4 ms·
Not an issue I experienced at my old company (a consultancy) but this is a huge factor on security teams that I think is often overlooked. "Old" style security
by InitialBP 4y ago
Not an issue I experienced at my old company (a consultancy) but this is a huge factor on security teams that I think is often overlooked.
"Old" style security teams often have a "you (wrote bad code|bad config|picked bad libraries), now go fix it" attitude that really doesn't do them any favors. A big part of being on any security team is building rapport with other teams and making sure that the security team is seen as a part of the company and not "the assholes who make us do extra work."
Anecdotally it seems like the more the other teams have a strong relationship with security - the more likely they are to consult the team early on and get some input on design decisions and recommendations that reduce the overhead of fixing vulns later on.