Cloud Security Podcast

Incident Response of Kubernetes and how to Automate Containment

24 snips
Oct 10, 2025
Damien Burks, a Senior Security Engineer with a wealth of experience in fintech environments, dives into the complexities of incident response for Kubernetes. He explains the challenges of automation in containment for private EKS clusters, revealing why traditional tools often fall short. Damien shares his innovative solution using a dynamically deployed Lambda function that can contain breaches within ten minutes. The conversation also highlights the evolving role of the cloud security engineer and essential career advice for aspiring professionals.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ANECDOTE

From AppSec To Cloud IR Platform Builder

  • Damien built an incident response platform in financial services and later moved into senior roles at fintech companies.
  • He also runs DevSecBlueprint and creates content to help others enter DevSecOps.
INSIGHT

Detection Without True Automated Response

  • Many CNAPPs and runtime tools detect issues but lack deep automated response capabilities for complex environments like private EKS.
  • This gap makes automation the hardest and most important unsolved part of cloud incident response.
ANECDOTE

Automated Lambda-Based Containment

  • Damien automated containment for a private EKS cluster by dynamically deploying a Lambda into the cluster VPC to run kubectl commands.
  • The automation reduced containment time from hours to roughly ten minutes in a regulated environment.
Get the Snipd Podcast app to discover more snips from this episode
Get the app