Michael Wildpaner
Why Security-First Development Helps You Ship Better Software Faster
#1about 4 minutes
The paradox of security and development speed
Security and reliability are foundational business needs, and focusing on them early can paradoxically accelerate the entire delivery lifecycle.
#2about 2 minutes
Optimizing for developer flow and experience
Security tools should be designed to preserve developer flow and minimize context switching to avoid making daily work miserable.
#3about 3 minutes
Integrating security across the development lifecycle
Security can be integrated at multiple stages, from initial project design and coding to the pre-commit and code review phases.
#4about 3 minutes
Understanding static analysis security testing (SAST)
Static analysis tools scan source code, infrastructure as code, containers, and dependencies to find vulnerabilities before the code is run.
#5about 4 minutes
Exploring dynamic analysis security testing (DAST)
Dynamic analysis tests running systems through techniques like web application scanning, API fuzzing, and overload testing to find runtime vulnerabilities.
#6about 3 minutes
Scaling AppSec teams by empowering developers
Shifting security responsibilities to developers helps the typically smaller AppSec team scale and focus on systemic architectural problems.
#7about 2 minutes
Future trends including AI and platform consolidation
The future of security involves AI-powered remediation and consolidated development platforms that embed security policies for the entire organization.
#8about 2 minutes
Key requirements for effective security tools
Modern security tools must be accurate to avoid false positives, provide context, and offer automated remediation to be truly effective.
Related jobs
Jobs that call for the skills explored in this talk.
Matching moments
01:33 MIN
Shifting security testing left in the development lifecycle
Vue3 practical development
02:43 MIN
Integrating security earlier in the development lifecycle
Vulnerable VS Code extensions are now at your front door
04:29 MIN
The modern DevSecOps approach to application security
Maturity assessment for technicians or how I learned to love OWASP SAMM
02:12 MIN
Why security must be integrated from the start
DevSecOps: Security in DevOps
02:52 MIN
Why security is often neglected in development
Security in modern Web Applications - OWASP to the rescue!
05:06 MIN
Hardening the CI/CD pipeline with automated security tools
You can’t hack what you can’t see
02:18 MIN
The evolution from traditional security to DevSecOps
DevSecOps culture
04:25 MIN
Balancing developer and stakeholder security priorities
What The Hack is Web App Sec?
Featured Partners
Related Videos
Simple Steps to Kill DevSec without Giving Up on Security
Isaac Evans
Real-World Security for Busy Developers
Kevin Lewis
Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together
Stefania Chaplin
Get security done: streamlining application security with Aikido
Mia Neethling
Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?
Tino Sokic
Security Pitfalls for Software Engineers
Jasmin Azemović
You can’t hack what you can’t see
Reto Kaeser
How GitHub secures open source
Joseph Katsioloudes
Related Articles
View all articles



From learning to earning
Jobs that call for the skills explored in this talk.


HvS-Consulting GmbH
Garching b. München, Germany
Intermediate
Senior
.NET
Angular
TypeScript

Peter Park System GmbH
München, Germany
Senior
Python
Docker
Node.js
JavaScript

Speech Processing Solutions
Vienna, Austria
Intermediate
CSS
HTML
JavaScript
TypeScript



Banco Santander, S.A.
Municipality of Madrid, Spain
Continuous Integration

SWIFT
Brussels, Belgium
Senior
Continuous Delivery
Continuous Integration
