Team Wabbi
April 10, 2024
Click below to listen to TestGuild DevOps Toolchain’s interview with Wabbi’s Founder & CEO, Brittany Greenfield. She talks with host, Joe, about the integration of security and development in the DevOps process.
This interview originally appeared on TestGuild DevOps Toolchain Podcast on April 10, 2024
AI-Powered Security Orchestration in DevOps
About the session
This transcript is from an episode of the Test Skill DevOps Tool Chain podcast. The host, Joe, is speaking with Brittany Greenfield, CEO and founder of Wabbi, about the integration of security and development in the DevOps process. They discuss the concept of application security posture management, the future of DevOps, and the role of Wabbi in bridging the gap between security and development.
Key speakers
– Joe, Host
– Brittany Greenfield, CEO and Founder of Wabbi
Agenda
– Introduction of Brittany Greenfield and her work in DevOps and application security.
– Discussion on the future of DevOps and the integration of security into the process.
– Explanation of Wabbi’s role in application security posture management.
– Discussion on the challenges in integrating security into the DevOps process.
– Explanation of how Wabbi addresses these challenges and facilitates the process.
– Discussion on the current state of application security and the role of government and tech companies in it.
– Advice for those working in DevOps and security.
Takeaways
Takeaway: DevSecOps should be absorbed into DevOps, streamlining development
Brittany Greenfield believes that the term “DevSecOps” should be obsolete as security should be inherently integrated into DevOps, which itself should be part of standard development. The concept of DevSecOps was born out of the recognition of the need to integrate security into the efficiency-maximizing, silo-breaking practices of DevOps, but this integration has not been fully realized.
“DevSecOps should exist as a term is it should just be DevOps which should just be development,” said Greenfield. She argued that the initial shift to DevOps was about maximizing efficiency through breaking down silos, but security was left behind due to its complexity and its different methodology.
Greenfield’s mission with Wabbi is to make DevSecOps obsolete by seamlessly integrating security into the development process, noting that “everybody recognizes that DevSecOps is the norm,” but most enterprises have only implemented DevSecOps without truly integrating it into their existing software development lifecycle process.
Takeaway: Application Security Posture Management can streamline security integration
Application Security Posture Management (ASPM) holds the potential to streamline the integration of security into the development process. ASPM leverages automation and orchestration to manage the end-to-end application security lifecycle as part of the software development lifecycle, allowing developers to focus primarily on developing code.
One feature of Wabbi, as explained by Greenfield, is that it “orchestrates the end-to-end application security lifecycle as part of the software development lifecycle.” This allows developers to just focus on developing code, while the security tasks are fed into the process at the right time.
Greenfield gave an example of how Wabbi works: when developers submit a pull request, Wabbi will automatically kick off a security scan, bring back the results, prioritize them, and if needed, block the pull request from being completed until the critical vulnerabilities are fixed.
Takeaway: Security should be more than just compliance
Greenfield emphasized that while compliance is important, security should not be merely viewed as a checkbox to tick off. She argued that security should also consider business risk and customer risk, and that each company has different security standards depending on its risk profile.
Greenfield criticized the idea of security being just about compliance, saying “if you’re only doing security to do compliance then you’re just doing check the box security.” She pointed out that each company, especially in large enterprises, treats their applications with different security risks.
She concluded by highlighting the importance of collaboration in achieving effective security, saying “at the end of the day all of this is just good development because it’s about good collaboration and breaking down silos.”
Insights surfaced
– Application security posture management is a growing field that bridges the gap between security and development in the DevOps process.
– The integration of security into the DevOps process is a challenging but necessary step to ensure the safety and efficiency of software development.
– Wabbi is a platform that facilitates this integration by managing the end-to-end application security lifecycle as part of the software development lifecycle.
– The role of developers in the security process should not be to become security experts, but to work in collaboration with security professionals to ensure secure development practices.
– The future of application security will likely involve more government involvement and regulations, as well as the continued development of transformative technologies like application security posture management.
Key quotes
– “The reason I don’t believe DevSecOps should exist as a term is it should just be DevOps which should just be development right and if we think about where DevOps came from it was really about breaking down silos and DevSecOps is no different.”
– “Part of my mission with Wabbi is to make that term DevSecOps obsolete because it should just be the norm.”
– “We’ve created all of this data but it’s not enough to have data you have to have actionable information.”
– “We’re not expecting nor should we developers to suddenly start doing different things right they’ve got good workflows those will evolve as development evolves same with security they’ve got their own workflows.”
– “One actionable piece of information I think I can give that’s going to move the ball forward a lot faster is pick up a phone and call an application security manager.”
Related Articles

Wabbi Named a “Vendor to Watch” in IDC MarketScape: Application Security Posture Management (ASPM) 2025 Vendor Assessment
BOSTON / Press Release / September 18, 2025 Wabbi, a leader in Application Security Posture Management, is proud to announce that it has been named as a Vendor to Watch in the IDC MarketScape: Application Security Posture Management (ASPM) 2025 Vendor Assessment. This...

From Weak Link to First Line of Defense: How DevSecOps Turns Teams into Security Partners
From Weak Link to First Line of Defense: How DevSecOps Turns Teams into Security Partners We’ve all heard it: People are the weakest link in cybersecurity. And in software development, it often feels true—developers skipping scans to hit a release date, ops teams...

Security That Doesn’t Get in the Way: Why Dev Experience is the Real Key to DevSecOps
Security That Doesn’t Get in the Way: Why Dev Experience is the Real Key to DevSecOps We say we want to “shift left.” We say we want secure code from the start. But too often, security tools and processes still expect developers to leave their workflows, learn new...

AI is Solving the Puzzle. Are You Missing the Corner Pieces?
AI is Solving the Puzzle. Are You Missing the Corner Pieces? The game has changed—and it’s moving faster than ever. Artificial intelligence is no longer just a tool for innovation. It’s now a powerful asset in the hands of attackers, helping them scan, test, and...

Security That Works How Developers Work: Why Dev-Centric Design is Non-Negotiable
Security That Works How Developers Work: Why Dev-Centric Design is Non-Negotiable For years, application security has been treated as a destination—something developers "hand off" for validation at the end of the build process. But in a world of continuous...

Secure by Design: Embedding Risk-Based AppSec in Every Sprint
Secure by Design: Embedding Risk-Based AppSec in Every Sprint In the high-speed development world, embedding security into the software development lifecycle (SDLC) is no longer optional—it’s foundational. But as teams work to shift left and integrate security...

Beyond Automation: What True AppSec Orchestration Means in 2025
Beyond Automation: What True AppSec Orchestration Means in 2025 In the ever-evolving world of software security, “automation” has become a buzzword synonymous with efficiency, speed, and scalability. But in 2025, automation alone isn’t enough. As software delivery...

From Tool Overload to Targeted Orchestration: How to Simplify Your AppSec Stack
From Tool Overload to Targeted Orchestration: How to Simplify Your AppSec Stack As organizations race to secure increasingly complex software environments, many have responded by piling on more tools—scanners, dashboards, policy engines, ticketing systems, and more....

How Hackers Use AI Today—And How To Stay Safe – Forbes –
This article originally appeared on Forbes on July 23, 2025 Expert Panel® Forbes Councils Member Forbes Technology Council COUNCIL POST| Membership (Fee-Based) getty As artificial intelligence advances, so do the tactics of malicious actors. Hackers are now...

Weaponized AI Is Already Here. Is Your Security Strategy Ready?
Weaponized AI Is Already Here. Is Your Security Strategy Ready? The cybersecurity arms race has taken on a new dimension. With artificial intelligence accelerating innovation on both sides of the equation, it’s no longer just a question of who has the best tools —...

Wabbi Announces Findings of Annual Continuous Security Report
BOSTON / Press Release / May 6, 2024 Progress in Integrating Security into Software Development, Progress in Adoption, but Bottlenecks Persist Wabbi, the leading application security posture management platform, today announced the findings of its annual report on...

Wabbi Announces General Availability of its Advanced Application Security Risk Index Enabling Risk-Management-by-Design
BOSTON / Press Release / February 21, 2024 Wabbi, the leader in Application Security Posture Management (ASPM), today announced the general availability of its Advanced Wabbi Risk Index. The Application Security Risk Index is a key component of Wabbi’s...

Wabbi Announces Phil Lawrence as New CTO to Spearhead Next Generation Application Security Posture Management Platform
BOSTON, MA, USA / November 20, 2023 /Originally Published at EINPresswire.com Industry leading ASPM provider, Wabbi, has appointed Phil Lawrence as CTO to lead product vision and growth in this high-demand cybersecurity space. Today, Wabbi (www.wabbisoft.com), the...

Wabbi Founder & CEO, Brittany Greenfield, Named 40 under 40
BOSTON, MA, USA / August 16, 2023 Brittany Greenfield, CEO & Founder of Wabbi, the leading ASPM platform, has been named to Boston Business Journal's prestigious 40 Under 40 list for 2024. This annual award honors 40 outstanding professionals under the age of 40...

Wabbi Named in Three Gartner® Reports as ASPM Sample Vendor
BOSTON, MA, USA / August 1, 2023 For more information on Wabbi's Application Security Posture Management platform, visit https://wabbisoft.com. Wabbi, a leading provider of Application Security Posture Management (ASPM) solutions, is pleased to announce that it has...

WABBI NAMED IN 2023 GARTNER® HYPE CYCLE FOR APPLICATION SECURITY REPORT AS AN ASPM SAMPLE VENDOR
BOSTON, MA, USA / July 25, 2023 / Originally Published at EINPresswire.com/ Wabbi, the leading Application Security Posture Management (ASPM) platform, today announced that it has been recognized as a Sample Vendor for Application Security Posture Management (ASPM) in...

Wabbi Named in 2023 Gartner® How to Select DevSecOps Tools for Secure Software Delivery Report as an ASPM Sample Vendor
BOSTON, MA, USA / June 14, 2023 /Originally Published at EINPresswire.com Wabbi announces its inclusion in the 2023 Gartner® How to Select DevSecOps Tools for Secure Software Delivery report as an Application Security Posture Management (ASPM) sample vendor. Gartner®...

Wabbi Unlocks the Secret to Enterprise Secrets Management
Wabbi unveils new Secrets Mangement solution as part of their leading application security posture management and orchestration platform. BOSTON, MA, USA / May 17, 2023 /Originally Published at EINPresswire.com Today, Wabbi, a leader in Application Security Posture...

Wabbi Named to CyberTech 100 for Leadership in Application Security Posture Management & Orchestration for Financial Institutions
BOSTON, MA / May 11, 2023 / EINPresswire.com Wabbi, the leading application security posture management & orchestration company, announced today that it has been named in the CyberTech100 list for 2023. Sponsored by FinTech Global and now in its fourth year, the...

Wabbi Named Winner of the Coveted Global InfoSec Awards during RSA Conference 2023
Wabbi Wins Editor’s Choice for DevSecOps in 11th Annual Global InfoSec Awards at #RSAC 2023 SAN FRANCISCO/ Press Release / April 24, 2023 Wabbi is proud to announce we have won the following award(s) from Cyber Defense Magazine (CDM), the industry’s leading electronic...

AI is Solving the Puzzle. Are You Missing the Corner Pieces?
AI is Solving the Puzzle. Are You Missing the Corner Pieces? The game has changed—and it’s moving faster than ever. Artificial intelligence is no longer just a tool for innovation. It’s now a powerful asset in the hands of attackers, helping them scan, test, and...

Security That Works How Developers Work: Why Dev-Centric Design is Non-Negotiable
Security That Works How Developers Work: Why Dev-Centric Design is Non-Negotiable For years, application security has been treated as a destination—something developers "hand off" for validation at the end of the build process. But in a world of continuous...

Secure by Design: Embedding Risk-Based AppSec in Every Sprint
Secure by Design: Embedding Risk-Based AppSec in Every Sprint In the high-speed development world, embedding security into the software development lifecycle (SDLC) is no longer optional—it’s foundational. But as teams work to shift left and integrate security...

Beyond Automation: What True AppSec Orchestration Means in 2025
Beyond Automation: What True AppSec Orchestration Means in 2025 In the ever-evolving world of software security, “automation” has become a buzzword synonymous with efficiency, speed, and scalability. But in 2025, automation alone isn’t enough. As software delivery...

From Tool Overload to Targeted Orchestration: How to Simplify Your AppSec Stack
From Tool Overload to Targeted Orchestration: How to Simplify Your AppSec Stack As organizations race to secure increasingly complex software environments, many have responded by piling on more tools—scanners, dashboards, policy engines, ticketing systems, and more....

Weaponized AI Is Already Here. Is Your Security Strategy Ready?
Weaponized AI Is Already Here. Is Your Security Strategy Ready? The cybersecurity arms race has taken on a new dimension. With artificial intelligence accelerating innovation on both sides of the equation, it’s no longer just a question of who has the best tools —...

Why Dev Sec Ops is the Future of Secure Software Development
Why Dev Sec Ops is the Future of Secure Software Development As cyber threats become more sophisticated and development cycles accelerate, organizations can no longer afford to treat security as a last-minute checkpoint. Organizations are increasingly adopting Dev Sec...

The Cultural Shift Driving Dev Sec Ops Success
The Cultural Shift Driving Dev Sec Ops Success For years, security has been seen as the final step before deployment—a gatekeeper rather than an enabler. But as the software development lifecycle has evolved, so too has the need to integrate security into every phase...

Why Security Must Sit at the Table in Digital Transformations
Why Security Must Sit at the Table in Digital Transformations In today’s fast-moving world of digital transformation, organizations are under immense pressure to innovate quickly, scale rapidly, and deliver seamless customer experiences. But in that rush to...

Why Digital Transformation Fails (and How to Fix It): Foundations Over Flash
Why Digital Transformation Fails (and How to Fix It): Foundations Over Flash Digital transformation is one of those buzzwords that gets tossed around in boardrooms, strategy decks, and investor updates. But for many organizations, the actual experience of digital...