Home / Companies / Endor Labs / Blog / Post Details
Content Deep Dive

Under the Hood: Jellyfish’s Data-Driven Security Program

Blog post from Endor Labs

Post Details
Company
Date Published
Author
James Kirk
Word Count
2,175
Company Posts That Month
9
Language
English
Hacker News Points
-
Post removed?
No
Summary

The blog post by Jellyfish security team members James Kirk and Josiah Bruner discusses the establishment and evolution of Jellyfish's security team, highlighting their unique approach to integrating security into the software development lifecycle. At Jellyfish, security is embraced not as a regulatory burden but as an integral part of product development, thanks to a pre-existing culture of "shift left" security. The company utilizes data-driven methods to measure and predict security effectiveness, focusing on swift incident response and risk management rather than merely counting vulnerabilities. The post also details their journey to find a suitable software composition analysis (SCA) tool, culminating in their adoption of Endor Labs due to its function-level reachability and efficient risk prioritization capabilities. This tool has significantly improved their ability to accurately assess and mitigate risks, allowing them to confidently report security status to executives and the board. Additionally, Jellyfish's security team works closely with developers to prevent the introduction of new risks, using policies to manage dependencies effectively. Overall, the post emphasizes a collaborative and proactive approach to security, treating it as an equal partner in engineering efforts.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.