Security teams are challenged to modernize application security practices in light of accelerating shifts to DevOps delivery models and rapid adoption of cloud-native application designs. Applications built on microservices (e.g. serverless, containers, APIs) and delivered continuously are outpacing application security teams ability to secure them. CISOs need to consider new skills, new touch points and new platforms to maintain a strong security posture in light of these trends and the speed at which they are re-shaping IT.
CISO
CISO Council
Application Security in a DevOps, Cloud and API World

Speakers
September 16, 2021
CouncilNavigating 3rd Party Risk
Filling the Talent Void
The Greatest Fears?
Technology Supply Chain
Being Effective…. Securely
AI and ML: Using Emerging Technologies to Reinforce Security Defense Efforts
Patch Management and Endpoint Protection
Data Security: Cloud Computing, Mobility and Regulations
Agenda
All times Eastern Standard Time (EST)
3:00 PM - 4:15 PM
Application Security in a DevOps, Cloud and API World
Panelists
Karl Mattson
CISO
Noname Security
As a future-oriented information security executive my key strength is coaching and educating cybersecurity companies on listening to and interpreting the pain-points and priorities of enterprise customers. These insights help drive effective product strategies, go-to-market strategies and ongoing customer success.
Over the years, I’ve had the privilege of advising several cyber entrepreneurs who are now thriving. On the heels of their success, I was looking for a new challenge. In 2020, I had the opportunity to meet with the Noname Security team early in its platform design. Recognizing that they were on the verge of solving several challenges in securing APIs, I wanted to be a part of their exciting adventure.
I joined Noname as Chief Information Security Officer, where I’m currently establishing a rigorous standard for operational and security excellence, in addition to advocating for ongoing platform changes based on our customers’ needs.
ABOUT NONAME SECURITY:
Noname Security ensures secure APIs at the speed of business with the most powerful, complete and easy-to-use API security platform. How do I know it works? I was their first customer! I believe in the platform and want to share it with the world.
According to Gartner, APIs will be the #1 attack vector by 2022. Gateways and WAFs don’t protect against API breaches or find misconfigurations. API testing and bug bounty programs have significant gaps, leaving businesses exposed.
Noname resolves API vulnerabilities across 4 key pillars, or as we call it, DART:
➤ Discover
➤ Analyze
➤ Remediate
➤ Test
We’ll find and take inventory of all existing APIs, use AI-based detection to illuminate risks, block attacks in real time and run tests to ensure API integrity before production.
WHAT YOU CAN EXPECT:
➤ Solid engineering underpinning a product that’s ahead of the competition
➤ Flexible deployment model with many integrations that adapt to your business
➤ Coverage of the 3 main areas needed to protect APIs: posture management, detection and response and code security
What are you doing to protect your company’s digital content? Keep your company’s APIs out of the news with Noname Security.
LEARN MORE:
See what our customers are saying about us and find more information on our website: www.nonamesecurity.com
Esmond Kane
CISO
Steward Health Care System
Esmond Kane currently serves as Chief Information Security Officer (CISO) at Steward Health Care, a 35 hospital, multi-state healthcare organization that provides world class care to millions of patients annually. In his role at Steward, Esmond’s focus has been on transforming Steward’s approach to information security, threat, and risk management to comply with industry frameworks, regulations and best practices.
Esmond has over 20 years’ experience leading IT and Security programs in multiple industries. Before joining Steward he served as Deputy CISO at Partners Healthcare in Boston, working with executives and advisors on cyber security and business practice
Todd Gordon
CISO
EisnerAmper
EisnerAmper clients are based in the U.S., or comprised of U.S. business interests of foreign entities. To serve domestically-based clients with interests in financial services opportunities overseas, Eisner Amper offers the resources of offices in the UK, Israel, India and EisnerAmper Global, with offices in the Cayman Islands, Singapore, and Ireland; as well as the services of Allinial Global.
Todd, leads the information security team and is an experienced, detail-oriented, and innovative professional with proven performance in information security, enterprise-level systems administration, and project management.
Gary Eppinger
VP of Technology & CISO
CSX Corporation
Ken Foster
Head of Global Cyber Risk Governance
Fiserv
Accomplished CISO with proven track record of implementing Cyber Security programs and strategy, a US Navy Veteran with expertise in Information Risk, Governance, and IT enterprise operations and enterprise architecture in the public and private sectors. Transformational leader that excels at developing and implementing strategic, technical, and operational security/infrastructure architectures that are aligned with business goals and objectives using a risk based methodology. Established history of innovation, utilizing technology and processes effectively to minimize operational risk, cost, and increase operational efficiency to meet business goals by building a strategy that becomes a business differentiator