- Member Interview
Member Spotlight: DeCaPa
DeCaPa is a Security Architect with a focus on security, compliance, and privacy. With a background in Application Security Architecture and Cloud Security, he works seamlessly with application architects, IT, and business leaders to ensure investments are secure, compliant and meet corporate risk objectives.
As one of the founding members, DeCaPa has been a notable asset in the Veracode Community. Drawing from his decades of experience implementing DevSecOps for organizations, he leads discussions and shares his insights across numerous AppSec topics, such as getting buy-in for AppSec investment, standing up a security champion program, and driving developer engagement.
In addition to his engagement in the Veracode Community, he is also active in various local tech User Groups, including the WebSphere User group, Java User Group, local OWASP, AWS meetup, and Infragard chapters, where he has undertaken leadership roles and given workshop presentations.
Learn more about DeCaPa in this recent interview:
About Your Experience with Veracode & Community
Profession: What are your current role and your responsibilities in your company?
Security Architect. In addition to Application Security, I focus on privacy, compliance, and security solutions and technologies. I regularly work with teams across the enterprise, from developers and security architects, to our cybersecurity group where I’m socializing for a DevOps-focused Application Security (AppSec) program, with all the bells and whistles.
Which Veracode product(s) do you use? What problems were you trying to solve and how did the product(s) help you achieve your goals?
The current company I work for does not leverage Veracode products. While that may change one day, I have experience with Veracode’s SAST, DAST, SCA and Education products. Products are a great compliment (or dare I say requirement) to an AppSec program. I also find it just as important to have established people and processes in addition to leveraging technologies. After all, who is going to own and operate it? How will it be used? What process should be followed?
When did you join the Veracode Community? What motivates you to contribute to the Community?
I joined the Veracode Community while at my last job, where Veracode products were used as the cornerstone to my AppSec Program. I had gotten so much value from the Community that I continue to hang around! I’m proof that the Veracode Community is not only for companies that license Veracode products but serves as a valuable collaborative space for AppSec communities as a whole. I’ll stick around as long as Veracode will have me.
About You
Have you picked up any new hobbies – or revisited a long-lost one – during the pandemic? (Feel free to add any picture!).
I have begun doing more cooking and baking since the pandemic has limited dining opportunities. It turns out that you can make healthy and great tasting food at home! Who knew?
Can you share with us a favorite podcast, movie, song, blog, or book? We’re all about finding something new and interesting to listen to/watch/read :)
I like Security Journey’s, “The Application Security Podcast”. Chris Romeo and Robert Hurlbut interview AppSec experts and discuss relevant topics. A lot of AppSec podcasts have come and gone, but this one has stood the test of time. One of the best I’ve heard.
Have a question?
Ask our Community of Veracode product experts and AppSec leaders.
.png)