Interview with Ariel Shin

Listen to full episode :

Join Ariel Shin, Twilio's Product Security Team Lead, as she simplifies the complex topic of vulnerability management in governance, risk, and compliance (GRC). In this podcast, Ariel helps us grasp the various roles that stakeholders play, the essentials of policy and standards documents, and how vulnerabilities, risks, and incidents are connected. She clarifies technical terms like 'zero-day' and 'exploitability' and discusses why it's crucial for companies to be open about their security practices.

We also tackle the tricky subject of meeting compliance and security standards across different industries. Ariel uses the OWASP mobile checklist to highlight the challenges of applying one set of rules to all kinds of organizations and talks about the 'NIST peanut butter' approach in security discussions. We emphasize the need to communicate compliance requirements effectively to various audiences.

In the concluding part, Ariel and I discuss how GRC and developers can work together more effectively to manage vulnerabilities. We look at the obstacles in compliance and the importance of clear communication and influence in prompting developers to fix security issues. Ariel gives valuable advice on automated reporting and the best ways to report security matters to management.

So, tune in to get a clearer picture of vulnerability management, learn strategies for engaging with stakeholders, and gain insights into building a straightforward program that connects vulnerability management, security risk, and incident response.


Connect With Our Guest


Show Collateral

In August 2023, more than 30 Twilions from the Information Security (InfoSec) team attended DEFCON 31

I’m plugging another podcast here. I’ve listened to this episode multiple times and we only scratched the surface on the things she covered here with respect to the concept of “Democratized Vulnerability Management”

Just look up “Ariel Shin” on YouTube. She’s been on a few different shows and each clip/episode is a banger. Click around, learn something.

Previous
Previous

Interview with Alex Bovee

Next
Next

Interview with Jeevan Singh