Gå frakoblet med Player FM -appen!
EP 35 — Streamlining and Accelerating Your Product Security with iHerb’s Mike de Libero
Manage episode 366118254 series 3330694
In this episode of the Future of Application Security, Harshil speaks with Mike de Libero, Director of Product Security at iHerb, an online health and wellness shop. They discuss the ways in which automation helps lighten the workload and creates more consistency, when you need to hire someone for security automation, and what to look for when scaling visibility. They also discuss how the role of product security has evolved, the benefits and drawbacks of today's tools, and how to build more effective remediation.
Topics discussed:
- How to implement automation to lighten the load of product security engineers and to create a more consistent experience for everyone.
- What to look for and what questions to ask in order to scale your visibility.
- How to know if it's the right time to hire someone for security automation — and why you should borrow someone from the dev team first.
- How product security has changed over the years, including its shift from testing and finding issues to building libraries, controls, and frameworks to help dev teams push code out quicker.
- How to group classes of security issues in order to streamline remediation, and how Mike's team went from 1900 tickets to 30 with this practice.
- How Mike's background as a programmer gives him more understanding and empathy in his role as Director of Product Security at iHerb, LLC.
- What Mike learned about product security at different companies in the past, including Salesforce, Microsoft, Uber, and Unity.
60 episoder
Manage episode 366118254 series 3330694
In this episode of the Future of Application Security, Harshil speaks with Mike de Libero, Director of Product Security at iHerb, an online health and wellness shop. They discuss the ways in which automation helps lighten the workload and creates more consistency, when you need to hire someone for security automation, and what to look for when scaling visibility. They also discuss how the role of product security has evolved, the benefits and drawbacks of today's tools, and how to build more effective remediation.
Topics discussed:
- How to implement automation to lighten the load of product security engineers and to create a more consistent experience for everyone.
- What to look for and what questions to ask in order to scale your visibility.
- How to know if it's the right time to hire someone for security automation — and why you should borrow someone from the dev team first.
- How product security has changed over the years, including its shift from testing and finding issues to building libraries, controls, and frameworks to help dev teams push code out quicker.
- How to group classes of security issues in order to streamline remediation, and how Mike's team went from 1900 tickets to 30 with this practice.
- How Mike's background as a programmer gives him more understanding and empathy in his role as Director of Product Security at iHerb, LLC.
- What Mike learned about product security at different companies in the past, including Salesforce, Microsoft, Uber, and Unity.
60 episoder
सभी एपिसोड
×Velkommen til Player FM!
Player FM scanner netter for høykvalitets podcaster som du kan nyte nå. Det er den beste podcastappen og fungerer på Android, iPhone og internett. Registrer deg for å synkronisere abonnement på flere enheter.