Traditional perimeter-based security (“castle-and-moat”) is obsolete in modern distributed, cloud-native engineering environments. This session demystifies how to apply Zero Trust Architecture (ZTA) directly into the Software Development Lifecycle (SDLC), moving security from a network-layer boundary directly into application logic, identity propagation, and deployment automation.
Attendees will learn how to shift from implicit trust assumptions to explicit, continuous verification across source code repositories, automated CI/CD pipelines, workload-to-workload communication, and cloud infrastructure. We will cover real-world architecture patterns, developer tooling, and actionable steps to build resilient, tamper-evident software architectures without compromising engineering velocity.
Key Takeaways
- Core Zero Trust Principles in SDLC: Translate NIST SP 800-207 and CISA Zero Trust models into concrete software design, identity-centric authentication, and micro-segmentation strategies.
- Workload Identity & Service Authentication: Replace static credentials and long-lived secrets with ephemeral, cryptographically verifiable workload identities using SPIFFE/SPIRE, mTLS, and OIDC.
- Software Supply Chain Security: Implement end-to-end provenance, cryptographic commit signing, automated dependency attestations (SLSA framework), and signed SBOMs across CI/CD pipelines.
- Developer Experience & Guardrails: Embed automated policy-as-code (OPA/Cedar), continuous authorization, and automated pipeline guardrails that empower developers rather than slow them down.
Target Audience
- Software Engineers, DevOps/DevSecOps Engineers, Cloud Architects, Application Security Specialists, and Engineering Leaders looking to modernize security practices across distributed architectures.
Prerequisites
- Basic understanding of application architecture (APIs, microservices, cloud deployments) and fundamental security concepts (authentication, tokens, CI/CD pipelines).