All Sessions>

Talk: “Why Devs Struggle with Application and API Security”

Talk: “Why Devs Struggle with Application and API Security”

We’ve all heard the buzz around pushing application security into the hands of developers, but if you’re like most companies, it has been hard to actually make this a reality. You aren’t alone - putting the culture, processes, and tooling into place to make this happen is tough. Join Stackhawk CSO Scott Gerlach as he shares his triumphs and failures while building devsecops practices and tools at companies such as godaddy, sendgrid, and Twilio. Dig into specific reasons why developers struggle with appsec and what you can do to make it work better.

Scott Gerlach, CSO and Co-founder at StackHawk.

Scott Gerlach

CSO and Co-founder

StackHawk

Interested in Postman Galaxy 2022?

Join the mailing list for the latest Galaxy updates.

View More Talks from Postman Galaxy

From the Postman Blog

Wed Jan 27 2021

Top 5 API Security Best Practices for 2021

By: Guest Author

This is a guest blog post by Subho Halder, chief information security officer and co-founder at Appknox. With APIs being the new norm in the modern software development era, a rise in security concerns related to APIs is also inevitable. Gartner predicts that by 2022, API security will be the topmost cause of concern for…

Fri Jan 22 2021

Introducing Postman Security Scans

By: Tirthankar Saha

According to the 2020 State of the API Report, businesses worldwide are becoming more reliant on APIs for their day-to-day work. And with the increasing number of APIs made available for public consumption today, it’s extremely important that any linked API documentation and saved examples demonstrating how to use an API don’t contain sensitive information…

Wed Oct 07 2020

Encryption, SSL/TLS, and Managing Your Certificates in Postman

By: Kin Lane

Just like when it comes to making API requests and working with responses, Postman aims to give you greater control when it comes to configuring API encryption—which is now a standard part of API operations in 2020. Encryption is pushing API providers to leverage Transport Layer Security (TLS) to secure the data, content, and other…