Wednesday Jun 14, 2023

EP 35 — Streamlining and Accelerating Your Product Security with iHerb’s Mike de Libero

In this episode of the Future of Application Security, Harshil speaks with Mike de Libero, Director of Product Security at iHerb, an online health and wellness shop. They discuss the ways in which automation helps lighten the workload and creates more consistency, when you need to hire someone for security automation, and what to look for when scaling visibility. They also discuss how the role of product security has evolved, the benefits and drawbacks of today's tools, and how to build more effective remediation.

Topics discussed:

  • How to implement automation to lighten the load of product security engineers and to create a more consistent experience for everyone.
  • What to look for and what questions to ask in order to scale your visibility.
  • How to know if it's the right time to hire someone for security automation — and why you should borrow someone from the dev team first.
  • How product security has changed over the years, including its shift from testing and finding issues to building libraries, controls, and frameworks to help dev teams push code out quicker.
  • How to group classes of security issues in order to streamline remediation, and how Mike's team went from 1900 tickets to 30 with this practice.
  • How Mike's background as a programmer gives him more understanding and empathy in his role as Director of Product Security at iHerb, LLC.
  • What Mike learned about product security at different companies in the past, including Salesforce, Microsoft, Uber, and Unity.

 

Comments (0)

To leave or reply to comments, please download free Podbean or

No Comments

Copyright 2022 All rights reserved.

Podcast Powered By Podbean

Version: 20240731