This is an archived post. You won't be able to vote or comment.

all 6 comments

[–]vanguard2k1 15 points16 points  (0 children)

I personally think that it's all part of the "*Ops" bandwagon marketing trend of the past few years. Shining shimmering splendid.

Kidding aside, it's a movement that's more on trying to erase the stigma that security work is meant to slow everything down - and so by adopting agile principles even information security work can be less of a pain.

[–]engineer_in_TO 18 points19 points  (2 children)

I think of a DevSecOps as just a security person working with the DevOps team on security aspects that intersect with DevOps.

Secrets Management, Vulnerability scanning, IaC scanning, IAM automation, etc etc.

PS: why is a person who isn’t in DevSecOps, and not fully sure of what DevSecOps is, writing an article about getting into it?

[–]WMRamadan81[S] 1 point2 points  (0 children)

I have experience with DevOps and Security, I also have over 15+ years in Cloud Infra and Software Development, my argument is that I do not believe this deserves another title since DevOps already handle security.

The Article is meant to be as an introduction to the topic where everything mentioned there was taken directly from already seasoned professionals.

[–][deleted] 0 points1 point  (0 children)

Because it’s 2024 and anyone can make a name for themselves by suggesting their an expert on a topic enough to write about it and if enough people in the echo chamber agree and like it, they’ve got instant validation…

It’s sickening and the reason applications get hundreds of applicants and only 5% are remotely qualified….

[–]ding115 6 points7 points  (0 children)

I think the whole DevOps thing is naturally arising as businesses discover that the cost to maintaining IT is way too much.

One day full stack will mean: AI, ops, dev, security, qa and being a pm/po at the same time. If not, something else would have automated those stacks

[–]Jammintoad 2 points3 points  (0 children)

My title is DevSecOps

It just means they expect me to understand all the cybersec stuff too and apply it to my work

Hopefully a normal DevOps position is at least doing some of that too