Log in

goodpods headphones icon

To access all our features

Open the Goodpods app
Close icon
BrakeSec Education Podcast - 2019-041-circuitswan, diana initiative, diversity initiatives at conferences

2019-041-circuitswan, diana initiative, diversity initiatives at conferences

11/21/19 • 38 min

BrakeSec Education Podcast

Diana Initiative

@circuitswan

https://www.dianainitiative.org/

https://twitter.com/DianaInitiative

Conference in Las Vegas (Aug 6-7, 2020) (Thu & Fri)

[email protected]

Topics

  1. Diana initiatives
    1. Past
      1. 2015 - idea at defcon 23
      2. 2016-17-18 growing but got too big!
      3. 2019 got our own space, ~800 tickets
      4. 2020 plans-westin again, 2 speaking tracks and 1 workshop track, solder village, career village, CTF, lock picking
      5. Mentoring both CFP and presenters this year! (expansion from last year)
      6. student scholarship (we want to double the amount of money, target still 10)
      7. Free tickets (expansion over last year)
    2. Present
      1. Slogan contest 2020
      2. I don’t want to think about 2021 yet :)
    3. Future
      1. Mentors
      2. Reviewers
      3. Volunteers
      4. Donations (giving tuesday, scholarships)
    4. Needs/wants
  2. Discuss how to add more DNI into your event (conference, meetup, slack, etc)
    1. Women in Technology Diana 2018
    2. https://business.linkedin.com/talent-solutions/blog/job-descriptions/2018/5-must-dos-for-writing-inclusive-job-descriptions
    3. https://www.hudsonrpo.com/rpo-intelligence/recruitment-process-outsourcing/how-to-write-an-inclusive-job-description/
    4. https://www.refinery29.com/en-us/2017/04/148547/how-to-get-a-raise-chatbot-cindy-gallop
  3. Better job descriptions
  1. We are responsible for baking Sec into DevOps and hence write the red team software (well integrate in most cases) for your appsec team if your devs are using GitLab. We have a security team that secures GitLab itself but that's not us. We have SAST, DAST, Dependency, Secret Detection and License Compliance baked into our paid tier, and SAST is coming down to the free tier! I’m pitching a talk about tuning to shmoocon because it seems like that's the most common question I got as a result of my devsecops talks at derbycon / shellcon / bsidesdc.
    1. N.Schwartz: Are you ready to leverage DevSecOps? BSidesDC 2019

2019 ShellCon Tuneup Tips for Your CV and Profile, From an Interviewer

SE Village Con - Thu, Feb 20 - Sat, Feb 22 | Hilton Orlando Buena Vista Palace

Layer8conf - https://www.workshopcon.com/events

http...

plus icon
bookmark

Diana Initiative

@circuitswan

https://www.dianainitiative.org/

https://twitter.com/DianaInitiative

Conference in Las Vegas (Aug 6-7, 2020) (Thu & Fri)

[email protected]

Topics

  1. Diana initiatives
    1. Past
      1. 2015 - idea at defcon 23
      2. 2016-17-18 growing but got too big!
      3. 2019 got our own space, ~800 tickets
      4. 2020 plans-westin again, 2 speaking tracks and 1 workshop track, solder village, career village, CTF, lock picking
      5. Mentoring both CFP and presenters this year! (expansion from last year)
      6. student scholarship (we want to double the amount of money, target still 10)
      7. Free tickets (expansion over last year)
    2. Present
      1. Slogan contest 2020
      2. I don’t want to think about 2021 yet :)
    3. Future
      1. Mentors
      2. Reviewers
      3. Volunteers
      4. Donations (giving tuesday, scholarships)
    4. Needs/wants
  2. Discuss how to add more DNI into your event (conference, meetup, slack, etc)
    1. Women in Technology Diana 2018
    2. https://business.linkedin.com/talent-solutions/blog/job-descriptions/2018/5-must-dos-for-writing-inclusive-job-descriptions
    3. https://www.hudsonrpo.com/rpo-intelligence/recruitment-process-outsourcing/how-to-write-an-inclusive-job-description/
    4. https://www.refinery29.com/en-us/2017/04/148547/how-to-get-a-raise-chatbot-cindy-gallop
  3. Better job descriptions
  1. We are responsible for baking Sec into DevOps and hence write the red team software (well integrate in most cases) for your appsec team if your devs are using GitLab. We have a security team that secures GitLab itself but that's not us. We have SAST, DAST, Dependency, Secret Detection and License Compliance baked into our paid tier, and SAST is coming down to the free tier! I’m pitching a talk about tuning to shmoocon because it seems like that's the most common question I got as a result of my devsecops talks at derbycon / shellcon / bsidesdc.
    1. N.Schwartz: Are you ready to leverage DevSecOps? BSidesDC 2019

2019 ShellCon Tuneup Tips for Your CV and Profile, From an Interviewer

SE Village Con - Thu, Feb 20 - Sat, Feb 22 | Hilton Orlando Buena Vista Palace

Layer8conf - https://www.workshopcon.com/events

http...

Previous Episode

undefined - 2019-040-vulns in cisco kit, google's project 'nightmare', healthcare data issues, TAGNW conference update

2019-040-vulns in cisco kit, google's project 'nightmare', healthcare data issues, TAGNW conference update

Tagnw.org

Amazon Smile - brakesec.com/smile

News:

https://www.androidpolice.com/2019/11/11/google-project-nightingale-health-records-collection/

https://www.csoonline.com/article/3439400/secrets-of-latest-smominru-botnet-variant-revealed-in-new-attack.html

https://blog.naijasecforce.com/the-jar-based-malware/ - ms. Infosecsherpa mailing list “nuzzle”

https://www.axios.com/hospitals-cybersecurity-medical-information-hacking-076cb826-fc69-4ba6-b3fd-57ce19ab00c6.html

https://www.axios.com/hospitals-doctors-privacy-records-hacks-data-5cb5d8c1-27de-4cc1-94d8-634015efc04a.html

https://blog.ropnop.com/extracting-ssh-private-keys-from-windows-10-ssh-agent/

https://en.wikipedia.org/wiki/Data_Protection_API

https://latesthackingnews.com/2019/11/10/multiple-security-issues-detected-in-cisco-small-business-routers-update-now/

https://www.routefifty.com/tech-data/2019/11/plan-engage-hackers-election-security/161045/

https://www.darkreading.com/vulnerabilities---threats/microsoft-security-setting-ironically-increases-risks-for-office-for-mac-users/d/d-id/1336268

Check out our Store on Teepub! https://brakesec.com/store

Join us on our #Slack Channel! Send a request to @brakesec on Twitter or email [email protected]

#Brakesec Store!:https://www.teepublic.com/user/bdspodcast

#Spotify: https://brakesec.com/spotifyBDS

#RSS: https://brakesec.com/BrakesecRSS

#Youtube Channel: http://www.youtube.com/c/BDSPodcast

#iTunes Store Link: https://brakesec.com/BDSiTunes

#Google Play Store: https://brakesec.com/BDS-GooglePlay

Our main site: https://brakesec.com/bdswebsite

#iHeartRadio App: https://brakesec.com/iHeartBrakesec

#SoundCloud: https://brakesec.com/SoundcloudBrakesec

Comments, Questions, Feedback: [email protected]

Support Brakeing Down Security Podcast by using our #Paypal: https://brakesec.com/PaypalBDS OR our #Patreon

https://brakesec.com/BDSPatreon

#Twitter: @brakesec @boettcherpwned @bryanbrake @infosystir

#Player.FM : https://brakesec.com/BDS-PlayerFM

#Stitcher Network: https://brakesec.com/BrakeSecStitcher

#TuneIn Radio App: https://brakesec.com/TuneInBrakesec

Next Episode

undefined - 2019-042-CircuitSwan, Gitlabs, Job descriptions that don't suck, layer8con

2019-042-CircuitSwan, Gitlabs, Job descriptions that don't suck, layer8con

Diana Initiative

@circuitswan @dianainitiative

https://www.dianainitiative.org/

https://twitter.com/DianaInitiative

Conference in Las Vegas (Aug 6-7, 2020) (Thu & Fri)

[email protected]

Topics

  1. Diana initiatives
    1. Past
      1. 2015 - idea at defcon 23
      2. 2016-17-18 growing but got too big!
      3. 2019 got our own space, ~800 tickets
      4. 2020 plans-westin again, 2 speaking tracks and 1 workshop track, solder village, career village, CTF, lock picking
      5. Mentoring both CFP and presenters this year! (expansion from last year)
      6. student scholarship (we want to double the amount of money, target still 10)
      7. Free tickets (expansion over last year)
    2. Present
      1. Slogan contest 2020
      2. I don’t want to think about 2021 yet :)
    3. Future
      1. Mentors
      2. Reviewers
      3. Volunteers
      4. Donations (giving tuesday, scholarships)
    4. Needs/wants
  2. Discuss how to add more DNI into your event (conference, meetup, slack, etc)
    1. Women in Technology Diana 2018
    2. https://business.linkedin.com/talent-solutions/blog/job-descriptions/2018/5-must-dos-for-writing-inclusive-job-descriptions
    3. https://www.hudsonrpo.com/rpo-intelligence/recruitment-process-outsourcing/how-to-write-an-inclusive-job-description/
    4. https://www.refinery29.com/en-us/2017/04/148547/how-to-get-a-raise-chatbot-cindy-gallop
  3. Better job descriptions
  1. We are responsible for baking Sec into DevOps and hence write the red team software (well integrate in most cases) for your appsec team if your devs are using GitLab. We have a security team that secures GitLab itself but that's not us. We have SAST, DAST, Dependency, Secret Detection and License Compliance baked into our paid tier, and SAST is coming down to the free tier! I’m pitching a talk about tuning to shmoocon because it seems like that's the most common question I got as a result of my devsecops talks at derbycon / shellcon / bsidesdc.
    1. N.Schwartz: Are you ready to leverage DevSecOps? BSidesDC 2019

2019 ShellCon Tuneup Tips for Your CV and Profile, From an Interviewer

SE Village Con - Thu, Feb 20 - Sat, Feb 22 | Hilton Orlando Buena Vista Palace

Layer8conf - https://www.workshopcon.com/event...

Episode Comments

Generate a badge

Get a badge for your website that links back to this episode

Select type & size
Open dropdown icon
share badge image

<a href="https://goodpods.com/podcasts/brakesec-education-podcast-15362/2019-041-circuitswan-diana-initiative-diversity-initiatives-at-confere-7883606"> <img src="https://storage.googleapis.com/goodpods-images-bucket/badges/generic-badge-1.svg" alt="listen to 2019-041-circuitswan, diana initiative, diversity initiatives at conferences on goodpods" style="width: 225px" /> </a>

Copy