Security for High Velocity Engineering
Editor’s note: I’m super excited to share this post by Jason Chan. If you’re not familiar, Jason was the VP of InfoSec at Netflix for many years, building the security culture that’s led to countless great conference talks about building scalable security programs, coining terms like Paved Road, and more. You can also watch an interview I did with Jason here. Enjoy! -Clint This blog is based off Jason's keynote at LocoMocoSec 2024. I retired in 2021 after spending twenty plus years in security, with most of that time focusing on what I think is one of the most interesting and challenging problems in our field - collaborating with engineering teams to build and operate secure software. The time away has given me a chance to reflect - what worked, what didn’t work, what I would have changed. I’m now combining my experience and those reflections to provide my best current guidance on how to build a security program to work effectively with high velocity engineering organizations. I got st
Security for High Velocity Engineering 0 tl;dr sec Posts Security for High Velocity Engineering Security for High Velocity Engineering Strategy and Tactics for Protecting and Enabling Modern Software Organizations Jason Chan May 13, 2025 Editor’s note: I’m super excited to share this post by Jason Chan . If you’re not familiar, Jason was the VP of InfoSec at Netflix for many years, building the security culture that’s led to countless great conference talks about building scalable security programs, coining terms like Paved Road, and more. You can also watch an interview I did with Jason here
related reading
- High-Leverage Security Engineering Tasksfranklyspeaking.substack.com
- The Future Application Security Engineergyan.ca
- Challenges in Security Engineering Programsventureinsecurity.net
- The rise of security engineering and how it is changing the cybersecurity of tomorrowventureinsecurity.net
- Writing an engineering strategy. | Irrational Exuberancelethain.com
- The Letter - Stop Hacklore!hacklore.org
- Building practitioner-focused cybersecurity: nine principles for founders and product leadersventureinsecurity.net
- Why I Ignore The Spotlight as a Staff Engineer - Lalit Magantilalitm.com
- 'Inside Security' with Andreas Haugsnes (Ex-Chief Security Architect at Unity Technologies)leen.dev
- Panther Labs' Jack Naglieri on Cloud-Native SIEM and Self-Growthmadrona.com
- Scaling with common sense #2: Being future ready. - Zerodha Tech Blogzerodha.tech
- Most of the security teams’ work has nothing to do with chasing advanced adversariesventureinsecurity.net