• The Secure Developer

  • De: Snyk
  • Podcast

The Secure Developer

De: Snyk
  • Resumen

  • Securing the future of DevOps and AI: real talk with industry leaders.
    2016 - 2024 Snyk
    Más Menos
Episodios
  • The Case For Steward Ownership And Open Source With Melanie Rieback
    Apr 29 2025

    Episode Summary

    Is the traditional Silicon Valley startup model harming the security industry? In this episode of The Secure Developer, Danny Allan talks with Melanie Rieback, founder of Radically Open Security, about shaking up the industry with nonprofit business models. Tuning in, you’ll learn about the inner workings of Radically Open Security as a non-profit organization and the positive impact its donations have had on the open source ecosystem.

    We discuss the benefits of a steward-ownership business model, why it pairs so well with open source, and its power to reform venture capital and align incentives with long-term sustainability. For those interested in diving deeper, Melanie shares resources from her startup incubator, Nonprofit Ventures, and her free online Post Growth Entrepreneurship course. Tune in to learn why reforming our business models is vital for preserving and protecting our open source ecosystem and, by extension, security!

    Show Notes

    In this episode, Snyk CTO Danny Allan chats with Dr. Melanie Rieback, founder of Radically Open Security, about her journey from academia and pen testing to founding a cybersecurity company with a radically different business model. Melanie shares the motivations behind creating a not-for-profit organization that donates 90% of its profits to the NLnet Foundation, supporting open source and digital rights initiatives. They discuss the discontent with traditional cybersecurity business practices, including lack of transparency and ethical concerns like selling zero-days.

    Melanie explains Radically Open Security's structure, operating as a collective primarily using contractors, and how this model has allowed them to grow to 50 people while serving major clients and offering pro-bono work for nonprofits and critical open source projects like the Tor Project and Tails. The conversation then broadens to discuss alternative business models like steward ownership, where profit rights are separated from voting rights, aiming to lock value within the company and prevent mission drift often caused by traditional VC funding.

    They explore the concept of "Post Growth Entrepreneurship," which Melanie teaches, focusing on non-extractive business models and reforming finance itself. The discussion touches upon whether the tech industry, particularly open source, is moving towards more sustainable and ethical models, citing examples like Signal, Proton, Mastodon, and Mozilla. Melanie emphasizes that the culture of open source developers is often inherently altruistic, not greedy, but can be compromised by traditional funding systems. Finally, Melanie offers resources for listeners interested in learning more about these alternative models.

    Links

    • Radically Open Security
    • Radically Open Security on LinkedIn
    • NLnet Foundation
    • Nonprofit Ventures
    • Post Growth Entrepreneurship Course
    • Snyk - The Developer Security Company

    Follow Us

    • Our Website
    • Our LinkedIn
    Más Menos
    44 m
  • Advancing AppSec With AI With Akira Brand
    Apr 15 2025

    Episode Summary

    In this episode of The Secure Developer, Danny Allan sits down with Akira Brand, AVP of Application Security at PRA Group, to explore the evolving landscape of application security and AI. Akira shares her unconventional journey from opera to cybersecurity, discusses why AppSec is fundamentally a customer service role and breaks down how AI is reshaping security workflows. Tune in to hear insights on integrating security seamlessly into development, AI’s role in secure coding, and the future of AppSec in a rapidly shifting tech landscape.

    Show Notes

    In this engaging episode, The Secure Developer welcomes Akira Brand, AVP of Application Security at PRA Group, for an in-depth discussion on the intersection of AI and application security. Akira’s unique background in opera and stage direction offers a fresh perspective on fostering collaboration in security teams and influencing organizational culture.

    Key Topics Covered:

    • From Opera to AppSec: Akira shares her journey from classical music to cybersecurity and how her experience in stage direction translates into leading security teams.
    • AppSec as a Customer Service Role: The importance of serving software engineers by providing security solutions that fit seamlessly into their workflows.
    • The ‘Give Them the Pickle’ Approach: How meeting developers where they are and educating them can lead to better security adoption.
    • AI’s Role in Secure Development: How AI-driven tools are transforming the way security is integrated into the software development lifecycle.
    • Challenges in Security Culture: Why security is still an afterthought in many development processes and how to change that mindset.
    • Future of AI in Security: The promise and risks of AI-assisted security tools and the need for standards to keep pace with rapid technological advancements.

    Links

    • PRA Group
    • Turing School
    • Brian Holt
    • Frontend Masters
    • Resilia
    • Snyk - The Developer Security Company

    Follow Us

    • Our Website
    • Our LinkedIn
    Más Menos
    35 m
  • Authentication, Authorization, And The Future Of AI Security With Alex Salazar
    Apr 1 2025

    Episode Summary

    In this episode of The Secure Developer, host Danny Allan sits down with Alex Salazar, founder and CEO of Arcade, to discuss the evolving landscape of authentication and authorization in an AI-driven world. Alex shares insights on the shift from traditional front-door security to back-end agent interactions, the challenges of securing AI-driven agents, and the role of identity in modern security frameworks. The conversation delves into the future of AI, agentic workflows, and how organizations can navigate authentication, authorization, and security in this new era.

    Show Notes

    Danny Allan welcomes Alex Salazar, an experienced security leader and CEO of Arcade, to explore the transformation of authentication and authorization in AI-powered environments. Drawing from his experience at Okta, Stormpath, and venture capital, Alex provides a unique perspective on securing interactions between AI agents and authenticated services.

    Key topics discussed include:

    • The Evolution of Authentication & Authorization: Traditional models focused on front-door access (user logins, SSO), whereas AI-driven agents require secure back-end interactions.
    • Agentic AI and Security Risks: How AI agents interact with services on behalf of users, and why identity becomes the new perimeter in security.
    • OAuth and Identity Challenges: Adapting OAuth for AI agents, ensuring least-privilege access, and maintaining security compliance.
    • AI Hallucinations & Risk Management: Strategies for mitigating LLM hallucinations, ensuring accuracy, and maintaining human oversight.
    • The Future of AI & Agentic Workflows: Predictions on how AI will continue to evolve, the rise of specialized AI models, and the intersection of AI and physical automation.

    Alex and Danny also discuss the broader impact of AI on developer productivity, with insights into how companies can leverage AI responsibly to boost efficiency without compromising security.

    Links

    • Arcade.dev - Make AI Actually Do Things
    • Okta - Identity
    • OAuth - Authorization Protocol
    • LangChain - Applications that Can Reason
    • Hugging Face - The AI Community Building the Future
    • Snyk - The Developer Security Company

    Follow Us

    • Our Website
    • Our LinkedIn
    Más Menos
    39 m
adbl_web_global_use_to_activate_webcro768_stickypopup

Lo que los oyentes dicen sobre The Secure Developer

Calificaciones medias de los clientes

Reseñas - Selecciona las pestañas a continuación para cambiar el origen de las reseñas.