Topics: Technology
**Jacob DePriest** (0:00)
Internal security teams are starting to become a business differentiator as well for companies. So how your security team approaches threat actors, be they nation state or crypto miners or whatever it is, and how they talk about it, how they disclose it, what's the tone in the blogs, how quick is it, how transparent is it. Like these things are starting to become not just nice to haves, but expected from security teams and start to be things that like, if you're evaluating a set of vendors for, you know, a choice to come help you out, you start to think about like, well, how are they approaching this? How do they tackle the security challenges and how do they think about it? And is that a team I want to partner with when things go bad? Because something's gonna go bad.
**Conor Bronsdon** (0:42)
At some point.
**Jacob DePriest** (0:43)
And who are you gonna partner with to do it, right? And so I think that's an interesting trend that I think we're seeing as well.
**Conor Bronsdon** (0:48)
Is your engineering team focused on efficiency, but struggling with inaccessible or costly Dora metrics? Insights into the health of your engineering team don't have to be complicated or expensive. That's why Linear B is introducing free Dora metrics for all. Say goodbye to spreadsheets and manual tracking or paying for your Dora metrics.
Linear B is giving away a free, comprehensive Dora dashboard packed with essential insights, including all four key Dora metrics tailored to your team's data, industry standard benchmarks for gauging performance and setting data-driven goals, plus additional leading metrics, including merge frequency and pull request size. Empower your team with the metrics they deserve. Sign up for your free Dora dashboard today at linearb.io/dora, or follow the link in the show notes.
Hey everyone, welcome back to Dev Interrupted. I am your co-host, Conor Bronsdon, and I'm delighted to be joined by Jacob DePriest. He is the VP and Deputy Chief Security Officer at GitHub. Jacob, welcome to Dev Interrupted.
**Jacob DePriest** (1:45)
Yeah, thanks for having me. I'm really excited to talk to you today.
**Conor Bronsdon** (1:47)
It's gonna be a lot of fun. I've heard some incredible things, like you helped protect us from North Korean hackers. You spent 15 years at the NSA before your work at GitHub on the security side of things. And there's such an evolving threat area in this space currently and also opportunity. So very excited to dive in.
And GitHub is obviously a company that needs no introduction to our audience. It's home to over a hundred million developers and you're really responsible for leading the teams that keeps the platform, product and users, as well as customers safe. So I know you started that DevSecOps career long before GitHub with the NSA. And because of that experience, you're kind of the perfect person to talk to about how AI and these other trends are impacting the security space.
You're joining us today live here at DevOps Enterprise Summit. If you're watching on YouTube, I highly recommend it. We're here in the Dev Interrupted Dome. It's ton of fun.
And you also gave a presentation, I believe today, on how AI is impacting developers through capabilities like GitHub Copilot, how AI is evolving the security space and suggestions on how to move security into an AI assisted future. So I mean, that's the hot topic, right? Let's just dive in right there. Tell us about your talk.
**Jacob DePriest** (2:52)
Yeah, so we started today talking about how DevOps and security really mix together and need to happen together, right? We can't have security without DevOps.
As we think about the biggest security challenges that a lot of companies are facing, a lot of them tie back to the software development process, developer accounts, account security. They tie to supply chain, right? It's not just an easy way to point and say, like, there's this one area we got to focus on. It's the whole thing.
And so today we talked through how all those things fit together. And then a little bit of GitHub's journey, a little bit of my journey, and then how now that we have things like GitHub Advanced Security at GitHub, we've really been pushing to shift security left in the developer workflow. What's that look like now in 2023 and beyond as we're integrating AI into many aspects of the software development lifecycle?
**Conor Bronsdon** (3:48)
Yeah, I'll share, I previously worked in the Microsoft Services Organization on the cybersecurity, particularly around the thought leadership of what's coming trend-wise. And it's so interesting for me, having left that org four or five years ago now, to see these trends that we were seeing, the research that we were seeing, the things that people are thinking about start to be really real, particularly with AI, Copilot, all these new things coming out of GitHub.
35 more minutes of transcript below
Thousands of transcripts fetched by people building searchable podcast archives
Try it now — copy, paste, done:
curl -H "x-api-key: pt_demo" \
https://spoken.md/transcripts/1000651996090
Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.
From $0.10 per transcript. No subscription. Credits never expire. Prices exclude VAT, added at checkout for EU customers. Not what you expected? Email us within 14 days with 20 or fewer credits used and we refund the pack in full.
Using your own key:
curl -H "x-api-key: YOUR_KEY" \
https://spoken.md/transcripts/YOUR_EPISODE_ID