GitHub is doubling down on security with the hiring of the National Security Agency’s former head of open source Jacob DePriest. He recently joined the company as VP of security operations.
“When we talk about security on the platform and security for our community, our goal is to shift left really in all aspects of security,” DePriest said in an interview with SDxCentral. “In today’s age, every developer needs to understand a little about security, or has to think about and account for security.”
GitHub’s goal is to make that seamless and built-in, while starting as far left as possible from the platform and tools.
GitHub serves over 65 million developers globally. The company recently rolled out new tools for GitHub Advanced Security suite featuring code scanning and dependency review.
Over the next couple of years, open source will be even more impactful, as the security landscape shifts, DePriest said. GitHub has a responsibility to make open source as secure as it can through its products, infrastructure and platform, he added.
At NSA, DePriest was in charge of fostering private and public sector engagement with the open source community. However, he was involved in open source even back in the school, DePriest said.
He built the developer experience function during his tenure at the agency — this is open source software available to the public — and also worked on enterprise security and cloud-facing security. The opportunity to join the GitHub team aligned with his passions, DePriest said.
This is GitHub’s second security executive hire in recent months. In February, the company appointed Mike Hanley, Cisco’s former CISO as its first-ever chief security officer.
In 2019, a ransomware attack hit user accounts on GitHub and two other organizations. The attacker used automated means to take over repositories linked to the targeted accounts with weak passwords.
UPDATE: This story has been updated to clarify comments that developers need to take into account security requirements and the impact open source is having as the market shifts.
Comments