Security Compass

Threat Modeling Unleashed

Education EN ↓ 91 episodes

Security Compass, a leading provider of cybersecurity solutions and advisory services, enables organizations to adopt balanced development automation for rapid and secure application development. With their flagship product, SD Elements, the company helps automate significant portions of proactive manual processes for security and compliance that improves time to market for new technology. In addition, they offer advisory services on how organizations can embrace emerging technologies like cloud to strengthen their security posture. Security Compass is the trusted solution provider to leading...

Author

Security Compass

Category

Education

Podcast website

podcast.securitycompass.com

Latest episode

Dec 2, 2025

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Sesh Vaidyula & Harvey Nusz - Impact of CMMC on Organizations 11.12.2020

Today we are joined by Altaz Valani from Security Compass, Sesh Vaidyula , Partner at Templar shield, and Harvey Nusz , Principal at 4IT Security, Governance & Compliance, in our second podcast about CMMC we will talk about what it means for DoD vendors. We will discuss the transformational leadership role that the DoD has as they work toward a more secure supply chain. We will conclude by discuss...

Sesh Vaidyula & Harvey Nusz - Understand the CMMC 04.12.2020

Today we are joined by Altaz Valani from Security Compass, Sesh Vaidyula , Partner at Templar shield,  and Harvey Nusz , Principal at 4IT Security, Governance & Compliance, in our second podcast to talk about CMMC. We will talk about what CMMC means to DoD suppliers around building maturity. We will then discuss the transformational leadership role that the DoD has as they work toward a more secur...

Wendy Murphy - Insights from CMMC Center of Excellence 30.11.2020

Today we are joined by Altaz Valani from Security Compass and Wendy Murphy , Chair - Events & Outreach Working Group for CMMC Center of Excellence, to talk about their mission and then dive deeper into the common challenges organizations face with CMMC. We will conclude by talking about where the CMMC CoE is headed in the future. Given the importance of CMMC and its implications for ensuring secur...

Ayhan Tek - How a Security Executive Can Help Accelerate Software Development 27.11.2020

Today we are joined by Altaz Valani from Security Compass and Ayhan Tek , VP of Information Security at Cyber Electra, to talk about how a security executive can enable speed to market in software development. Competition adds a lot of pressure to deliver software products faster which is why we will explore how a senior security executive can enable the business to keep moving fast instead of bei...

Rohini Narasipur - Build a Product Security Program 23.11.2020

Today we are joined by Altaz Valani from Security Compass and Rohini Narasipur, Product Security Engineer at Bosch, to talk about what makes product security different from software security. With the convergence of software and hardware, it has become important to understand how software and hardware security processes can integrate with each other. To conclude, we get some forward-looking insigh...

David Fairman - Convergence of Cyber Physical Systems 20.11.2020

Today we are joined by Rohit Sethi from Security Compass and David Fairman , Chief Security Officer at Netskope, to understand the concept of cyber-physical systems and how these are transforming the way we interact with engineered objects and infrastructure. We will also delve into the security concerns for cyber-physical systems as these play an increasingly vital role in critical infrastructure...

Arun Prabhakar - The Difference Between Product and Software Security 16.11.2020

Today we are joined by Altaz Valani from Security Compass and Arun Prabhakar , Security Consultant at Security Compass, to talk about product security. We start by talking about both product and software security, where there are similarities and differences. We then turn the conversation to look at quality and the categories of metrics that help make secure products. At the end of our discussion,...

DJ Schleen - Using Technology to Enhance DevSecOps 13.11.2020

Today we are joined by Pranoy De and Michael Bolger from Security Compass and DJ Schleen , Senior Manager of Software Security at Rally Health, to talk about how we can leverage technology to enhance DevSecOps practices. In this podcast, we delve into the details of technology and automation tools that are essential for setting up a robust DevSecOps program, with specific emphasis on the Healthcar...

Enabling Both Speed and Security 09.11.2020

Today we are joined by Pranoy De, Eleonor Lee, and Altaz Valani from Security Compass, to talk about three DevSecOps challenges from a technical leader’s perspective: integrating security into DevOps pipelines; building a knowledge retention and training model that balances speed and security; and the convergence of business and IT. In all cases, security has a key role to play in enabling the bus...

Spencer Koch - An Executive Perspective on Agile Security 02.11.2020

Today we are joined by Altaz Valani from Security Compass and Spencer Koch , Offensive Security Professional at Reddit, to talk about Agile Security in technology companies from an Executive’s perspective. We would start with the question — Why does the business think security gets in the way of being agile — and discuss how a security executive can start to change this perception. As with any cha...

Purnima Bihari - Managing Speed and Security in Your DevOps Product Lifecycle 30.10.2020

Today we are joined by Altaz Valani from Security Compass and Purnima Bihari , Product Owner at Security Compass, to talk about how managing a fast moving product delivery lifecycle while ensuring security is a challenging task. Purnima will share insights from her experience about the role a product owner plays in injecting security early into the product lifecycle and the impact being a security...

Nicolas Chaillan - The Introspection of Building Software Quickly and Managing Security & Compliance Risks 26.10.2020

Today we are joined by Rohit Sethi from Security Compass and Nicolas Chaillan, Chief Software Officer, U.S. Air Force, to gain insights into building a DevSecOps program for a large government organization. In this podcast, we will talk about the challenges, key considerations, and the need to balance security with fast delivery cycles in the defense world. We will also cover the program structure...

Bob Aiello - Operationalizing Security in DevOps 23.10.2020

Today we are joined by Altaz Valani from Security Compass and Bob Aiello , DevOps architect and trainer with decades of experience leading enterprise software process improvement initiatives. We will start by asking the question, “Why do so many organizations struggle with integrating security into DevOps?” Since automation is a key part of DevOps, we will discuss security practices that are easil...

Spencer Koch - Maintain Your Security Through Application Modernization 19.10.2020

Today we are joined by Altaz Valani from Security Compass and Spencer Koch, Security Wizard at Reddit, to discuss the role of security in Application Modernization. In today’s digital world, businesses have to modernize their applications routinely. In this podcast, we will discuss current trends and security challenges around application modernization; and how security can help minimize the risk....

Jeff Sorrell - An Industry Perspective on CMMC 16.10.2020

Today we are joined by Altaz Valani from Security Compass and Jeff Sorrell , a Data Privacy and Information Security Consultant. We will discuss, at a high level, the importance of Cybersecurity Maturity Model Certification (CMMC) and its operational impact on companies that have contracts with the U.S. Department of Defense. We dive into some of the nuances of CMMC as it advocates moving away fro...

Andrew Wertkin - Where Application Security Meets Infrastructure Security in Cyberspace 09.10.2020

Today we are joined by Ehsan Foroughi from Security Compass, and Andrew Wertkin , Chief Strategy Officer at BlueCat. In this podcast, we will discuss the intersection of network infrastructure and security, and how to bake security requirements from that perspective. Drawing from his experience in enterprise architecture and distributed computing networks, Andrew will also share valuable security...

Hasan Yasar - Achieve Continuous ATO Through DevSecOps 05.10.2020

Today we are joined by Hasan Yasar, Technical Director of Continuous Deployment at the Software Engineering Institute, CMU, to talk about Continuous ATO. We will start with the need to automate architectural assurance across the application build and deployment pipeline. Further, we will discuss how risk management is embedded into the process through security controls. Finally, we will conclude w...

Brian Pitts - Adoption of SD Elements 02.10.2020

In this podcast, we are joined by Brian Pitts , Director, Product Security Governance at Johnson Controls (JCI) to discuss some of the unique security challenges faced by IOT device manufacturers and how advanced tooling has helped JCI bolster their product security practices.

Glen Notman - Bridging the Gap Between Security and Business Teams 25.09.2020

Today we are joined by Glen Notman , Associate Partner at Citihub. In this podcast, we will talk about the gap that exists between the security and business teams. To communicate the value of security, it’s important for security teams to make their findings and recommendations relevant to the business. This involves empathizing with the real needs of a business stakeholder.

Gopi Reddy - Enabling Digital Through Secure DevOps 21.09.2020

Today we are joined by Gopi Reddy who is an experienced Enterprise Architect. We will talk about digital transformation and how DevOps enables the business imperative. Security is often not considered a key part of this transformation because of the perception that it is a low-level technical activity. With the shift to digital product enablement in a high velocity environment, this is now changin...

Ruth G. Lennon - First Steps in Building Proactive Security 18.09.2020

Today we are joined by Ruth G. Lennon , Lecturer, Department of Computing at the Letterkenny Institute of Technology, to talk about initiating the journey of injecting security into development. Many teams feel enormous pressure from the start to quickly understand security. In this podcast, we delve into taking a more thoughtful and deliberate approach that focuses on building a strong foundation...

Nikhil Kumar & Altaz Valani - Feasibility of Zero Trust 14.09.2020

Today we are joined by Altaz Valani from Security Compass and Nikhil Kumar , President, and Founder of ApTSi, to discuss the feasibility of Zero Trust. In this podcast, we will talk about the value of Zero Trust from a business enablement perspective. We will also dive into the feasibility of Zero Trust for technical leaders. While Zero Trust is not a silver bullet, for today’s rapidly evolving bu...

Stephen Whitlock & Altaz Valani - Rolling Out Zero Trust 11.09.2020

Today we are joined by Altaz Valani from Security Compass and Stephen Whitlock , one of the first members of the Jericho Forum and a security expert with 16 years of experience at Boeing. In this podcast, we will discuss the evolution of Zero Trust and its roots in the Jericho Forum work. We will also talk about the business value of Zero Trust and the pitfalls of rolling out a Zero Trust program....

Tony Carrato & Altaz Valani - Business Value of Zero Trust Compared to Other Security Models 08.09.2020

Today we are joined by Altaz Valani from Security Compass and Tony Carrato, an independent consultant with expertise in delivering enterprise architecture across varied industries. In this podcast, we will discuss the evolution of the Zero Trust security model and how it is different from existing models. We will also delve into the business value that Zero Trust can offer organizations in the mid...

Ehsan Foroughi - Importance of Security Culture 04.09.2020

Today we are joined by Ehsan Foroughi , Head of Products at Security Compass, to talk about the importance of a security culture in an organization. In this episode, he will explain how the effectiveness of any application security program is impacted by the security culture across teams. Citing examples from his personal experiences, he delves into the human factor in security and how strong orga...

Listen to the Threat Modeling Unleashed podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.