Hacker News new | past | comments | ask | show | jobs | submit login

Companies which actually do DevSecOps are unlikely to have roles with that title.

That's almost exactly what my thoughts were. Its not a role, it's culture/mindset/ "this is how we fold security into our development and operations". An expectation perhaps. I've seen platform engineering roles evolve however to include security specialists, but again, with platform engineering the goal is to bake security and guardrails and general optimisations into to the platform.

I also want to elaborate on the flipside; having dedicated roles as devsecops, there is a high potential that security and responsibilities shifts to people in those roles, and from experience this leads to "someone else will take care of that", where as what you really want is something along the lines of "security is everyone's responsibility (including mine)"

When something is everyone's responsibility, no one will be responsible

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact
