Skip to content

VIDEO

What is a vulnerability?

Contrast Demo Laptop

Vulnerability management is a crucial part of what application security (AppSec) teams are tasked to do, but what exactly needs to be managed and addressed? In this video, Larry Maccherone, Dev(Sec)Ops Transformation Architect at Contract Security, highlights the issues with traditional definitions of vulnerabilities and discusses why better definitions can help AppSec teams more effectively safeguard their critical applications.

What to expect from this video:

  • Why generic definitions are accurate but not useful or actionable
  • Benefits of focusing on “gnarly” vulnerabilities
  • The downsides of relying on Static Application Security Testing (SAST)
  • How Runtime Security improves application security

About Larry:

Larry Maccherone is a thought leader on DevSecOps, Agile, and Analytics. At Comcast, Larry built and scaled to 600 development teams the Dev(Sec)Ops Transformation program over five years.

In his Dev(Sec)Ops Transformation role at Contrast Security, he's now looking to apply what he learned to guide organizations with a framework for safely empowering development teams to take ownership of the security of their products.

Larry writes code every day. He is the primary author of a dozen open-source projects... one of which gets 1M downloads per month. He believes that if you are going to give advice to developers and development teams you can't just have done it at some point in your career. You have to be doing it now. He’s not just talking the talk. He’s also walking the walk when it comes to developer-first security.

Full video transcript

Secure your apps and APIs from within

Schedule a one-to-one demo to see what Contrast Runtime Security can do for you.