Patch Me If You Can™

RBAC is Broken (Here's Why) with Dmitri Altum, GitLab, ex-Ramp

24 min · 17. Sept. 2025
Episode RBAC is Broken (Here's Why) with Dmitri Altum, GitLab, ex-Ramp Cover

Beschreibung

In this episode of Patch Me If You Can™, Arek Dreyer sits down with Dmitri Altum, Staff Security Engineer at GitLab, who breaks down why Role Based Access Control (RBAC) is failing modern businesses. Dmitri shares his experience building dynamic identity systems that analyze user behavior rather than relying on static job titles, especially as AI blurs traditional role boundaries. He also demonstrates how his team achieved 93% automated approval rates with just 3 second response times, proving that security and speed don't have to pull in opposite directions.

Kommentare

0

Sei die erste Person, die kommentiert

Melde dich jetzt an und werde Teil der Patch Me If You Can™-Community!

Loslegen

2 Monate für 1 €

Dann 4,99 € / Monat · Jederzeit kündbar.

  • Podcasts nur bei Podimo
  • 20 Stunden Hörbücher / Monat
  • Alle kostenlosen Podcasts

Alle Folgen

11 Folgen

Episode Balancing Security with Speed with Ralph Pyne, CISO, Apollo.io Cover

Balancing Security with Speed with Ralph Pyne, CISO, Apollo.io

In this episode of Patch Me If You Can™, Ralph Pyne, CISO at Apollo.io, reveals why traditional security approaches are failing in the age of AI and citizen developers. Ralph shares hard-won insights from building zero-to-one security programs at high-growth startups, including why the principle of least privilege access is fundamentally broken and how AI is making most security controls obsolete. Ralph discusses topics such as the explosive growth of citizen developers using AI coding tools and the security challenges this creates when thousands of single-use apps can emerge across an organization in months, as well as his contrarian view that security teams need to assume failure and move toward statistical models similar to fraud prevention, rather than trying to achieve perfect access controls. The conversation covers practical strategies in areas such as building security programs that accelerate rather than slow down business growth, and making security training and policies more human-centered and consumable.

17. Juni 202628 min