Overview
Syllabus
Introduction
Agenda
The average developer
Myths about security
We already have a security department
The state of developer security
Developers are the first line of defense
Developers think like security people
What defines a security person
Start with why
This is a people problem
Four different answers
The Unfamiliar
Foundational Lessons
Everyone is a Security Person
Proactive Controls
Overworked
Automate
Objections
The Apathetic
The Shock Value
The Pain
Thegungho
Security Community
Security People
Security Behaviors
Security Habits
Security Learning
Experience Security
Community Participation
Planning Resources
Threat Modeling
Security Code Review
Red Teaming
Respond to Security Problems
Putting it All Together
Takeaways
Questions
Behavior not process
Taught by
NDC Conferences