VOOZH about

URL: https://thenewstack.io/gitlabs-security-officer-on-an-easier-path-to-app-security/

⇱ GitLab's Security Officer on an Easier Path to App Security - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2023-10-02 05:00:27
GitLab's Security Officer on an Easier Path to App Security
sponsor-gitlab,sponsored-topic,
AI / Frontend Development / Security / Software Development

GitLab’s Security Officer on an Easier Path to App Security

GitLab CISO sees a path to better security practices by leverage automation and machine learning while developers are still coding.
Oct 2nd, 2023 5:00am by Loraine Lawson
👁 Featued image for: GitLab’s Security Officer on an Easier Path to App Security
Image via GitLab

Security tends to be a checklist for developers — one more thing to tick off on a long list of tasks to check off while creating an application. Time and time again, security pros have said security needs to start with developers. But developers haven’t always felt the same way. That’s changing, said Josh Lemos, who became GitLab’s new chief information security officer in June.

Security is becoming more of a domain, similar to performance and observability, where developers have some portion of security as a functional responsibility within their role, whether that means using some kind of paved road, or whether that means that they have to know what a good security design pattern is to implement that in their codebase,” Lemos told The New Stack. “And for me, that’s encouraging, because for a very long time, it wasn’t that way.”

GitLab is the most comprehensive, intelligent DevSecOps platform for software innovation. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation.
Learn More
The latest from GitLab

Rethinking Security and Development

But what really needs to change is that security needs to be baked into development tools, he said. In his previous roles with companies such as ServiceNow, Square and Cylance, the goal was to design good security patterns into the developer tools so that developers can manage security as part of their normal workflow, he said.

“What we did was we build systems that would have Infrastructure as Code components ready to deploy in a modular fashion, we abstracted away the complexity of authentication and authorization interfaces for APIs, and developers could just adopt the design pattern that was there in place and not have to write their own and reimplement it,” he said, adding that it’s a boring solution but it created consistency and drove better security outcomes.

If a developer didn’t use that security design pattern, his team would investigate to find out why not.

“It allowed our security team to then focus effort on creating an alternative design pattern, if that was necessary,” he said.

That’s why he came to GitLab, he said. He realized there are thousands of companies that don’t have the resources to engineer their own security patterns.

“If I could express that same value for 1,000s of companies and millions of developers, that could be a lot more powerful in terms of a contribution to the broader infosec landscape,” he said. “We’re running millions of the world’s build pipelines as well. So it’s not just the source code repository aside, but also the building and deploying that software.”

Developers Want Automation and Velocity

GitLab is focused on opportunities to improve automation and velocity, two themes that he said keep coming up with developers.

“We’re going to have to build our own security tools that automate at the same velocity, and that are able to evaluate security issues at the scale of software development, at the speed of software development, rather than having security as a gatekeeping function, which has been on the way out for the last 10 years,” he said.

Gitlab is looking at both traditional methods as well as machine learning to examine developer concepts such as code coverage and integration tests. Machine learning can provide visibility into security vulnerabilities and fixes for them. For instance, it can help with vulnerability and reachability issues, such as: is this code ever called when there’s a security vulnerability that comes with it, and whether it’s fixable.

“That allows us to prioritize our vulnerability patching efforts or remediation efforts based on empirical data that we know to be true about the accessibility of those vulnerable code functions,” he said.

He also sees meaningful use cases with generative AI that can accelerate GitLab’s security program. For instance, a purpose-built chatbot trained on open source code could allow developers to ask questions as they code, like is it safe to use this package, or provide a secure design pattern for a function for this version, and get an answer.

“Those are very powerful potential use cases for self-service in the developer workflow, without leaving their development environment to find those answers, without having to track down an application security engineer, without having someone necessarily review their code at human scale,” he said. “Security is going to have to keep pace with automation and software velocity, and it’s going to happen at a programmatic scale, not a human scale.

GitLab is the most comprehensive, intelligent DevSecOps platform for software innovation. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation.
Learn More
The latest from GitLab
TRENDING STORIES
Loraine Lawson is a veteran technology reporter who has covered technology issues from data integration to security for 25 years. Before joining The New Stack, she served as the editor of the banking technology site Bank Automation News. She has...
Read more from Loraine Lawson
SHARE THIS STORY
TRENDING STORIES
TNS owner Insight Partners is an investor in: Pragma, Velocity.
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.