#devsecops
2 essays on devsecops from the people writing in Remote Since Forever.
- Essays
- 2
- Contributors
- 1
- First filed
- Jul 2026
- Latest
- Jul 2026
Written by
NH
-
jwt
How a JWT Audience Map Saved a CORS Mistake: A Defense-in-Depth Case Study
On a client's API, a CORS wildcard looked like a HIGH severity finding — until we tried to actually exploit it. A second, independent JWT audience check turned a trivially exploitable bug into one that required a much harder prerequisite.
-
devsecops
From DevOps to DevSecOps: How I Became Clearview's In-House Pen-Tester
How we built an in-sprint pen-tester role into every engagement — the DevSecOps handoff, the two decades of DevOps that led to it, and the OWASP Top 10 categories that show up first in real client APIs.
No essays match that search.