search menu icon-carat-right cmu-wordmark

Are We Forever Doomed By Software Supply Chain Risks?

Presentation
This session was presented by Steve Kinman of Snyk at DevSecOps Days Pittsburgh, held virtually April 27, 2022.
Publisher

Software Engineering Institute

Subjects

Watch

Abstract

The adoption of open-source software continues to grow and creates significant security concerns for everything from software supply chain attacks in language ecosystem registries to cloud-native application security concerns. In this session, we will explore how developers are targeted as a vehicle for malware distribution, how immensely we depend on open-source maintainers to release timely security fixes, and how the race to the cloud creates new security concerns for developers to cope with, as computing resources turn into infrastructure as code.

Steve Kinman is a dedicated technology leader, with 20+ years of innovative compliance-driven security strategy knowledge and the ability to deliver scalable, principle-based security and privacy programs focused on business requirements. Most recently, he led a security program transformation at Zalando SE in Berlin, Germany, joining as the first CISO for the now Dax listed publicly traded company in 2018 to help solve GDPR challenges. Kinman is currently the Field CISO of Snyk, a developer-first security platform.

Download the graphic recording.