Skip to content

VIDEO

Strategic evolution of DevSecOps: Interview with Larry Maccherone at RSA Conference 2024

main-screeen

Simply pushing traditional security practices “left” without adaptation to the way developers want to work won’t cut it. Finding vulnerabilities is not the problem; resolving vulnerabilities is the real bottleneck.

Luckily, a better way exists: Runtime Security.

As Larry Maccherone, Dev(Sec)Ops Transformation Architect at Contrast Security, has noted before, he believes that the biggest transformation in Application Security (AppSec) and application programming interface (API) security over the next few years will be that more and more of it will occur in production as opposed to pre-production. 

During RSA earlier this year, Larry sat down with Alan Shimel from TechStrong to talk about how DevSecOps is evolving and why app and API security testing in production will eventually become the norm. Check out the 13-minute interview:

 

Interview highlights:

  • How Larry championed and implemented DevSecOps as head of AppSec at Comcast
  • The downsides of the “shift left” approach and the need to have DevOps and developers take ownership over AppSec.
  • The benefits of testing and securing applications in production, particularly using Contrast Security.

Full video transcript

Secure your apps and APIs from within

Schedule a one-to-one demo to see what Contrast Runtime Security can do for you.