Building Security into DevSecOps

CISO Dinner

November 9, 2022 - New York, NY

Attend this event

Company is Required

By clicking the “Register" button, you are agreeing to the Privacy Policy and Terms of Use

Visionaries

Rafi Buchnick RBC
Rafi Buchnick

Head, Tech Risk and Cybersecurity - RBC Clear

RBC

Dinner

Hello, my name is Rafi Buchnick. I am a risk and security expert with extensive experience leading cross-functional teams, assisting them in the delivery of secure IT solutions. I ensure protection for global business operations and mitigate cyber risks for multiple clients, worldwide and am recognized for my impeccable record, in protecting client business interests, and any further damages to operations, during forensic investigations. After serving as Captain in Israel’s IDF Intelligence Corps, I began my career working as Chairman of the Board, ‘Bashan’ Market and Productions. From there, I progressed to a position as Financial Controller, Schneider Children Medical Center, and then, as Division Deputy Head at the Israel Institute for Biological Research. The rest of my work history is detailed in this profile. For more than fifteen years, I have been involved in ensuring security operations and planning for business continuity, should there be a disruption in services and/or the occurrence of a natural or manmade disaster/cyberattack. I am successful because of my meticulous attention to detail, as well as my ability to communicate technical information in easy-to understand language. I know I am only as good as the team I assemble, so I take time to train, coach, and mentor team members for career growth and business success. My key areas of expertise include, but are not limited to, Information Security, Risk Assessments/Mitigation, Stakeholder Communication, Regulatory Compliance, Technology & Application Vulnerability Review, Investigations to Support Client Business Interests, Disaster Recovery & Business Continuity, Cross-Functional Team Collaboration, Cost Reduction, Project Management, Industry Best Practices, and Increasing Cyber Capabilities.

Scot Miller Mr. Cooper
Scot Miller

SVP & CISO

Mr. Cooper

Dinner

Scot Miller, CISSP, CISM, is the Senior Vice President and Chief Information Security Officer for Mr. Cooper Group. He serves on the Dallas CISO Board, has presented on advances in Information Security and Technology Governance at consortiums in Florida, Texas, New York, Arizona, and Connecticut, and has been quoted in national magazines and other industry symposiums. Scot built high performing Security and Operations teams from the ground up, and over the past few years, brought Mr. Cooper’s Identity Governance and Compliance teams to a new level. The supporting projects won the 2021 Cybersecurity Team of the Year and CSO50 Award from a pool of national and international candidates for innovation, agility, and meaningful impact on a business. Scot’s team is responsible for identifying, analyzing, and reducing risk for all Mr. Cooper’s Group business entities. Previous to his duty at the Mortgage Servicing institution, he was CISO for HMS (a Texas based Healthcare Information Services organization), Head of Global IT Security for Alcon Laboratories, and Chief Security Architect at MassMutual Financial Group. Scot was also the VP and CTO for the CT chapter of ISSA.

Devon Bryan Carnival Corporation
Devon Bryan

Global CIO

Carnival Corporation

Dinner

DEVON BRYAN was appointed as the Global Chief Information Officer (CIO) for Carnival Corporation effective December 14, 2022. He joined Carnival Corporation in October 2021 as the Global Chief Information Security Officer with responsibilities for conceiving, implementing and leading technology solutions that assure compliance, protect personal data and corporate assets, increase organizational capability and advance productivity within Carnival Corporation and our world-leading cruise line brands. Prior to Carnival Corporation, Devon was Managing Director, Chief Information Security Officer, MUFG Union Bank N.A where he was responsible for establishing and maintaining a comprehensive information security strategy and program to ensure that information assets and technologies were appropriately protected. He was also responsible for ensuring that information security risks were identified, evaluated, mitigated, and reported in a manner that meets compliance and regulatory requirements and aligns with the risk tolerance for MUFG in the Americas region. Most recently, he served as the CISO for KPMG LLC where he was charged with effectively designing and executing a best-in-class information and data security function with a proactive approach to enable business results. Prior to KPMG, Devon was the Executive Vice President and Chief Information Security Officer for the National IT Organization of the US Federal Reserve System. As the System-level CISO, he was responsible for ensuring the Fed’s information security policies, architecture, programs and incident response team remain effective and efficient. Prior to the Fed, Devon was the Global Chief Information Security Officer (CISO for Fortune 500 outsourced payroll and human resources provider ADP. As Global CISO for ADP, Devon led ADP’s information security strategy, collaborating across the company’s geographically dispersed business operations to ensure coordination, consensus, and effective cybersecurity protections across global operations. Prior to joining ADP in 2011, he served as the Deputy Chief Information Security Officer (CISO) for the Internal Revenue Service (IRS) where he was appointed to the Senior Executive Services (SES) and directed the IRS’s FISMA-compliant information security program and the IRS’s cybersecurity incident response team. His information security career began in the U.S. Air Force, where he served as a Captain and Lead Network Security Engineer working on systems and programs to protect the critical network and communications networks of the Air Force’s Air Combat Command. Devon is a co-founder of Cyversity, a 501c3 non-profit which he helped launch in 2014 and geared toward improving the underrepresentation of women and minorities in the field of cybersecurity through academic scholarships, certifications, mentoring and networking opportunities. Devon received a Bachelor of Science, Applied Mathematics from South Dakota Technological University and a Master of Science, Computer Science from Colorado Technological University, graduating Summa Cum Laude. He holds multiple industry recoginized certifications serves on several non-profit boards and participates in select industry forums as a sought-after speaker and writer on emerging technology trends and issues.

Anthony Gonzalez QBE North America
Anthony Gonzalez

CISO NA

QBE North America

Dinner

Visionary, results and solutions-driven professional with 20+ years of experience in progressively responsible Cyber Security and IT leadership roles in the financial services, insurance, pharmaceutical, biotechnology, consumer goods,and chemical manufacturing industries. Adept in building and leading global Cyber Security, IT technical and support functions. Creative, resourceful problem solver with a track record of success in delivering cost-effective and value-added services to his customers. Additional experience in industrial engineering and process improvement. Specialties: Areas of expertise include: Cyber Security, Network Security,Application Security, Infrastructure Management and Security Incident Management, Disaster Recovery, Forensic Investigations, Operations Management, Financial Management, Project/Portfolio Management, Policy/Procedure Development, Budget Preparation, Strategic Planning, Process Design/Implementation, Risk Mitigation, Enterprise Architecture, IT Governance, Manufacturing/Laboratory Automation, Organizational Design, Vendor Audits, System, Start-Up Operations, Sarbanes-Oxley (SOX), Talent Development/Mentoring, International Team Management, and Regulatory Compliance

Ibrahim Jackson Ubiquitous Preferred Services
Ibrahim Jackson

Founder

Ubiquitous Preferred Services

Dinner

Ibrahim works with technology, human resource, and other business leaders to develop, upskill, and retool teams of people for next practice leadership in a changing world of work. By providing workshops, coaching, and consulting, with a team of industry experienced professionals, to large-scale enterprises and government agencies, employees are prepared for future opportunities today. Our underpinning Digital Professional Framework governs our people transformation programs with a focus on four key areas: 1. Digital Depth 📱 2. Business Acumen 📊 3. Interpersonal Skills 🤝 4. Social Impact 🌎 Whether transformation, modernization, evolution, or restructuring, all of these changes have a basis for moving the organization forward. Leaders are trusted and relied upon to bring sustainable change to successful completion using competence, appropriate practices, skills, behaviors, and mental models to galvanize people and achieve sustainable change, continuous improvement, and make the most significant impact, so their organization realizes optimal value. TRAINING Our focus on digital and leadership attracts technology leaders and human resource executives working on developing people that need to be ready to lead in an era of emerging technology and where business models are expanding and evolving. We provide standard training, bespoke modules customized to the needs of the organization, modules tailored to the specific business objectives of the organization, and on-demand modules. Our learning journeys are immersive, experiential, and applicable to the particular business challenges our clients have. COACHING While many challenges and opportunities across organizations may be similar, their specific context, focus area, and goals are often unique. Having a coach or executive coach that can be an extension of your brain trust often leads to better decision making, improved results, and career elevation. We use a variety of coaching and group coaching models that help our clients excel at the aforementioned. CONSULTING By pairing our client's institutional knowledge with our broad range of expertise from across many industries, we help leaders tackle today's problems so that they achieve a competitive advantage on their journey towards making a material difference in their business. We perform simple to complex assessments, primary and secondary research, and strategy development where and when needed. When working with us, we own your problem, allowing you to capitalize on the solution's rewards.

Anthony Gonzalez (1)
Anthony Gonzalez

Principal, Strategic Advisor

Innervision Services LLC

Dinner

Visionary, results and solutions-driven professional with 20+ years of experience in progressively responsible Cyber Security and IT leadership roles in the financial services, insurance, pharmaceutical, biotechnology, consumer goods,and chemical manufacturing industries. Adept in building and leading global Cyber Security, IT technical and support functions. Creative, resourceful problem solver with a track record of success in delivering cost-effective and value-added services to his customers. Additional experience in industrial engineering and process improvement. Specialties: Areas of expertise include: Cyber Security, Network Security,Application Security, Infrastructure Management and Security Incident Management, Disaster Recovery, Forensic Investigations, Operations Management, Financial Management, Project/Portfolio Management, Policy/Procedure Development, Budget Preparation, Strategic Planning, Process Design/Implementation, Risk Mitigation, Enterprise Architecture, IT Governance, Manufacturing/Laboratory Automation, Organizational Design, Vendor Audits, System, Start-Up Operations, Sarbanes-Oxley (SOX), Talent Development/Mentoring, International Team Management, and Regulatory Compliance

Agenda

All times Eastern Time

6:00 PM-9:30 PM

Building Security into DevSecOps

Many organizations struggle with how and where to introduce automation and integrations efficiently. Conventional approaches to application security can’t keep pace with cloud-native environments that use agile methodologies and API-driven architectures, microservices, containers, and serverless functions. Application security testing is evolving to meet the speed at which DevOps teams operate. DevSecOps teams are challenged with how to make sense of the noise their AppSec tools generate once they’ve been automated into DevOps pipelines. Processes and tools are more fast-paced and rely on integration and automation to maintain efficiency throughout the software development life cycle. A new approach to DevSecOps is required addressing a change in the security mindset. How do CISOs achieve this without the buy-in from stakeholders?

In Partnership With