Reimagining Security Engineering using Semgrep and OPA | Rohit Salecha
In today’s rapidly evolving technology landscape, ensuring the security of modern applications is a daunting task. With code running on containers in cloud environments, security engineers face the challenge of protecting not just the application itself but also its underlying infrastructure. Manual evaluation of security vulnerabilities is impractical given the volume and complexity of changes constantly being made. This is where tools like Semgrep and OPA (Open Policy Agent) come into play, providing the capability to identify and mitigate security risks proactively. Security engineers are tasked with observing changes in four critical aspects of modern applications: code, containers, clusters, and cloud environments. Their responsibility is to ensure the confidentiality, integrity, and availability (CIA) triad is not compromised. While change is constant, security teams must not act as gatekeepers, which can slow down development processes. Instead, they should leverage automated to
Reimagining Security Engineering using Semgrep and OPA Rohit Salecha Last updated on Oct 20, 2024 4 min read Security Security Engineering In today's rapidly evolving technology landscape, ensuring the security of modern applications is a daunting task. With code running on containers in cloud environments, security engineers face the challenge of protecting not just the application itself but also its underlying infrastructure. Manual evaluation of security vulnerabilities is impractical given the volume and complexity of changes constantly being made. This is where tools like Semgrep and OPA
Explore this link on the map →related reading
- Defining A Software Supply Chain Security Platform & Exploring New Techniques, Part 2softwareanalyst.substack.com
- Project Glasswing: Securing critical software for the AI era \ Anthropicanthropic.com
- Security incident disclosure — July 2026huggingface.co
- Report: Taking The Fight To The Cloud | A Contrary Research Deep Dive | Contrary Researchresearch.contrary.com
- Report: Taking The Fight To The Cloud | A Contrary Research Deep Dive | Contrary Researchresearch.contrary.com
- Our Approach to Building Security Tooling | Latacoralatacora.com
- Top 22 Docker Security Best Practices: Ultimate Guideaquasec.com
- State of DevSecOps | Datadogdatadoghq.com
- What is container threat detection? | Sysdigsysdig.com
- Best practices for creating custom detection rules with Datadog Cloud SIEM | Datadogdatadoghq.com
- Cloud Detection & Response: Simplifying Cloud Securityarmosec.io
- Container Threat Detection and Response for AWS Fargate with Sysdig | AWS Partner Network (APN) Blogaws.amazon.com