Dev Interrupted

How Marketing Ruined Shift Left | Semgrep’s Tanya Janca

5 snips
Apr 15, 2025
Tanya Janca, a cybersecurity expert with 28 years of experience and author of "Alice and Bob Learn Secure Coding," sheds light on the pitfalls of treating security as an afterthought. She emphasizes the need to redefine security as an ongoing practice rather than a final gate. Tanya shares insights on enhancing developer empowerment through clear guidelines and internal knowledge libraries. The conversation also touches on the evolving relationship between AI integration and security, advocating for continuous learning and critical evaluation of AI-generated code.
Ask episode
AI Snips
Chapters
Books
Transcript
Episode notes
ANECDOTE

Late Security Checks

  • Tanya Janca recalls early security practices as disruptive and frustrating for developers.
  • Security checks often occurred right before release, creating conflict and rushed work.
INSIGHT

Shift Left Misinterpretation

  • "Shift left" was meant to integrate security earlier in the development lifecycle.
  • However, marketing misused it, promising effortless security with tools alone.
ADVICE

Early Security Integration

  • Start with clear security requirements and technical guidance for each project type.
  • Empower developers with tools and ownership of security testing, improving collaboration.
Get the Snipd Podcast app to discover more snips from this episode
Get the app