Glenn Wilson, and Steve Giguere

DSO Overflow

In this podcast, we speak with professionals working in cyber security, software engineering and operations to talks about a number of DevSecOps topics. We discuss how organisations factor security into their product delivery cycles without compromising the value of doing DevOps and Agile.

Author

Glenn Wilson, and Steve Giguere

Category

Technology

Podcast website

dso-overflow.buzzsprout.com

Latest episode

Jan 5, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

S3Ep3 - Leveraging Systems Thinking with Simon Copsey 06.03.2023

DSO Overflow S3EP3 Leveraging Systems Thinking with Simon Copley In this episode, Steve, Jess and I are joined by Simon Copsey who talks to us about taking a systems thinking approach to improving organisational performance. He tells us among other things, about challenging assumptions, identifying, understanding and managing constraints, and how important it is to recognise cognitive dissonance....

S3Ep2 - Cloud Security with Paul Schwarzenberger 06.02.2023

DSO Overflow S3EP2 Cloud Security with Paul Schwarzenberger In this episode, Steve and I are joined by Paul Schwarzenberger who talks to us about cloud providers, cloud security and an OWASP project he has recently started working on. We hear about Paul's journey into cloud security, his views on certification programmes, and he warns us of the security traps that await us when working with c...

S3Ep1 - CVE, CVSS and the Land of Broken Dreams with Francesco Cipollone 16.01.2023

DSO Overflow S3EP1 CVE, CVSS and the Land of Broken Dreams with Francesco Cipollone In this episode, Steve and Glenn are joined by Francesco 'Frank' Cipollone CEO and Founder of AppSec Phoenix. Frank talks about CVEs, CVSS scoring and how they create too much noise to be effective in helping organisations improve their security posture. We hear Frank speak about contextualisation and ris...

S2Ep5 - Security Differently with Mario Platt 12.09.2022

DSO Overflow S3EP5 Security Differently with Mario Platt from LastPass In this episode Glenn Wilson and Steve Giguere sit down with Mario Platt to discuss how the current paradigm of doing security is not working. Taking lessons from how safety is managed within a physically demanding role, Mario examens why compliance is failing and how we need to build a new model based on resilience. Resources...

S2Ep4 - Cloud Security @ Large with Ashish and Shilpi 02.09.2022

DSO/Overflow S2EP4 Cloud Security at Large with Ashish Rajan and Shilpi Bhattacharjee from the Cloud Security Podcast https://cloudsecuritypodcast.tv/ https://twitter.com/cloudsecpod?lang=en https://www.youtube.com/c/CloudSecurityPodcast?sub_confirmation=1 Watch on YouTube: https://youtu.be/HV6iJReLoXE In the episode, Jessica Cregg sits with Ashish and Shilpi and breaks the 4th wall about their me...

S2Ep3 - Or Weis on Modern Authorization 31.03.2022

In this episode, Or Weis talks to us about Full Stack Permission as a Service, why simplifying access control is crucial to creating secure infrastructure and how the use of access control could facilitate a zero-trust architecture. BIO Or is the CEO and co-founder of Permit.io , and co-maintainer and author of open source OPAL.ac. Or is a serial entrepreneur who is passionate about developer tool...

S2Ep2 - Chris Tomkins and Nathan Skrzypczak on VPP and K8s Calico Data Planes 09.03.2022

In this episode, Nathan and Chris talk about VPP, Calico, CNI and Service Mesh architecture. We will learn how VPP can enhance security and performance of your K8s clusters and the benefits of using Calico. Bios Chris Tomkins - Chris is lead developer advocate at Tigera, where he champions user needs to support Project Calico’s users and contributor community. He has worked in networking since 200...

S2Ep1 - Nigel Kersten: Accelerating DevOps Adoption 31.01.2022

Episode Summary In this episode, Nigel gives his views on the current state of DevOps adoption, the role of security in DevOps, and gives us some clues from the State of DevOps Report 2021 that will help organisations accelerate their DevOps journey. Nigel's Bio Nigel is a Field CTO at Puppet where he is responsible for bringing product knowledge and a senior technical operations perspective...

EP17: A History of Kubernetes Security with Rory McCune 29.12.2021

From containers to Kubernetes to cloud, it can be hard enough to keep up with the technologies let alone how to secure them.  Rory McCune was there at the inception.  Starting as a pen tester looking into  containers he has become one of the world's foremost Kubernetes security authorities. In this episode Glenn and Steve talk to him about the early days of containers, the orchestration wars,...

EP:16 Breaking down silos with Stefania Chaplin 26.12.2021

In this episode, Steve and Glenn are joined by Stefania Chaplin to talk about breaking down silos. Bio Stefania Chaplin’s experience within Cybersecurity, DevSecOps and OSS governance means she's helped countless organisations understand and implement security throughout their SDLC. As a python developer at heart, Stefania is always optimising and improving efficiency wherever she goes by scr...

EP15: DevSecOps Personas 25.10.2021

In this episode, Steve and Glenn speak with Ed Tucker and Gary Robinson about the differences between DevSecOps personas. DevSecOps Personas – what Developers, Security, and Operations think when it comes to people/tech/processes/culture when it comes to rolling out DevSecOps programs.  Each of these teams have different drivers, ambitions, blockers, and challenges when it comes to a successful De...

EP14: Threat Modeling - A Manifesto And Some Code 23.08.2021

Title: Threat Modeling - A Manifesto And Some Code Threat Modeling: Why we think it matters for you, and how you can implement it in your organization. Modeling: How to model your system in an expressive way. Eliciting threats: What are some of the major approaches in use and how can it be done closer to the developer and at Agile speed. Evolution: Automated threat analysis using an open source to...

EP13: Top 5 things I wish I knew about SAST 04.08.2021

Application security testing ... top tips to achieve more SASTisfaction from your tooling. References Youtube Channel: AppSecEngineer Youtube Channel: we45 OSSF Scorecard Please visit our YouTube Channel to see Florin present in our July 2021 Gathering (monthly meet-up). Guest Speakers Florin Coada I've been working in the Application Security testing space for the last eight years. I was luc...

EP12: Exploring eBPF Cloud Native Security 19.06.2021

Extended Berkeley Packet Filter (eBPF) allows us to tap into the kernel to implement monitoring, observability, networking, and security.  In this episode, we invited Chris Kranz and Liz Rice to discuss the usage and adoption of eBPF within Cloud Native solutions. References http://www.brendangregg.com/ https://nathanleclaire.com/ https://github.com/iovisor/bpftrace https://ebpf.io/what-is-ebpf ht...

Ep11: From Zero To a DevSecOps Hero 06.06.2021

Learning or knowing what to study in the field of security is a tough subject in it's own right.  Join us with Marcus and Josh where we understand what best practices they follow them. Please visit our YouTube Channel to see Marcus present in our May 2021 Gathering (monthly meet-up). Guest Speakers: Marcus Maxwell: Marcus Maxwell is a Principal Consultant at Contino. He has spent the last 5 y...

Ep10: Security Chaos Engineering 09.05.2021

Join us to explore and learn what is Security Chaos Engineering with two of the leading figures in this field Aaron Reinhart and Kennedy Torkura. If you missed the Gathering watch the meet-up here . References: Aaron Reinhart Chaos Engineering: System Resiliency in Practice Security Chaos Engineering References: Kennedy Torkura Security-Chaos-Engineering-for-Cloud-Services From Dependability to Re...

Ep09: DevOps meets Security 24.04.2021

DevOps meets Security. London DevOps meets DevSecOps - London Gathering.  https://www.meetup.com/London-DevOps/ Speakers Bio: Matt Saunders is a technical operations leader, using Devops and continuous delivery to help teams deliver quality software quickly and efficiently. He is also co-organiser of the London DevOps meetup - a group with over 8,000 members which meets monthly. https://www.linked...

Ep08:Kubernetes Exam Cram 05.04.2021

We have the pleasure to have Steve Giguere and Michael Foster, the hosts from Clust3rF8ck, to share with us their experience cramming in all the relevant materials to take both the CKA (Kubernetes Administrator) and CKS (Kubernetes Security Specialist) exams https://www.twitch.tv/clust3rf8ck https://www.cncf.io/certification/cka/ https://www.cncf.io/certification/cks/ Speakers Bio: Steve Giguere i...

Ep07:Using Rego to define your policies 18.02.2021

In this episode we invited Anders from the Open Policy Agent project and Alex one of the masterminds behind a new opensource project called KICS. OpenSource Projects KICS - Keep your Infrastructure as Code Secure: https://kics.io/ Styra Academy: https://academy.styra.com/ Rego Playground: https://play.openpolicyagent.org/ Official Docs: https://www.openpolicyagent.org/docs/latest/ OPA Blog: https:...

Ep06: Checkov 12.09.2020

In this episode I have the pleasure of talking to James and Corcoran - two very talented individuals when it comes to Infrastructure as Code as well as all things DevOps; in addition we have Barak the CTO of Bridgecrew the company behind the opensource project - Checkov Checkov details: https://www.checkov.io/1.Introduction/Getting%20Started.html ### DevSecOps - London Gathering ### https://dso-lg...

Ep05: Semgrep 12.09.2020

In this episode I have the pleasure of talking to Clint from R2C - a software security startup from the US.  They are championing an open source project called semgrep. I will be exploring what this is and how it is modernising SAST. Semgrep details: https://semgrep.dev/ ### DevSecOps - London Gathering ### https://dso-lg.com https://dso-overflow.com Also follow us on Twitter: @DevSecOps_LG

Ep04: Secure Delivery Playbook 12.09.2020

In this episode I have invited Stuart and James who are the project leads behind the Secure Delivery Playbook. This is a distilled version of their various client engagements when incorporating security into their development. Secure Delivery Playbook details: https://secure-delivery.playbook.ee/ ### DevSecOps - London Gathering ### https://dso-lg.com https://dso-overflow.com Also follow us on Twi...

Ep03: Experimenting with and adopting AWS Lambda (Matthew Joyce) 17.05.2020

In this episode, Matthew Joyce shares his experience with taking on AWS Lamdba for one of his projects. Matthew's details: https://www.linkedin.com/in/matthew-joyce-1301772/ ### DevSecOps - London Gathering ### https://dso-lg.com https://dso-overflow.com Also follow us on Twitter: @DevSecOps_LG

Ep02: Passing a DSO Online Course (Emily Young) 10.05.2020

In this episode, I speak to Emily Young who has embarked on the Certified DevSeOps Professional online course and the gruelling twelve hour exam. Emily's details: https://www.linkedin.com/in/emily-young-a3a77255/ @Ra1nb0wAn4lyst ### DevSecOps - London Gathering ### https://www.meetup.com/DevSecOps-London-Gathering/ Also follow us on Twitter: @DevSecOps_LG

Ep01: terraform-compliance with Emre Erkunt 24.11.2019

In this episode I have the pleasure of talking to Emre Erkunt - he is an independent consultant and the founder of an opensource project called Terraform-Compliance.  Look out for the black falcon logo.  Stickers available in our next Gathering. Emre's details: https://terraform-compliance.com/ @3rkunt ### DevSecOps - London Gathering ### https://www.meetup.com/DevSecOps-London-Gathering/ Als...

Listen to the DSO Overflow podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.