Challenges in implementing application security programs and tools for engineering teams
- Starting a small application security program with a small engineering team and choosing a technology like SCA and DAST
- Helping engineering teams understand and take measured risks in developing and testing code
- Enabling process and tooling that can easily get people started quickly in testing application security
- AppSec tools are built for security teams and can be complicated and difficult to understand for engineering teams
- Using technical jargon and wall of text to describe application security issues can be confusing for engineering teams