Green Beret turned Director of Application Security. A security advocate providing cutting-edge research into a security-first software development approach.
🚨 Episode two of The Security Champions Podcast is now available!
Tim Brown, CISO of SolarWinds, joined to discuss the importance of elegant coding and its impact on organizational security.
Tune in to learn more! https://t.co/AupDhEncVQ
@TacticalAppSec#securitychampions
🔐Are You A Security Champion?
Gain exclusive insight from software development and security experts in our NEW Security Champions Podcast, hosted by @TacticalAppSec. We'll cover topics from automation to shift-left to training frameworks.
Follow Along: https://t.co/GmrXgdHWmm
It's Friday, and I am repeatedly running into the phrase "Work-life balance" on social media. This is thrown around a lot to explain why people need to prioritize their personal life over their work life. There is truth in that, but the saying is often ab…https://t.co/woNHKkvQNO
When I was in the military we had a very basic principle to leadership. I would never ask you to do something that I couldn't or haven't done myself. This was a way to set realistic expectations for the people working under a leader.
This doesn't always…https://t.co/CzdQIPjCUr
When I was in the military we had a very basic principle to leadership. I would never ask you to do something that I couldn't or haven't done myself. This was a way to set realistic expectations for the people working under a leader.
This doesn't always…https://t.co/lyqayZGI9i
I am a big fan of new years resolutions. I try not to pick things that I know I will fail. Instead, I focus on what I know I can do realistically and will have a meaningful impact. One I do every year is a "Dry January." I have a c…https://t.co/bCuFf3OFzT https://t.co/BqZKJWmXPD
We are in a downturn... what does that mean for security. When layoffs are happening and companies are tightening budgets how do we ensure security stays a priority? It's difficult to decide where to tighten the budget and what cos…https://t.co/7SiB5Vk7V5 https://t.co/x5AegKzGPz
Awareness versus Education
I think we can initially grasp the difference but we need to embrace the impact of one over another. If I am "Aware" I might be identify when something goes wrong, but when I am "Educated" I know what to…https://t.co/ypSRIzsAZE https://t.co/h3QAAL2dGv
For me this is the year of Security Champions. How do we get our developer community to adopt a security first mindset? Treat them like they are part of the security team, because they are!
I like to use an example from my days in Special Forces. We wou…https://t.co/1Xv8ibKxyQ
One of my new hobbies is getting into blockchain security. I'm not concerned with the value of cryptocurrencies or even the viability of the technology as a solution to industry problems. What fascinates me is the unique security issues it faces compared…https://t.co/ipPSEKGu3p
Focus is everything. When I go to work I’m not creating security training content based on what my competitors are doing. Instead we focus on making the content our developer community needs to create secure applications. Focus on your customer and you wi…https://t.co/uF9WLmh3MQ
Let's talk about new years resolutions! As a security advocate I am always looking for ways to continue my security learning journey. This year I want to upgrade my offensive knowledge because you cannot have a good defense if you do not understand how th…https://t.co/pirtCJUJAw
Let's talk about those new years resolutions! As a security advocate I am always looking to up my game and continue my security learning journey. This year I am looking to add a little more knowledge to my offensive game. I am a strong believer that to ha…https://t.co/RKifeeCyJu
"When assessing the two solutions, reviewers found Security Journey Platform easier to use, set up, and administer. Reviewers also preferred doing business with Security Journey Platform overall."
I love this type of feedback. It…https://t.co/F9GbGdHtjC https://t.co/hZsxP4zq5P
How do you approach security testing in your SDLC? If you have not heard of SWSTL before check out this video as we break down the Software Security Testing Lifecycle. https://t.co/wXbG47KQge
When we talk about security training for developers what is the most important factor?
Things that always come to mind are the value of the training compared to the cost. Is this something that is engaging and simple to implement? Will my developer audi…https://t.co/ucmO9waoiq
I had a great time giving this talk at BSides Charlotte this weekend. Check it out: "A tactical approach to Application Security | A Green Berets perspective." https://t.co/NlsaPSgGdL
Join me this weekend at BSides Charlotte! On day one, I am giving my talk, "A tactical look at Application Security | A Green Berets perspective." You can also join my workshop, "Security Threat Modelling Workshop," on day 2. https://t.co/SiHVNQ0Riy