logo

Cloud Security Alliance Webinar Recap: Avoid the Breach with Shopify’s Andrew Dunbar

ID: c891f761-f5bc-5fb5-8d27-e0f28b47908e

STIX ID: report--c891f761-f5bc-5fb5-8d27-e0f28b47908e

Feed Name: HackerOne Blog

Date Published: 2023-07-27

Date Updated: 2026-06-11

...
...

This CSA fireside chat summarizes Shopify’s application security approach, focusing on automation, standardized tooling and environments, close partnerships between security and product engineers, and pragmatic risk management. Key points include vetting new languages and tools via Hack Days, building vulnerability-management tooling that integrates with developer workflows, a simple high/low risk rating model, the concept of “trust batteries” for stakeholder trust, and reliance on bug-bounty programs to surface hard-to-find issues.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.