Agile + DevOps East 2020 Concurrent Session : Practical DevSecOps Using Security Instrumentation

Conference archive


Wednesday, November 11, 2020 - 4:00pm to 5:00pm

Practical DevSecOps Using Security Instrumentation

The traditional “outside in” scanning and firewalling approach to application security has failed. Vulnerability rates are still staggering, attacks are increasing in volume and severity, and security is disrupting software pipelines.  We need a new approach to security that doesn’t slow development or hamper innovation.  In this talk, we will show how you can ensure software security from the “inside out” by leveraging the power of software instrumentation. Unlike scanning and firewalling, this approach is fast, accurate, and scalable. Security observability also creates an environment where development, security, and operations teams can collaborate effectively. In this talk, we’ll show how software security instrumentation works, how it’s being used in many organizations, and what the future holds for DevSecOps.Coming Soon!

Jeff Williams
Contrast Security

Jeff Williams brings more than 20 years of security leadership experience as co-founder and Chief Technology Officer of Contrast Security. He recently authored the DZone DevSecOps, IAST, and RASP refcards and speaks frequently at conferences including JavaOne (Java Rockstar), BlackHat, QCon, RSA, OWASP, Velocity, and PivotalOne. Jeff is also a founder and major contributor to OWASP, where he served as Global Chairman for 9 years, and created the OWASP Top 10, OWASP Enterprise Security API, OWASP Application Security Verification Standard, XSS Prevention Cheat Sheet, and many more popular open source projects. Jeff has a BA from Virginia, an MA from George Mason, and a JD from Georgetown. Reach out to Jeff on LinkedIn.