DevSecOps at a Crossroads: AI, Collaboration and the Road Ahead – DevSecOps: Cracking the Code EP3
In this special edition of the series, recorded live at RSAC 2025, Alan Shimel, Eran Kinsbruner and Tyler Agypt sit down with Moran Ashkenazi of JFrog to explore the ongoing evolution of DevSecOps. The discussion emphasizes the growing need for stronger collaboration between development and security teams, and why empowering developers to take ownership of security risks is more critical than ever.
The conversation also takes a close look at the role of AI in modern software development—how it’s reshaping productivity, impacting job roles, and influencing the future of secure coding practices. As AI capabilities expand, so too does the DevSecOps landscape, signaling a shift that’s just getting started.
Transcript
Hey everyone. Welcome back here to our live coverage of RSA conference 2025. We are in Moscone West on what they call Broadcast Alley, and we've been doing mostly the interviews of people here at the show, and we're gonna do that today.
But really, this is a special edition of our DevSecOps Show, cracking the code, which we do like every other week. Anyway, um, cracking the codes available on your favorite podcast, uh, platform, whatever that may be. Excel on Textron tv, YouTube's Textron TV channel.
And by the time you watch this, probably our Textron TV OTT channel. So you could watch this on Apple TV or Roku or Amazon or whatever you'd like. The important thing is to watch it on cracking the code, we explore the frontiers of DevSecOps.
Um, and just yesterday we had our 10th annual DevSecOps event here at the RSA conference, and it was about ai, AppSec and app dev. Great, great show. We have actually some of our speakers here today, were there yesterday.
Um, but let me introduce you to today's panel for this episode of Cracking the Code. I'm gonna start to my far right, this gentleman here, Aaron. Yeah.
Kranzberg. Yes. Aaron is, um, with Check Marks, who of course is the sponsor of our Cracking the Code show, our partner in producing it.
Aaron, it's great to have you on in person across the table from me. Yeah. Thank you for having me.
Uh, thank you. Uh, I'm on the product marketing for check marks and, uh, excited about the show. We are hearing ama hearing amazing things, uh, at, uh, RSA so far.
Good. Happy to share them with you guys. Absolutely.
It's great to have you on. I've said this before, Aron and I go back a little while, even before check Marks and everything else, so it's great to be working with him again. Next tour Iran.
This, this little lady right here is a firecracker. She came to our show yesterday and lit it up at the, on the stage there. And she was up, she was in the panel with the CIO, the CISO CSOs of Open AI and anthropic and senior Security people from Meta, but she had the most to say her name is Marran Ashkenazi Marran, welcome and thank you.
Thank You everyone. It's pleasure to be here. Thank you for having me yesterday.
It was amazing panel and super interesting to get everyone's thoughts, so excellent. Happy think to be here. I people a little bit about you.
Yeah. So I am Jfr Chief Security Officer. I'm within J FFR for five and a half years.
It's amazing because we're doing our own journey into the security and we're at a DevOps company and now the DevSecOps company that's providing a whole solution for the supply chain and secure with ai. Uh, everything simple. Absolutely.
Of course, our audience is no stranger to check marks or Jfr for that matter. Well, let me introduce you to our third, third guest. Tyler, I blanked on your last name.
Egypt. Egypt. I apologize.
Egypt. It's all right. How do you pronounce it?
Egypt. Egypt. Mm-hmm.
Tyler, Egypt. Tyler, why don't you introduce yourself? I appreciate it.
Thanks for having me here. So, my name is Tyler Egypt. I'm our Vice President of Global Enablement at check marks.
So I work closely with, uh, enabling, uh, not only the field at check marks, but also our customers and partners bringing awareness around AppSec, uh, and the great capabilities that we have and offer. So, very excited to talk about DevSecOps and some of the advancements we've seen and, uh, especially at this event of, uh, learning more and more about trends across the products. Absolutely.
So let me kick things off. You know, as I mentioned yesterday was our 10th annual DevSecOps Connect here. I remember 10 years ago it was like having a wedding where the in-laws didn't get along.
Right. So on one side of the audience sat, the security people on one side of the audience sat the DevOps people. And I like, I could build a wall in the middle.
Yeah, right? True. You could.
They just wouldn't come together. A lot's happened in 10 years. They have come together.
DevSecOps is real. We all realize that we all want to have better code, more secure code. I've never met one developer who raised their hand and said, I don't care about the security of my code.
They all care. It's quality. They have pride in what they do.
Security people, they're the old, and I'm a security person, I should say. We used to say, no one cares about security, but us, excuse me, only we can care about security. But we realize now everyone cares about security from the highest levels of our, our companies on down.
So we made a lot of progress, but we've also made some mistakes. I think one of those mistakes was like we do with everything else. We, we took our security tools designed by security people and said, here, developer, Good luck.
Good Luck. Enjoy. Yeah.
Well, that, that didn't work out so well. Did it. Right?
No, and and the reason is is they're not security people. So a lot of DevSecOps companies died on the side of the road with that. Right.
And it's interesting because we got two different companies here, check Marks. You are an abec company from the day you were, I remember when Check Marks was founded. Yeah.
Mm-hmm. Jfr, you weren't No, you were a developer company and, and a Artifactory. Right?
Right. But you've come, you know, parallel evolution to the same point of what do we need to make developers successful? Yeah.
And so I I'll ask all of you Yeah. What, what is this magic formula? What's the secret sauce to enabling developers to develop more secure code?
And please don't tell me it's ai. No, it's not. Okay.
It's who wants, who wants not today anyway. Yeah. Who wants to go first?
Tyler, we're gonna make you go first. Absolutely. So we, like you said, developers take pride in their work.
Uh, they want to deliver code on time, uh, with security in mind, but they need to be empowered to, uh, understand the risk that's involved. And they need to be guided and helped with, uh, how they address those, the risks that's created. So we found understanding that developer experience, uh, working in their existing workflows within their existing tool set, um, is extremely important.
So we're not disrupting their flow. We're giving them the right information at the right time. So they're the catalyst to change, uh, and, and improve their DevSecOps footprint at the company.
So we know they're a key part of DevSecOps and the ones that are gonna be driving the majority of the fixes. So really meeting them where they work, a common theme. We've seen, um, more codes being generated by AI and productivities going through the roof right now.
We're seeing, but that also adds layers of complexity, uh, uncertainty. Um, so we need to really understand, again, how they're writing modern code with modern applications, what risk that presents them, and then let's empower them to, uh, address that risk with the right kind of information and guidance. So that's kind of where we've seen that collaboration come together.
And, uh, yeah, both parties need to work together to make a, you know, advancements within software delivery. So it's, it's, they're needed more on. I think that, uh, we learned from the, that's, uh, that's something that both humans and We learn more from mistakes than we do from success sometimes.
And absolutely. And I think that both side understand that we depends on each other. We cannot do that independently.
Security cannot do anything without the right partners to drive it. We can bring the product, but it's a banner of, uh, uh, democratization. Developers need to have the platforms and choose the right tool that will accelerate their day to day and not like find them, like we we're talking about, like the shift left.
So it need to be like in their IDE, something very natural, very native, not go to a different interface, try to find the CVE, try the vulnerability, try to fix it, go back to the code, go back to the malicious packet, go back. It need to be very na natively, not extra work, and need to be very effective. 'cause by the end of the day, they want to like focus on releasing a product, a perfect product and innovative feature.
And that's it. They don't care about security. Yeah.
But on the other hand, they do need to like implement that. They need to really secure software. Right.
Because it's their, it's your code. You, you own it, you own it. So both side need to come together.
So that's the thing that, that's the point. I, I agree. They, they do need to come together and they have let, let's, I don't want to give a false narrative.
Right? We've made a tremendous amount of progress. If you were out there yesterday, you couldn't tell who was who, where they were sitting.
They're all mixed in. So we've made progress there. I wonder, it's funny.
So you come from the security side, you come from the developer side. When you are talking to security folks, did they say, but you're not a security company, right? And vice versa.
Well, you are not a developer tools company. You're a security company. How do you get credibility across the aisle, Aaron, around any thoughts?
Of course. Uh, so I think, uh, and you mentioned like 10, 10 years ago and now, okay. I think that today you're no longer working in silos.
Okay? So it's not, you're a developer, you security, they all have the same objectives of releasing high quality software highly secured. And what is changing is the scale.
Okay? More pipelines, more development teams, higher, higher sized developer teams. Uh, and these guys need to trust what they're using.
Okay? So the world trust here, I think is a key word because these guys, whether it's they, we, the head of a security or developer or quality engineer or platform engineering leader, they need to have the trust in their tools that will get them towards their objectives and their objective are the same. Zero fibers in production, higher security, because we know that these guys are dealing with, I know, 60, 70, 80, sometimes 90% of open source code.
Most of the code that they're using is not even theirs. Okay? So if they, maybe they don't trust the code that they're using coming from others, they should trust the tools that we are giving them with check marks, with J Fog that will get them towards, you know, uh, the finish line successfully.
And another keyword is trust and continuously, right. Okay. What you see today is not what you see tomorrow.
Every, like, the minute, the minute I'm speaking with you here, Ellen, someone is working on a new malicious package. Right? Right.
So, uh, it's a moment in time if you like Moran. Any thoughts on that? Yeah, I think that, uh, totally agree with you.
It's about the, the speed is just, uh, something that we cannot control anymore. It just, it's, it's there. It's running super fast and you need to have like, automation as part of it.
So that's the part of the lifecycle need to go grow and fast. Therefore, it's like different motivations. I want the security, I want the product to be super secure and r and d want it to be fast, and we need to collaborate to make it, to make it happen.
So it's different motivation, but single target to get this done. Uh, and it's okay to have like different motivation in order to, to make it happen. Definitely.
Yeah. I want to talk about another dev ecop principle that I think has undergone a big change. Yeah.
com 20 14, 20 13, actually shift left. Everything was shift left, Right? I gotta tell you the truth.
I'm of the opinion now, you gotta shift everywhere. Mm-hmm. But what do you think about shift left as it was, let's say eight, 10 years ago versus today?
I think it has been changed because we understand that it's not just the shift left, it's also shift right to the runtime shift up to the cloud. Yeah. It's like, like Shift out to the End, turn around and around.
It's all over. That's continuum. It shift every wrap.
Yeah, it is. And that's the security Yeah. Mission.
Now Every chain in the, the lifecycle Agree. Right? So I think we've recognized these things and, and they've manifested themselves into tools, security tools that are easier for the developers to use.
Yes. Built into the IDE. Yes.
For your instance, I know check marks they made, I think you made an announcement here at R-S-A-I-I got the, uh, yes. We embargo. Yes.
You're building, uh, into, into IDE. Correct. So we've had, uh, integration in the IDE on understanding risk, whether it's the custom code you wrote, your open source software, infrastructures, codes, that's all been available.
What we recently announced was, uh, our application security, posture management right. View of those results. So now not only do you have this large, uh, list, hopefully that's reducing over time, but this large list of findings, but we're helping the developers prioritize on which actions to take on which items are most critical.
So that's, this goes back to balance. If you look at what we're asking the modern developers to do today, their responsibilities have grown. So they need to be understanding way more, you know, whether it's new languages and frameworks, whether it's, uh, cloud native development and understanding how, uh, the application will be deployed.
That's, we're getting faster, but we're also adding more complexity as a result of it. Um, so what we introduced in the, uh, IDE is a giving them the, a very, uh, condensed and focused view, so we're not overwhelming them and to what you were alluding to earlier, um, meeting them in the IDE. So it's, there's no context switching.
So as a developer, I'm doing my day to day activities trying to produce quality, cook quality code quickly. Um, and this allows me to address risk along that process. So it's not switching to different products or different views logging into different systems.
And we've seen as a result of this, that developer time to fix is drastically decreased. So now we're helping in, uh, not only prioritize, but the speed to fix is a new concern that we're addressing as well. Yeah.
Fair, fair. Now, Maran, I, I know, I know j Frog's history and story, right? You didn't just make a developer tool friendly for security people.
You j Frog's actually acquired several right. Security vendors, correct? I think you One we acquired Yeah.
Vision that became jfr Advanced Security, which I, I'll talk about it. And also Qua that became J froog, ml and L Yeah. And going back to the shift left, the, the reason that we're, I super like support that it's because it's about efficiency of the software development lifecycle.
When it's shift lab, when you identify the true issues that you need to focus on, that will really save the time, right? So be effective with that and understand the full lifecycle, but as, as, as soon as possible, if it's like malicious package or there is like malicious even model in LLM now. So think about the full dimensions that is, is operating in order to create a new application and try to push it as soon as possible.
So it'll be like time, it's time consuming. So if you can do that as fast as you can, it's a plus for everyone. And developers want it, but it must be very focused and not like spam, uh, different tools on the ID plugin, but consider everything, prioritize that, make sure that it's, validate that it's applicable and save time.
Yeah, Agreed. If I can just add on top of that, I think, uh, what Tyler and Morani was saying, it's exactly, you know, we, we are seeing today, uh, with the advancements of technology, uh, developers being overwhelmed with so much findings, okay? They don't know where to start.
Okay? There is too much noise in some cases, a lot of false positives, okay? At the end of the day, they need to get the job done, okay?
They have a feature that they need to fix, they have a bug they need to fix, they need to manage their pipelines. The more you reduce the noise on their end and walk within, of course the ID like serving them where, where they are, you are actually talking, going back to the trust, right? You are building the trust into the workflow of software development.
And that, in my mind, can transform developers into security champions because we know developers are not security champions by definition. Right? But if you feed them with the right amount of security training, security, findings, prioritization, risk management, right?
Uh, with this A SPM and the id, we actually also introduced protocol, uh, a very, uh, modern scoring, uh, algorithm. So it's not just that you're prioritizing that based on, you know, the severity of any findings, but actually what matters most to the developers so they can actually get their own unique report that they need to take, take care of the most unique CV that they need to take care of and whatever. So, uh, dev experience, user friendly, reduction of noise, these are the things that in my mind matter and allows developers to adopt more user security tools.
Yeah. And, uh, the company tools, and that's the power of platform. I think that is, we're talking about like platform engineering.
Yes. That's the power of platform to unify and give a context. So it'll be very clear, very like, precise.
We're gonna jump into platform engineering in a moment, but I want to focus just on platform for a second. Yeah. I, I did an interview, I did a few interviews over the last couple of days, and this whole concept of platform came up.
I've been in security 30 plus years. One thing I've learned about the security business is small companies, little fish, they make what they call products, then medium sized companies, they look at those products as features. Mm-hmm.
And they buy the little fish and they roll those products up as features into their products. And they think they have the product and we sell point products, but then the bigger fish, they say, no, we don't want products, we want platforms. Yes.
And my platform has multiple products in it, not just my products. We plug in, we connect API, whatever, we connect to other products into this holistic platform. And that's really where companies want to be.
And not only vendors. Yeah. But end user companies.
Yeah. Consumers. Yeah.
Consumers. They don't want 27, 36 integrations point products. Yes.
They want a platform that handles this mission for them. And so I think it behooves all of us, you know, of course everybody wants to be the platform. You are a platform, you're a plat, we're all a platform, right?
That doesn't work either. Right? But we want these tools to work together better.
And that's, I think a, a, a key piece of it. I want to turn to platform engineering. Sure.
com about, uh, eight months ago now. org. Very big.
He's a Great guy. Yeah. 200, 300,000 members there.
Luca and I, and the check marks people do our platform engineering show every other week. Yep. And round tables and stuff.
And we've spoken about this on that show, right? That if we could give the developers a platform that is both secure, tested, stable, scalable, and just say, developer, do what you like to do. Exactly.
Develop, focus on that. Just Develop, go code, go as fast as you could go. That's what we need.
Right? That's, and that's, I think at, at the Nugget that's appeal of platform engineering. I know how check marks is working with them.
How does Jfr view that platform engineering? That's, that's Jfr story. It's about DevSecOps for real, right?
Come from a company that did like DevOps and get into security world, but in a very natural way for the developers. It's bring developers into the security and and really connect, be the glue that connect between them. And that's exactly the power of the, of the platform.
Because you don't need to go to a different, you just got everything on a single place. And that's trusted releases. Um, combine those two together.
Yeah. Alright. So I think within platform engineering and what we call an IDP, right?
An internal developer, uh, platform portal, everyone is using the p in a different way, by the way. Uh, so I think if you give these guys the developers, uh, a centralized portfolio, if you like, of the best of breed platform for security, for, uh, I know for cloud, for whatever they need to get the job done. Uh, that's also how you build trust.
But also that's how you take that. People look at the platform engineering as the next level or next evolution of DevOps. Okay?
It doesn't replace DevOps. It's kind of built on top of DevOps to optimize these pipelines to optimize the software development lifecycle. But also, I've spoken with one of the analysts the other day also to put some safeguards on the tools that are being used, uh, and governed and controlled within the, the, you mentioned earlier, Alan, these different point solutions, right?
Right. So with so many platforms, so many different tools, especially when you're dealing with enterprises, you need a governed approach to different tool chains within, uh, the organization. And when you're dealing with, I know, 100 dev teams with thousands of pipelines, what you don't, you do want to give them, uh, the freedom of choice of tools and platforms, but you also want to control that.
And platform engineering brings this governance into the software development life cycle. I think that they're not, you know, dedicated has the knowledge, the right knowledge to do and accelerate that and give them that as a platform. They don't need to be security expert.
They don't need to be, uh, even like a legal expert or privacy expert, especially in ILLM. But they do need to, to just consume it, consume it as a service. And that's the change I think that we are going to see.
I think the service, that's the right, the right word here, right? The service and application, which is like, it's the higher level. It's not just the DevOps, it's just application that combine everything together, the security and the DevOps.
Let me turn now to another topic. 'cause we are going low on time. But look, we're here at RSA.
You can't walk more than five feet without tripping over ai. There's AI agents, there's generative ai, there's that ai, there's ml, there's everything. Both of your companies at Jfr and Checkmarx have news around ai Yep.
And have put big bets, right? Uh, JI Jfr ml, Right? You have AI agents.
Yes. I just spoke to Sandeep, the, uh, CEO about. Yeah.
How real, how big is ai? So is AI taking any jobs away here, or is AI making us better? If not, when will it, is it more talk at this point than real thoughts?
So I, I I can start. So ai, uh, serves a specific use case, okay? And each, let's say agent serves a specific use case for the developers, for the security engineers, whatever persona is using that.
So a AI is not going to replace anyone's or take anyone's job. I think that what we're going to see eventually, and we, we need just put it on the table, AI or people that are using AI are going to replace people that are not using ai. Okay?
So if you are today in the software development lifecycle, doing anything like from QA to dev to security, production monitoring, observability, I'm coming also from a previous observability space, they are all looking at ai. So if you're not going to start getting used to the fact that AI is kind of your co-pilot, your, uh, supporter in everything that you need to do, someone that uses AI will replace you. So AI is going to be driven by engineering, okay.
By engineers, uh, as part of the software development cycle. Okay? But it's not going to replace jobs for people in my mind.
That's just going to aid, uh, you know, bottlenecks or whatever challenges that these guys have and support them, uh, through their journey. So that's a, a short answer. I think they will replace humans in a lot of, uh, manual work.
People that are, that they're doing it today. It'll get into every position, not just like engineering. It'll replace in every, like, uh, every job in a company.
We're going to see, um, displacement, uh, for sure in support, uh, chat bot, replace support, you know, humans. So think about what AI will do, uh, about related to documentation. So many different aspects of service providers that will be totally improved and accelerate.
But I said it yesterday, I do think that the human factor is still very strong. And this is like our responsibility to make sure that we're doing the right thing. We're using it carefully, we're putting the right guardrails, we're putting the right foun foundations.
Yeah. Um, and it's in every several dimensions. Like the infrastructure need to be like aligned.
We have to put the right skeleton, the right model, um, due diligence, the models to make sure there won't be like data filtration and data poisoning. And then it's continue with AI agents understand what are their guardrails, what is the identity and access management, if it's like something that we implemented, reduce the, the actions that they can do, especially for various critical service and critical commands and operation or with sensitive data limit that align with the regulation. Make sure that we are aligned with the law.
Um, if, if autonomous AI agent will share data between us and, and, and, and uk, what about GDPR? How can I confirm that this identity is doing what it need to be done from legislation perspective? And that's a lot of things to do, or different dimension that we'll need to take care of them.
So we are going to focus on control them, manage it, do it the right thing, take it slowly, but it'll run fast. That's what I think. Fair.
Yeah. Tyler, what about you? Yeah, I'll just add, so it's gonna, the jury's still out.
It's obviously, uh, AI's here to stay. So that ship has sailed, but how it's being used, I think we're still waiting to see what's truly, uh, impactful and making a difference. There's a lot of noise around adding AI to certain product capabilities, but it goes back to what problem are we actually trying to solve, and how is it really, uh, empowering, especially in our case, the developers and security teams to work better together and remove a out of what they call like developer toil or those mundane tasks that, uh, can be easily replaced by something like an agent ai.
So, uh, we're excited to see and uh, we, we've launched, uh, a concept that we're working with our customers to really fit into their needs and understanding their workflows. But it'll be, uh, I think pretty groundbreaking, exciting to see how that plays out. And then, uh, if, if I could boil down, you know, the DevSecOps movement and, and focusing on the people and the processes, uh, AI's really gonna focus on the processes and I think that's a good movement for understanding, uh, the model of DevSecOps.
Everybody's kind of singing off the same sheet of music and there's alignment as far as how the processes work together and what everybody's role in that is. So, uh, yeah, definitely exciting times and seeing how it plays out though. Fair enough.
So one last question, we'll wrap up as we sit here today, really the first full day of RSAC in terms of keynotes and sessions, expo hall, are you bullish on DevSecOps? Do you think the best is yet to come? Or do we, is there another direction we need to go in?
What's your thought? Uh, I think it's evolutionary. So it, it will build on what we are doing today.
We're learning from what works and where we failed and where we can improve. I think we're only getting faster with the new, uh, AI capabilities and really having us look internally on what is working and what isn't. Um, so I think, uh, it's exciting to see a lot of the consolidation around what's happening in our space.
Um, and a lot of the great insights or context that we can derive from that. Uh, so I do think anytime you can get people together to solve the same types of problems, it's a powerful thing. So I think, uh, I don't think there's a way around it and I think it's the right trend.
It just will grow and, uh, evolve over time. I don't, I'm going to give you the last, Yeah, I don't think we are bullish, but I think we are reacting to the trends for sure. 'cause uh, just like cloud, it just started and everyone just start, you know, syn up and, and, and that, uh, same goes with ai.
So everyone are talking about MCP right now, right? Because it just started and then it's like a storm. Everyone are doing it.
So I do think that we're reacting to new trends and new technology and that, that makes sense. So reacting to that, just focus on doing the right thing and do, um, provide an holistic solution to drive that. Yeah.
Love it. Alright, that's gonna wrap us up here. You've just watched another episode of cracking the Code, the DevSecOps Show.
We'll be back live with more RSA conference coverage in just a moment. If you're not watching this live, you catch it on Apple or Spotify or YouTube or something. I'm sorry you weren't here to see it live, but we're doing our best to bring it to you.
I'm Alan Shimel. We're out.

