Netflix’s Dan Cao and Brex’s Josh Liburdi on Balancing Big Platforms and Bespoke Tools
Aug 20, 2024
auto_awesome
Dan Cao is the Engineering Manager of Security Incident and Response at Netflix, and Josh Liburdi is a Staff Security Engineer at Brex. They dive into the shift toward developer-centric security operations and the challenge of balancing big platforms with bespoke tools. The importance of critical thinking and foundational skills in cybersecurity is emphasized. They share strategies for building resilient security teams through effective mentorship and culture, highlighting the need for adaptability in our ever-evolving tech landscape.
The podcast highlights the necessity for security teams to focus on foundational skills and critical thinking for effective response operations.
It discusses the shift towards bespoke security solutions that align with unique organizational needs, moving away from generic vendor offerings.
Deep dives
The Importance of Tailored Security Solutions
There is no universal security strategy that fits all organizations; each entity must assess its unique needs and capabilities. Security engineering leaders often face vendors promising one-size-fits-all solutions, yet these rarely address the specific challenges that diverse teams encounter. The fundamental differences in team size, budget, and intellectual property protection underscore the need for customized approaches to security. As a result, organizations should focus on understanding their specific context and building layers of defense that correspond to their individual security landscape.
Building a Competent Security Team
The composition and skill set of a security team determine its effectiveness in response and detection operations. It is essential to prioritize foundational knowledge over reliance on specific tools, as understanding the basics fosters adaptability within the team. Inheriting a team with mixed skill levels means leaders must identify strengths and gaps, allowing for ongoing development and cross-training. By investing in analytical mindsets and supporting team members in honing their skills, security teams can be more effective and resilient against evolving threats.
The Rise of Developer-Centric Security Practices
Security practices are increasingly leaning towards a developer-oriented approach, driven by the need for agility and customization. As new security challenges emerge, many organizations are moving away from generic vendor solutions and opting for bespoke tools that cater specifically to their environments. This shift is indicative of a market that favors tailored solutions, which can better match the unique technology stack of individual companies. However, large organizations still see a need for dependable, existing frameworks and may prefer adopting comprehensive platforms for their broader capabilities.
Navigating Innovation in Security Technology
The security technology landscape is constantly evolving, yet many vendors often repeat existing solutions rather than truly innovating. Concepts like EBPF (Extended Berkeley Packet Filter) have existed for years but are only now being fully utilized for security enhancement, showing a lag in the adoption of technically sound practices. As security teams seek more sophisticated monitoring and detection systems, identifying tools that genuinely innovate and address current gaps is crucial. The challenge lies in balancing trusted solutions with the need for novel technologies that can effectively adapt to contemporary security threats.
In this special episode of Detection at Scale, Jack welcomes security experts Dan Cao, Engineering Manager of Security Incident and Response at Netflix, and returning guest Josh Liburdi, Staff Security Engineer at Brex. They discuss the rise of developer-centric security solutions and the ongoing balance between utilizing big platforms like CrowdStrike and bespoke tools — the build versus buy dilemma.
They highlight the importance of fundamental skills and critical thinking in security engineering, emphasizing the need for continual learning and adaptability. Dan and Josh also share insights on building effective security teams and the significance of mentorship and team culture in fostering innovation and resilience in an evolving tech landscape.
Topics discussed:
The shift towards security operations and incident response that prioritize developer involvement and custom coding solutions.
How to effectively integrate large security platforms like Crowdstrike with tailored, in-house security tools.
The need for critical and abstract thinking skills in security engineering to solve complex problems.
Strategies for leveraging team strengths and addressing skill gaps to create robust security teams.
The role of mentorship and a positive team culture in fostering growth and innovation within security teams.
The importance of mastering the basics of technology and cybersecurity as a foundation for advanced problem-solving.
The need for security professionals to stay adaptable and continually update their skills in a rapidly evolving tech landscape.
The difficulties small security teams face when managing and integrating diverse security tools and platforms.
The effectiveness and limitations of using commercial security solutions for large and small organizations.