Skip to content
Artwork for DevSecOps Podcast
TechnologyEducation

DevSecOps Podcast

Cássio Batista Pereira

The DevSecOps Podcast explores the intersection of software development, cybersecurity, and modern engineering, with a strong focus on Application Security and DevSecOps.Each episode brings practical conversations with security professionals, engineers, researchers, community leaders, and industry experts about the challenges of building and operating secure software at scale.We go beyond tools and vulnerability scanning to discuss secure development, security culture, threat modeling, AppSec programs, AI, automation, cloud security, security testing, maturity models, and the realities of integrating security throughout the entire software development lifecycle.Expect technical insights, real-world experiences, lessons learned, strong opinions, and honest discussions about what actually works, what does not, and where software security is heading next.If you build software, secure applications, lead engineering or security teams, or simply want to understand how modern organizations can deliver software faster without losing control of security, the DevSecOps Podcast is for you.

Become a supporter of this podcast: https://www.spreaker.com/podcast/devsecops-podcast--4179006/support.
Play
  • 21 episodes
  • weekly
  • Avg 51 min
  • Portuguese

Support the show

Goes straight to the publisher. podnod takes nothing.

Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • Monday · 46 min

    #08 - 12 - The surprising game that transformed AppSec training

    Transform your approach to cybersecurity training with this insightful episode featuring Max Alejandro Gomez Sanchez Vergaray, a pioneer in integrating gaming into application security. Discover how Max’s innovative methodology not only translates...

    • Transcript
  • August 12 · 50 min

    #08 - 10 - How to teach kids complext topics

    In a world where AI is rapidly becoming the cornerstone of technology, understanding its intricacies is more crucial than ever. Join Rob van der Veer, a veteran in the AI field with over three decades of experience, as he unveils essential insights...

  • S8 · E9
    August 5 · 48 min

    #08 - 09 - CyberSec Games: CyberSec conversations on the table

    In a world dominated by screens, how do we reignite the joy of face-to-face interaction? In this episode, Cássio Pereira and Marcos Santos sit down with Devika Gibbs, co-founder of Cybersec Games, to explore the transformative power of physical games...

  • S8 · E8
    July 29 · 45 min

    #08 - 08 - DSOMM - DevSecOps Maturity Model

    How mature is your DevSecOps program, and how do you know what to improve next? In this episode, we talk with Timo Pagel, creator of DSOOM, the DevSecOps Maturity Model, about why organizations need structured guidance to build security into software...

  • S8 · E7
    July 22 · 53 min

    #08 - 07 - From conflict to collaboration

    In this episode of the DevSecOps Podcast, we talk with Juliane Reimann about turning one of the most common tensions in software development into real collaboration: the relationship between agile teams and IT security. Although both sides want...

  • S8 · E6
    July 16 · 56 min

    #08 - 06 - Manipulating people for a good AppSec

    In this episode of the DevSecOps Podcast, we talk with Nariman Aga-Tagiyev about how behavioral science can help improve Application Security programs. Based on his presentation, “Keep It Between Us: Manipulating Humans for Better AppSec (Ethically),”...

  • S8 · E5
    July 8 · 55 min

    #08 - 05 - AI Explainability Score Card

    In this episode, we sit down with Michael Novack to talk about the AI Explainability Scorecard, a practical framework for evaluating whether AI explanations are actually useful, trustworthy, and actionable. Michael walks us through the SCORE...

  • S8 · E4
    June 17 · 43 min

    #08 - 04 - Auto remediation

    E se a correção de vulnerabilidades deixasse de ser um ticket esquecido no backlog e virasse um pull request pronto para revisar? Neste episódio do DevSecOps Podcast, falamos sobre Auto Remediation, a próxima grande virada em Application Security....

  • S8 · E3
    May 20 · 1 hr 4 min

    #08 - 03 - Os mesmos desafios de AppSec

    Este episódio aborda os principais desafios em segurança de aplicações, incluindo a cultura organizacional, o alinhamento entre times de desenvolvimento e segurança, e o papel de líderes na transformação dessa cultura. Os convidados compartilham suas...

  • S8 · E2
    May 14 · 54 min

    #08- 02 - M.A.R.I.A. inovação em AppSec

    A maioria dos programas de AppSec está afogada em findings, dashboards, scanners, CVEs, SLAs e relatórios que ninguém aguenta mais ler. O problema não é falta de ferramenta. O problema é falta de contexto, correlação e inteligência para entender o que...

  • S8 · E1
    May 6 · 50 min

    #08 - 01 - SpecOps com IA - O novo normal

    Todo mundo fala de DevSecOps. Todo mundo fala de IA. Mas quase ninguém conectou os pontos do jeito certo ainda. Neste episódio, a gente entra em um território que está começando a separar quem só usa ferramenta de quem realmente entende o jogo:...

  • S7 · E18
    April 29 · 44 min

    #07 - 18 - Episódio especial

    Episódio 200. Não é só número redondo, é checkpoint de uma jornada que saiu de conversa técnica entre amigos e virou referência em AppSec e DevSecOps. Nesse especial, a mesa está completa. Desde a formação raiz com Balbino e Vini, passando pela...

  • S7 · E17
    April 21 · 55 min

    #07 - 17 - CarameloSec e Testes de Segurança

    No episódio de hoje, recebemos o time da CarameloSec para uma conversa sem firula sobre segurança de aplicações na vida real. Nada de teoria bonita que não sobrevive ao deploy. Falamos de como segurança é construída no dia a dia, os desafios de levar...

  • S7 · E16
    April 15 · 48 min

    #07 - 16 - AppSec no futuro da IA

    A IA não vai “impactar” AppSec. Vai engolir quem estiver parado. Neste episódio, a conversa é direta: o que sobra para quem trabalha com Segurança de Aplicações quando a IA começa a escrever código, revisar pull request, gerar arquitetura e até...

  • S7 · E15
    March 31 · 40 min

    #07 - 15 - Supply Chain fresco

    Supply Chain Security deixou de ser teoria e virou problema real. Neste episódio, destrinchamos os casos recentes envolvendo ferramentas amplamente utilizadas como Trivy, KICS e a biblioteca Axios e o que eles expõem sobre a fragilidade da cadeia de...

  • S7 · E12
    March 10 · 58 min

    #07 - 14 - Log Modeling

    Neste episódio do DevSecOps Podcast, mergulhamos em um tema frequentemente subestimado, mas absolutamente crítico para a segurança moderna: Log Modeling. Enquanto muita gente trata logs apenas como registros para troubleshooting, a realidade é outra....

  • S7 · E13
    March 4 · 36 min

    #07 - 13 - Pós Graduação em AppSec

    Neste episódio do DevSecOps Podcast, o papo gira em torno de um tema que muita gente na área de tecnologia sente na pele: a falta de formação realmente sólida em Application Security. Em vez de cursos superficiais ou conteúdos soltos pela internet,...

  • S7 · E12
    February 18 · 1 hr

    #07 - 12 - SCA além do open source.

    Neste episódio do DevSecOps Podcast, fomos direto no ponto: SCA não é sinônimo de caçar CVE em biblioteca open source. Durante anos, muita empresa reduziu Software Composition Analysis a “rodar ferramenta e ver se tem vulnerabilidade no npm ou no...

  • S7 · E11
    February 13 · 55 min

    #07 - 11 - Temer a IA?

    IA é ferramenta. Poderosa. Rápida. Escalável. E completamente indiferente ao que é certo ou errado. Neste episódio do DevSecOps Podcast, mergulhamos nos perigos reais da Inteligência Artificial além do hype e além do medo irracional. Falamos sobre...

Showing 1–20 of 21 episodes