Diving Into DevSecOps with John Willis of Red Hat artwork

Diving Into DevSecOps with John Willis of Red Hat

Dev Interrupted

March 3, 2021

DevSecOps is one of those buzzwords that can mean a lot of things or nothing at all. But where DevOps helped us gain a more holistic understanding of our delivery pipeline, DevSecOps does the same for our security efforts.
Speakers: Dan, John Willis

Topics: Technology

**Dan** (0:02)
Where Dev Ops helped us gain a more holistic understanding of our delivery pipeline, DevSecOps does the same for our security efforts.
Over the next two episodes of Dev Interrupted, I explore what DevSecOps actually means to dev teams and how to implement the practice. My guest during this journey is John Willis, co-author of the Dev Ops Handbook, Speaker and the Senior Director of Global Transformation at Red Hat.

**SPEAKER_3** (0:32)
This episode is sponsored by Linear B. Give your dev team the power to improve with team-based metrics, high-risk code alerts and the world's first project board based on real-time Git activity.
Sign up free at linearb.io.

**Dan** (0:46)
John, awesome to have you on the show today.

**John Willis** (0:49)
Hey Dan, yeah, thank you.

**Dan** (0:50)
Thanks for inviting me. For sure, and let's just dive right into it.
Can you tell us what is DevSecOps to you?

**John Willis** (1:02)
Yeah, it's funny that, so there's always been obviously discussion around security in DevOps, right? So we're going to the history DevOps, right? But I honestly believe, and I get pushback from friends actually say, well, John, don't you remember 2013 DevOps days? Austin and I talked about security and operations and Dev, but Shannon Leets, who's over in Intuit, who's really one of my primary mentors on all these things related to DevSecOps or security, she's just like insanely awesome, and you should get her on the podcast, but she coined the term, right? Like it's a big deal, but it is a big deal. Like she literally created a website, so this is thing DevSecOps, everybody got all upset and mad, and because even myself, I didn't get upset, but it wasn't until I got to meet her, where I'm like, go argue with her, not me. Yeah, you wouldn't argue with her, like then you win.
But she just sort of put a stake in the ground on it, and the obvious thing that like, a lot of us fought it, right? Because we said, I've been part of this when sort of Adrian Karkroff, when he was at Netflix, started this no ops nonsense, and Adrian's a beautiful, great man, but it was nonsense to do this no ops, right? Now we've always had this, well, why can't we call it Mar DevSec, Mar this, that? And I'm like, no, stop it. It's a metaphor. It's Dev and Ops. It's a metaphor for collaboration and change. And then all of a sudden this DevSec Ops come on, and I'm like, here we go again. Somebody trying to rename to own the name. But when you got to meet Shannon and you read the sort of literature, and then you just went back and looked at the problem is, we went almost like maybe eight, nine years of sort of ignoring security. So all of us like DevOps people patting ourselves on the back and like, we're so awesome. I wrote this book. No, I wrote that book. Like I used to do a presentation where I'd say, I take the mic and I take my hat, I throw it on the floor and I go, God, darn it, we forgot security.
And a lot of people argue that we didn't, but in the aggregate, if you go back and look at prior to like 2017, almost every presentation, there was very little discussion. And one more piece, I was talking to a high level executive at a really large entertainment company. Everybody knows. He was very savvy on DevOps, speaks around the world. And it was probably around 2017, as I mentioned the word DevSecOps, and he leaped out of his chair.
No, I want to hear more about this. You know what I thought? You know what?
If you want to argue about the word, meet me after my session on the left-hand side of the road, because I won't be there. I'll be on the right-hand side of the room talking about how do we move forward. You know, and so I think the word, I think it will lose its efficacy over time.
We can talk about that. But I think it was a point in time that the word was necessary to be used to shock the system.

**Dan** (4:07)
So John, a lot of the listeners on our podcast are either, you know, engineering team leaders or, you know, directors of engineering, people that are kind of close to the development, the day-to-day development. How would you describe how DevSecOps relates back to kind of the team level?

**John Willis** (4:30)
Yeah, yeah, no, I like this question. You know, early days, just sort of DevSecOps, people would say, John, come in and look at my pipeline, and they'd show me like they were doing a vulnerability scanning, and that's it.

22 more minutes of transcript below

Thousands of transcripts fetched by people building searchable podcast archives

Feed this to your agent

Try it now — copy, paste, done:

curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire. Prices exclude VAT, added at checkout for EU customers. Not what you expected? Email us within 14 days with 20 or fewer credits used and we refund the pack in full.

Using your own key:

curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/YOUR_EPISODE_ID