SlideShare a Scribd company logo
The Rise of
Fabian Lim
/about
• DevSecOps Engineer
– 1.5 years
– Culture Hacking
– Passion in Infrastructure and Operations
• Carnegie Mellon University
– MSc Information Security Policy and Management
• Singapore Management University
– BSc Information Systems
• Gym, Krav Maga enthusiast
/journey
1. DevSecOps Engineer
2. Open-Source Projects
3. Red Team
4. Culture Hacking
5. Security Defect Reporting & Metrics
https://s-media-cache-ak0.pinimg.com/originals/f6/36/0d/f6360df9be90fa7b03cb7f4e7b5a6dc6.jpg
/peek
• A Peek into My Everyday
– Development and maintenance of in house tools
using experiments
– Security knowledge is essential to identify security
flaws
– Operations know-how of our own infrastructure so it
is resilient
• Red Team Monday is awesome!
• Blue Team All-Day is cool too!
/mindset
• Collaboration Focus
• Open and Transparent
• Prefer Shiteration over Perfection
• (Actively) “Hunting” mode over Reactive mode
• What keeps you up at night?
/how
• Everyone – needs to get their hands dirty at code
• Can-do Agile Attitude – Fail Fast, Crawl Walk Run
• Culture - Everyone is responsible for Security
• Red Teaming – Crucial to move the ‘urgency’ needle
• Metrics – to report, show trends
/why
• Passion
• Revolutionary Way of Doing Security
• Works and Improves the Security Posture of the
Company
• I Want to be Worked WITH Rather Than AGAINST
/open_source_projects
• GOAL: Get developers to be involved and
contribute your security tools
• EFFECT: Working together
• RESULT: Secure Company-Wide Projects
• TRADITION: Security Team v.s Development Team
• GOAL: We are all one – there is no ‘them’ and ‘us’
• METHOD: Security Understands Developers and
Helps to Solve Security Issues Together, not Blaming
• RESULT: Shared Sense of Responsibility
/culture
The Rise of DevSecOps - Fabian Lim - DevSecOpsSg
/red_team
• TARGET: Low-Hanging Fruit
• EFFECT: A Method to Convince
Management
• RESULT: Increases Focus and
Resources on Security
/security_defect_reporting
• GOAL: Measure State of Security
• EFFECT: Management sees
resources used effectively
• RESULT: Significantly improve
Visibility on Security Performance
/references
• devsecops.org
• github.com/devsecops/bootcamp
• @3jmaster
• http://www.devsecops.org/blog?tag=DevSecOps+Explained
/gracias

More Related Content

PDF
DevSecOps - The big picture
PDF
Integrating DevOps and Security
PDF
DevSecOps - The big picture
PDF
DevSecCon London 2017: Shift happens ... by Colin Domoney
PPTX
DevSecCon London 2017: when good containers go bad by Tim Mackey
PDF
DevSecCon London 2017: How far left do you want to go with security? by Javie...
PPTX
The Journey to DevSecOps
PDF
Practical DevSecOps Course - Part 1
DevSecOps - The big picture
Integrating DevOps and Security
DevSecOps - The big picture
DevSecCon London 2017: Shift happens ... by Colin Domoney
DevSecCon London 2017: when good containers go bad by Tim Mackey
DevSecCon London 2017: How far left do you want to go with security? by Javie...
The Journey to DevSecOps
Practical DevSecOps Course - Part 1

What's hot (20)

KEY
DevOpsSec: Appling DevOps Principles to Security, DevOpsDays Austin 2012
PDF
DevSecCon Asia 2017 Fabian Lim: DevSecOps in the government
PDF
2019 DevSecOps Reference Architectures
PPTX
Security & DevOps- Ways To Make Sure Your Apps & Infrastructure Are Secure
PDF
Application Security at DevOps Speed - DevOpsDays Singapore 2016
PDF
DevSecCon London 2017: Threat modeling in a CI environment by Steven Wierckx
PDF
Ast in CI/CD by Ofer Maor
PPTX
DevSecCon Asia 2017 Shannon Lietz: Security is Shifting Left
PDF
A Secure DevOps Journey
PPTX
Null application security in an agile world
PDF
DevSecOps: Bringing security to the DevOps pipeline
PPTX
Shifting left – embedding security into the devops pipeline by Mike d. Kail
PPTX
DevSecOps : an Introduction
PDF
Introducing DevSecOps by Madhu Akula - Software Security Bangalore - May 27 2...
PDF
Dos and Don'ts of DevSecOps
PDF
Application Security in an Agile World - Agile Singapore 2016
PDF
DevSecOps and the CI/CD Pipeline
PDF
DevSecCon Asia 2017 Ofer Maor: AppSec DevOps automation – real world cases
PDF
RSAC DevSecOpsDays 2018 - We are all Equifax
PDF
DevSecOps: Minimizing Risk, Improving Security
DevOpsSec: Appling DevOps Principles to Security, DevOpsDays Austin 2012
DevSecCon Asia 2017 Fabian Lim: DevSecOps in the government
2019 DevSecOps Reference Architectures
Security & DevOps- Ways To Make Sure Your Apps & Infrastructure Are Secure
Application Security at DevOps Speed - DevOpsDays Singapore 2016
DevSecCon London 2017: Threat modeling in a CI environment by Steven Wierckx
Ast in CI/CD by Ofer Maor
DevSecCon Asia 2017 Shannon Lietz: Security is Shifting Left
A Secure DevOps Journey
Null application security in an agile world
DevSecOps: Bringing security to the DevOps pipeline
Shifting left – embedding security into the devops pipeline by Mike d. Kail
DevSecOps : an Introduction
Introducing DevSecOps by Madhu Akula - Software Security Bangalore - May 27 2...
Dos and Don'ts of DevSecOps
Application Security in an Agile World - Agile Singapore 2016
DevSecOps and the CI/CD Pipeline
DevSecCon Asia 2017 Ofer Maor: AppSec DevOps automation – real world cases
RSAC DevSecOpsDays 2018 - We are all Equifax
DevSecOps: Minimizing Risk, Improving Security
Ad

Viewers also liked (18)

PPTX
DEVSECOPS: Coding DevSecOps journey
PDF
The Changing Landscape of Information Security
PDF
DevSecOps - Building Rugged Software
PDF
DevSecOps in Baby Steps
PPTX
DevOps & Security: Here & Now
PDF
Implementing DevOps in a Regulated Environment - DJ Schleen
PPTX
Implementing an Application Security Pipeline in Jenkins
PPTX
Infrastructure Saturday - Level Up to DevSecOps
PPTX
Cyber Security Landscape: Changes, Threats and Challenges
PDF
Devops, Secops, Opsec, DevSec *ops *.* ?
PDF
DevOps and IT security
PPTX
DevOps in a Regulated and Embedded Environment (AgileDC)
PDF
Release Engineering & Rugged DevOps: An Intersection - J. Paul Reed
PPTX
Making Security Agile - Oleg Gryb
PDF
Building Security In - A Tale of Two Stories - Laksh Raghavan
PPTX
Empowering Application Security Protection in the World of DevOps
PDF
Requirements Gathering for a Successful Rugged DevOps Implementation - Hasan ...
PDF
DevSecOps: Taking a DevOps Approach to Security
DEVSECOPS: Coding DevSecOps journey
The Changing Landscape of Information Security
DevSecOps - Building Rugged Software
DevSecOps in Baby Steps
DevOps & Security: Here & Now
Implementing DevOps in a Regulated Environment - DJ Schleen
Implementing an Application Security Pipeline in Jenkins
Infrastructure Saturday - Level Up to DevSecOps
Cyber Security Landscape: Changes, Threats and Challenges
Devops, Secops, Opsec, DevSec *ops *.* ?
DevOps and IT security
DevOps in a Regulated and Embedded Environment (AgileDC)
Release Engineering & Rugged DevOps: An Intersection - J. Paul Reed
Making Security Agile - Oleg Gryb
Building Security In - A Tale of Two Stories - Laksh Raghavan
Empowering Application Security Protection in the World of DevOps
Requirements Gathering for a Successful Rugged DevOps Implementation - Hasan ...
DevSecOps: Taking a DevOps Approach to Security
Ad

Similar to The Rise of DevSecOps - Fabian Lim - DevSecOpsSg (20)

PDF
Building Security Teams
PDF
Why Security Engineer Need Shift-Left to DevSecOps?
PPTX
ISACA Ireland Keynote 2015
PDF
Protecting Agile Transformation through Secure DevOps (DevSecOps)
PPTX
Lean_Security.pptx
PPTX
DevSecOps: Integrating Security Into DevOps! {Business Security}
PPTX
DevSecOps Training Bootcamp - A Practical DevSecOps Course
PDF
Strengthen and Scale Security for a dollar or less
PDF
Strengthen and Scale Security Using DevSecOps - OWASP Indonesia
PDF
[cb22] Keynote: Underwhelmed: Making Sense of the Overwhelming Challenge of C...
PPTX
Software Developer Resumes
PDF
Effective security
PDF
Scale security for a dollar or less
PPTX
DevSecCon Keynote
PPTX
DevSecCon KeyNote London 2015
PDF
Outpost24 webinar: Turning DevOps and security into DevSecOps
PPTX
SCS DevSecOps Seminar - State of DevSecOps
PDF
Leveraging red for defense
PDF
Power your way to becoming a red team cyber security expert
PDF
DevOps: Lead, Follow or Get Out of the Way - A CISO Perspective
Building Security Teams
Why Security Engineer Need Shift-Left to DevSecOps?
ISACA Ireland Keynote 2015
Protecting Agile Transformation through Secure DevOps (DevSecOps)
Lean_Security.pptx
DevSecOps: Integrating Security Into DevOps! {Business Security}
DevSecOps Training Bootcamp - A Practical DevSecOps Course
Strengthen and Scale Security for a dollar or less
Strengthen and Scale Security Using DevSecOps - OWASP Indonesia
[cb22] Keynote: Underwhelmed: Making Sense of the Overwhelming Challenge of C...
Software Developer Resumes
Effective security
Scale security for a dollar or less
DevSecCon Keynote
DevSecCon KeyNote London 2015
Outpost24 webinar: Turning DevOps and security into DevSecOps
SCS DevSecOps Seminar - State of DevSecOps
Leveraging red for defense
Power your way to becoming a red team cyber security expert
DevOps: Lead, Follow or Get Out of the Way - A CISO Perspective

Recently uploaded (20)

PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PPTX
Big Data Technologies - Introduction.pptx
PDF
Encapsulation theory and applications.pdf
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PPT
Teaching material agriculture food technology
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
KodekX | Application Modernization Development
PDF
Encapsulation_ Review paper, used for researhc scholars
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Digital-Transformation-Roadmap-for-Companies.pptx
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
Big Data Technologies - Introduction.pptx
Encapsulation theory and applications.pdf
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Understanding_Digital_Forensics_Presentation.pptx
Teaching material agriculture food technology
Advanced methodologies resolving dimensionality complications for autism neur...
Review of recent advances in non-invasive hemoglobin estimation
Per capita expenditure prediction using model stacking based on satellite ima...
KodekX | Application Modernization Development
Encapsulation_ Review paper, used for researhc scholars
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
The Rise and Fall of 3GPP – Time for a Sabbatical?
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
NewMind AI Weekly Chronicles - August'25 Week I
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Network Security Unit 5.pdf for BCA BBA.
Mobile App Security Testing_ A Comprehensive Guide.pdf

The Rise of DevSecOps - Fabian Lim - DevSecOpsSg