Search Results for "2017"

Speaker Feature: Jason Ross

algorythm@gmail.com

@rossjafmqH88GC.jpg (278×278)

Jason Ross is a Senior Consultant with NCC Group – a global information assurance specialist providing organizations with expert security consulting services. Working primarily from Rochester, NY, he has developed and delivered training tools and programs on topics such as advanced mobile penetration testing, android forensics techniques, and enterprise-level malware analysis.
Jason has spoken at many regional conferences across the United States, as well as major security conferences including Blackhat DC, BSides Las Vegas, DerbyCon, and DEF CON Skytalks.

DevOpSec – Killing the Buzz

The DevOps movement continues to grow, and it is beginning to move out of small startups into large enterprises. DevOps and Agile development bring a lot to the table, but are often viewed as coming at the expense of security. This presentation explores ways to integrate security into DevOps environments: identifying the benefits of doing so, outlining potential problems, and attempting to provide solutions to them. Ultimately, the talk hopes to provide practical guidance and tools that can be used as a base to improve security throughout the stack.

Come see me at RVAsec 2017. Register Now!

 


Speaker Feature: Mike Shema

mikeshema@yahoo.com

@CodexWebSecurumAAEAAQAAAAAAAAoZAAAAJGYwM2QxYmQwLThlNDktNGU4Mi1iNDhlLWFlMWUzZWY2OGI3MQ.jpg (200×200)

Mike Shema is VP of SecOps and Research at Cobalt.io, where he organizes crowdsourced pen tests. Mike’s experience with information security includes managing product security teams, building web application scanners, and consulting across a range of infosec topics. He’s put this experience into books like Anti-Hacker Tool Kit and Hacking Web Apps. He has taught hacking classes and presented research at conferences around the world.

Managing Crowdsourced Security Testing

The crowdsourced security model has been embraced by organizations running public bug bounty programs. These programs are intended to discover and resolve vulns in production applications, but they can unexpectedly deviate from being an effective part of the security development lifecycle into a source of noise. This presentation questions what role such programs have in improving security and what pitfalls they pose for security budgets. It covers strategies for keeping a bounty program focused on positive contributions to development and avoiding the traps that make it a distraction.

Come see me at RVAsec 2017. Register Now!


Speaker Feature: Seth Hanford

shanford@ckure.com

@SethHanfordbd0ca9e985a4cf12ed87d3247057a2ef.jpeg (500×500)

As a Staff Information Security Engineer, Seth Hanford applies his experience to incident response, PSIRT, and security operations functions for both enterprise and customer security. Hanford has been an individual contributor for PSIRTs, CSIRTs, and intelligence teams in small businesses, large enterprises, and several global teams. He has worked on-site in operations center watch floors, collaborated globally with FIRST Special Interest Groups, and has more than a decade of experience being an effective full-time remote worker. He has also had the pleasure to serve as a manager both globally and locally, and recruited for world-class threat research teams as well as to relaunch a Fortune 100 SOC into a threat-driven detection & response team.

Defend the Defenders: Managing and Participating in Excellent Teams

Response teams apply threat models to protect an organization’s goals and to determine which controls are important to defend organizational interests. But defensive teams themselves are under threat: working in emergency response takes its toll on individuals. Budgets, over-commitment, urgency, and crisis all put a great deal of pressure on incident responders. This presentation will examine “threats against the goals of the SIRT itself” for managers and “blue team” practitioners: how to build, manage, and participate a defensive / incident response team under fire. Attendees will learn a practical approach for identifying and defending against the key threats against their team goals. The speaker will share examples from his own past threat modeling, such as: how to find, hire, and retain good candidates; how to maintain morale when under crisis; how to improve a struggling team; how to (re)organize to meet imminent challenges to long-term success; and more.

Come see me at RVAsec 2017. Register now!


Speaker Feature: Greg Pepper

gpepper@checkpoint.com

@pepper_greg

Greg Pepper has been an IT professional for 15+ years with expertise in Security, Networking & Cloud Computing. Initially working for Sony Online Entertainment, PriceWaterhouse Coopers & Organic, Greg has spent the last 15 years working for Cisco & Check Point helping customers to design, plan and implement secure networks throughout the Internet Edge, Campus Backbone, Data Center and Cloud Environments. Currently as Head of Cloud Security Architects for Check Point, Greg focuses on Software Defined Data Centers working with customers and partners to secure Software defined solutions with in Amazon Web Services, Microsoft Azure, VMware NSX, Cisco ACI and OpenStack.

Best Practices for Securing the Hybrid Cloud

Cloud has enabled applications and infrastructure to move at a pace not seen before. Organizations are faces with options to invest in and enhance their physical data centers to deploy SDN and build private clouds. Alternatively, many companies are choosing to migrate these applications in to the Cloud. Public Cloud options for Infrastructure as a Service and or Platform as service exist, but there exists a shared responsibility for security in either of those scenarios. Come learn strategies, design templates and best practices on how to secure applications through automation & orchestrations, making security as a integral part of the cloud and SDN deployments.

Come see me at RVAsec 2017. Register Now!


Help Choose The RVAsec 6 Logo!

The conference is fast approaching and we are in high gear planning RVAsec. The CFP just closed and the committee is in the process of reviewing and choosing talks for this year. We hope to publish the speaker selection very soon!

2017 Badge Voting

A quick reminder that you have until April 21st until ticket prices increase. If you have not yet purchased your ticket, go get it done now!

This year we are again having a logo contest for the conference and shirts!

We need your help — vote for your favorite logos!

Here is the link for the RVAsec logo voting:
https://99designs.com/contests/poll/mbgu8k

Thanks everyone for your help, and please spread the link so we get as many votes as possible!


Speaker Feature: Andrea Matwyshyn

 

www.andreamm.com

@amatwyshyn

Dr. Andrea M. Matwyshyn is a legal academic studying technology innovation and its policy implications, particularly corporate information security regulation and consumer privacy. She is currently a (tenured full) professor of law/professor of computer science (by courtesy) at Northeastern University, a faculty affiliate of the Center for Internet and Society at Stanford Law School, and a visiting research collaborator at the Center for Information Technology Policy at Princeton University, where she was the Microsoft Visiting Professor during 2014-15. In 2014, Professor Matwyshyn served as the Senior Policy Advisor and Academic in Residence at the U.S. Federal Trade Commission. She has testified in Congress on issues of technology innovation and information security regulation and is a US-UK Fulbright Commission Cyber Security Scholar award recipient in 2016-2017.

CYBER!

This talk challenges the underlying assumptions of the “cyber” or “cybersecurity” legal and policy conversation. It argues that the two dominant paradigms – information sharing and deterrence – reflect last century’s policy approaches that channel our security energies in misguided directions: in their current form, they will neither thwart technology-mediated attacks on our national security nor meaningfully bolster consumer protection. Drawing insights from the work of seminal philosopher of science Michael Polanyi, this talk first identifies four analytical flaws that plague the legal and policy analysis of information security. It then offers a new policy paradigm – reciprocal security inducement. Reciprocal security inducement reframes the legal and policy security conversation around two key elements: information vigilance infrastructure and defense primacy. The talk concludes with a list of concrete legal and policy suggestions reflecting the reciprocal security inducement paradigm.* *This talk contains bacon.

Come see me at RVAsec 2016! Register now.

 


Sponsors-Old

Platinum Sponsors

VCU Technology Services
Altria Client Services
CrowdStrike

Gold Sponsors

Assura Consulting
Fortinet
Carmax
Okta
University of Richmond School of Continuing and Professional Studies
RSA
Rapid7

Silver Sponsors

Trend Micro
BHIS
Risk Based Security
Advanced Network Technologies
Extrahop
Focal Point Data Risk
Cyberark
ISACA Virginia Chapter
Infoblox
Deltarisk
Aruba Networks
Segra Communications
NC4
Tenable Security
Checkpoint Security
Optiv
Netskope
Palo Alto Networks
Malwarebytes
ePlus
Venafi
Infranet
Intsights
LogRhythm

Bronze Sponsors

GE

Mobile Site Sponsor

Badge Sponsor

Cisco

CTF Sponsor

Capital One

Hospitality Sponsors

SentinelOne
Lacework

After Party Sponsors

Risk Based Security
Guidepoint Security

CTF Support & Prize Sponsors

Netsparker

Speaker Dinner Sponsor

Varonis

Reception Sponsor

Vector

Room Sponsors

McAfee
Atos

Bag Sponsor

Fortinet

Associate Sponsors

Akamai
cirt.net

Wifi Sponsor

ABS Technology

Ice Cream Sponsor

Risk Based Security

Popcorn Sponsor

Zscaler

About RVAsec

RVAsec is the first Richmond, VA based security conference to bring top speakers to the mid-Atlantic region.

Why Sponsor

RVAsec is the only security conference between Washington DC and Raleigh NC, reaching a largely untapped market of security professionals and executives. We expect RVAsec 2019 to be approximately 650-700 people–a mix of technical engineers, managers and CISOs. Sponsorship has the potential to reach local attendees from several large corporations, including Capital One Bank, Carmax, Dominion, Markel, Altria, Genworth, GE, Federal Reserve Bank of Richmond, Anthem, and MeadeWestvaco, among others.

Levels

We have multiple sponsorship levels to meet your needs–each level includes various items and perks. There are a limited numbers of sponsors at each level, and sponsors are picked solely at the discretion of RVAsec in order to best serve our attendees and sponsors. We are also seeking sponsors for items such as breakfast, lunch, breaks, receptions and after-parties!

 Contact Us!

If you are interested in sponsoring this event or have any questions, please contact sponsors@rvasec.com to request the full sponsor marketing package.