new technologies, always seeking to understand their potential while at the same time bringing along proven engineering practices. Throughout his career Erik has been an advocate of agile values and open source software. He is a regular speaker at international conferences, contributed to a few books, and maintains several open source projects. Erik holds a degree in Informatics from the University of Dortmund and has studied Computer Science and Linguistics at University College Dublin. |
|||
14:00
Invalid Time
Invalid Time
|
We often define DevSecOps as ensuring that security isn't an afterthought to releasing software. It's an absolutely essential component, but initiatives can often fall into the trap of adding process and tools just to tick some boxes. How can we make sure that DevSecOps actually happens properly, getting security people and techniques into the full flow of agile delivery, and keep everyone happy? I'll go through the desires, the traps and pitfalls, and how to set up a DevSecOps initiative that doesn't compromise flow.
devsecops
process
security
About the speaker...Matt SaundersMatt is also co-organiser of the London DevOps meetup—a group with over 4,500 members which meets monthly. |
|||
15:00
Invalid Time
Invalid Time
|
Modern software teams usually strive for Continuous Delivery of business impact with a DevOps mindset: you build it, you run it. With short iterations and continuous feedback loops, teams deploy new software to production daily. As a software architect, it can be difficult to shape your role working in such a a fast-paced world. With daily deployments, is there even time for software architecture? How do you prevent being a delaying factor to the pace and success of a team? And how do you keep up? In this session, I’ll share my experiences working in a DevOps world as a software architect. We’ll look at the ideas behind DevOps and plot them to the domain of software architecture. I’ll talk about “just enough” architecture, about moving from up front design to evolving architecture, and will share lots of experiences and tips along the way. After this session, you’ll have practical insights and tips in how to work as an architect with a DevOps team.
devops
architecture
continuous-delivery
software-architecture
devsecops
About the speaker...Bert Jan SchrijverBert Jan is CTO at OpenValue and focuses on Java, software architecture, Continuous Delivery and DevOps. Bert Jan is a Java Champion, JavaOne Rock Star speaker, Duke’s Choice Award winner and leads NLJUG, the Dutch Java User Group. He loves to share his experience by speaking at conferences, writing for the Dutch Java magazine and helping out Devoxx4Kids with teaching kids how to code. Bert Jan is easily reachable on Twitter at @bjschrijver. |
|||
16:00
Invalid Time
Invalid Time
|
Security as Code (SaC) is the methodology of codifying security tests, scans, and policies. Security is implemented directly into the CI/CD pipeline to automatically and continuously detect security vulnerabilities. Adopting SaC tightly couples application development with security and vulnerability management, while simultaneously enabling developers to focus on core features and functionality. More importantly, it improves the collaboration between Development and Security teams and helps nurture a culture of security across the organization. In this session, we will review lessons learned from DevOps to implement a successful DevSecOps culture, in particular how we can make developers contribute security checks with the SaC approach. We will introduce CodeQL, a language that allows us to implement security checks with code, and will demo how we can code queries for vulnerabilities and misconfigurations so they can be identified as soon as they hit your CI/CD pipeline.
security
ci-cd
security-as-code
devsecops
About the speaker...Nancy GarichéNancy Gariché is a Senior Developer Advocate for GitHub Security Lab, where she helps build bridges between developers and security professionals to protect the open-source ecosystem. Before joining GitHub and the world of DevRel, she worked as a Senior Cybersecurity Analyst for the Canadian Government. This multi-hatted role allowed her to take on duties in multiple disciplines ranging from incident handling, to project and risk management. Involved in her local infosec community, she aspires to welcome and empower a new generation of industry professionals into the workforce. Outside of work, she volunteers for different non-profit organizations, co-lead the OWASP DevSlop Project and goes on weekend adventures with her family. |
-
Is DevSecOps the Wrong Name?
Featuring Dave Farley
How should we best deal with the security of our systems in a world of agile development and Continuous Delivery? The answer is to build security into our systems from the outset, rather than treat it as an afterthought.
devsecops continuous-delivery continuous-security security -
DevSecOps: A Practitioner's Perspective
Featuring Erik Dörnenburg
It was easy to sneak a “Sec” into DevOps, but in practice this raised more questions. In this example-filled talk, Erik will address these questions and discuss practices like container security scanning, binary attestation, and chaos engineering.
security devops container-security-scanning chaos-engineering binary-attestation security-scanning evolutionary-architecture fitness-functions devsecops -
DevSecOps and the Fight Against Friction
Featuring Matt Saunders
In this talk, Matt will go through the desires, the traps and pitfalls, and how to set up a DevSecOps initiative that doesn't compromise flow.
devsecops process security -
Software Architecture in a DevOps World
Featuring Bert Jan Schrijver
In this session, Bert Jan will share his experience working in a DevOps world as a software architect. After this session, you will have practical insights and tips in how to work as an architect with a DevOps team.
devops architecture continuous-delivery software-architecture devsecops -
Security as Code: A DevSecOps Approach
Featuring Nancy Gariché
In this session, we will review lessons learned from DevOps to implement a successful DevSecOps culture, in particular how we can make developers contribute security checks with the SaC approach.
security ci-cd security-as-code devsecops
-
J Forum
One day - Online Conference
Discover why Java remains a fundamental piece of the software industry a quarter of century after its creation. You're invited to the free J Forum featuring keynotes by Holly Cummins, Ben Evans, Heather VanCura and Martijn Verburg.
java17 java19 java11 containerised-apps microservices quarkus openjdk software-development java -
Rust Forum
0.5 days - Online Conference
Discover Rust: Stack Overflow's "most loved" programming language. Join us for 4 keynotes exploring why Rust is increasingly being used in production by the world's biggest brands in Fin-tech, Machine Learning, Distributed Systems, Cloud Native Infrastructure, and Embedded...
cross-discipline software-development rust programming -
Microservices Forum
0.5 days - Online Conference
Join us at the Microservices Forum where we'll welcome 3 of the world's top Microservice experts — Chris Richardson, James Lewis and Sarah Wells — to discuss what's next in Microservices, and explore what it means to work and live in an increasingly decoupled world.
architecture-and-design microservices -
Leadership eXchange Forum
One day - Online Conference
Join us for the Leadership eXchange Forum — a half‑day of keynote speakers including Rosemarie Wilson, Heike Heemann, Cynthia Curtis, and more. Explore eye-opening topics such as imposter syndrome, changing habits, how to set up your environment and support system, as well as ESG transformation.
... cross-discipline people-product-process leadership imposter-syndrome esg enterprise-transformation corporate-transformation social-justice climate-crisis habits -
CloudNative eXchange Forum 2021
Two days - Online Conference
-
Accelerated Software eXchange Forum
One day - Online Conference
Join Dave Farley, Chelsea Troy, Heidi Waterhouse and Barry O'Reilly for a half-day of keynotes. W'll explore the relationship between speed and quality in the world of software development.
cross-discipline architecture quality devops continuous-delivery
Awesome!
Friends don't let friends miss out on great events.
Share it, and make the event even better!