Security teams are challenged to modernize application security practices in light of accelerating shifts to DevOps delivery models and rapid adoption of cloud-native application designs. Applications built on microservices (e.g. serverless, containers, APIs) and delivered continuously are outpacing application security teams ability to secure them. CISOs need to consider new skills, new touch points and new platforms to maintain a strong security posture in light of these trends and the speed at which they are re-shaping IT.
Application Security in a DevOps, Cloud and API World
CISO Council

Speakers
Karl Mattson
CISO
Noname Security
About Me
Esmond Kane
CISO
Steward Health Care System
About Me
Todd Gordon
CISO
EisnerAmper
About Me
Gary Eppinger
VP of Technology & CISO
CSX Corporation
Larry Whiteside
Co-Founder & President
Cyversity
About Me
Larry Whiteside Jr. is a veteran CISO, former USAF Officer, and thought leader in the Cybersecurity field. He has 25+ years’ experience in building and running cybersecurity programs, holding C Level Security executive roles in multiple industries including DoD, Federal Government, Financial Services, Healthcare, and Critical Infrastructure.
Larry currently serves as the Chief Technology Officer and Chief Security Officer at CyberClan, a full service Global Incident Response and Managed Security Services Provider for the small to medium sized business.
Larry is also the Co-Founder, President, and on the Board of Directors at the International Consortium of Minority Cybersecurity Professionals (ICMCP), a 501(c)3 non-profit association that is dedicated to increase the number of minorities and women in the cybersecurity career field through providing workforce development that includes skills assessment, training, education, mentorship, and opportunity.
Since 2009, via Whiteside Security, which he founded, Larry has advised several corporate security executives and companies across the cybersecurity industry on how to make Cyber Security a number one objective to their business. He has helped CEOs and board members of private cybersecurity companies achieve their goals in sales, marketing, and customer retention.
Larry has spoken in front of C Level leadership and Board of Directors of some of the largest private and public sector organizations in America. A thought leader in the industry with extensive experience presenting at conferences such as the Gartner Security Summit, RSA Conference, and SC World Congress, Larry has been featured in many articles relating to information security and risk management.
Larry received his Bachelor of Science degree in computer science at Huston-Tillotson University.
Ken Foster
Head of Global Cyber Risk Governance
Fiserv
About Me
Igor Volovich
Security Strategist
Cyber Strategy Partners
About Me
Igor Volovich is the founder and chief strategist at Cyber Strategy Partners, a Washington, DC‐area cybersecurity leadership and strategy advisory practice focusing on enterprise risk management, cyber defense, governance, and compliance, and national critical infrastructure protection, serving large-scale multinationals, public sector agencies, and emerging segments such as Smart Cities, Internet‐of‐Things (IoT), Industrial-Internet-of-Things (IIoT), and Smart Grid.
Mr. Volovich has recently served as Senior Advisor, Enterprise Security Architecture and Strategy, Office of the CISO at the United States Postal Service, advising senior executive leadership on cyber risk management strategies, program development, capability maturity improvements, and governance and compliance for the Postal enterprise including IT and OT environments, creating and guiding transformative initiatives across the cybersecurity program.
Previously, Mr. Volovich served as the Chief Strategy Officer at Romad Cyber, an emerging-stage endpoint security startup, where he led product and market strategy efforts leading to two consecutive Security Shark Tank® wins for innovation and product strategy, and development of $30M in net-new enterprise business.
Mr. Volovich served as the Chief Information Security Officer (CISO) and Vice President of Global Information Security at Schneider Electric, a $32‐billion 185,000‐staff industrial automation and energy management multinational, leading the firm’s information security functions in the Americas region. Prior to joining Schneider through a merger, Mr. Volovich served as the Chief Information Security Officer (CISO) and Vice President of Information Security and Cyber Risk Management of Invensys plc, a global $5B market leader in the fields of industrial process control, automation, and safety systems (ICS/DCS/SCADA).
Before entering private practice, Mr. Volovich served as a senior member of the Corporate Incident Response and Intrusion Detection Team at Microsoft’s Trustworthy Computing (TwC) organization, where he was responsible for the architecture and management of security controls deployed in protection of Microsoft’s global information assets, as well as internal investigations and incident response functions.
Additionally, Igor has volunteered as a STARS Mentor at MACH37 (mach37.com), the nation’s first cyber-focused startup accelerator operated in partnership with Virginia’s Center for Innovative Technology (cit.org) and CIT GAP Funds, advising founders and leaders of emerging cyber technology firms on product development, market positioning, and business strategy.
Mr. Volovich has worked with and advised some of the world’s leading firms including United States Postal Service, Schneider Electric, Invensys, Microsoft, MSN, IBM, Altria/Philip Morris, Standard & Poors, AT&T Wireless, Freddie Mac, FINRA, Estée Lauder, US Department of Defense, US Department of Labor, British Telecom, Pep Boys, Toyota Financial, Aviva, Asurion, as well as tech startups such as Romad Cyber, TeraBeam Networks, eCharge, and LivingSocial.
Mr. Volovich holds the CISSP designation from ISC², Certified in Risk Controls (CRISC), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA) designations from the Information systems Audit and Control Association (ISACA), and the Certified Information Privacy Professional (CIPP) certification from the International Association of Privacy Professionals (IAPP).
Mr. Volovich is a member of ISC², ISACA, InfraGard, NIST Cloud Forensics Working Group, US DHS ICS‐CERT, Alliance for Gray Market and Counterfeit Abatement (AGMA Global), and the Airborne Law Enforcement Association (ALEA). In addition to his professional work, Mr. Volovich volunteered as a Flight Officer with Virginia Airborne Search and Rescue Squad, serving the Northern Virginia and DC area communities, attaining the rank of Lieutenant, and serving as Chair of the Membership Committee and a Fundraising Committee member.
EVENT DETAILS
September 16, 2021
CouncilAgenda
3:00 PM-4:15 PM
Application Security in a DevOps, Cloud and API World
Panelists
Chair
Igor Volovich
Security Strategist
Cyber Strategy Partners
Igor Volovich is the founder and chief strategist at Cyber Strategy Partners, a Washington, DC‐area cybersecurity leadership and strategy advisory practice focusing on enterprise risk management, cyber defense, governance, and compliance, and national critical infrastructure protection, serving large-scale multinationals, public sector agencies, and emerging segments such as Smart Cities, Internet‐of‐Things (IoT), Industrial-Internet-of-Things (IIoT), and Smart Grid.
Mr. Volovich has recently served as Senior Advisor, Enterprise Security Architecture and Strategy, Office of the CISO at the United States Postal Service, advising senior executive leadership on cyber risk management strategies, program development, capability maturity improvements, and governance and compliance for the Postal enterprise including IT and OT environments, creating and guiding transformative initiatives across the cybersecurity program.
Previously, Mr. Volovich served as the Chief Strategy Officer at Romad Cyber, an emerging-stage endpoint security startup, where he led product and market strategy efforts leading to two consecutive Security Shark Tank® wins for innovation and product strategy, and development of $30M in net-new enterprise business.
Mr. Volovich served as the Chief Information Security Officer (CISO) and Vice President of Global Information Security at Schneider Electric, a $32‐billion 185,000‐staff industrial automation and energy management multinational, leading the firm’s information security functions in the Americas region. Prior to joining Schneider through a merger, Mr. Volovich served as the Chief Information Security Officer (CISO) and Vice President of Information Security and Cyber Risk Management of Invensys plc, a global $5B market leader in the fields of industrial process control, automation, and safety systems (ICS/DCS/SCADA).
Before entering private practice, Mr. Volovich served as a senior member of the Corporate Incident Response and Intrusion Detection Team at Microsoft’s Trustworthy Computing (TwC) organization, where he was responsible for the architecture and management of security controls deployed in protection of Microsoft’s global information assets, as well as internal investigations and incident response functions.
Additionally, Igor has volunteered as a STARS Mentor at MACH37 (mach37.com), the nation’s first cyber-focused startup accelerator operated in partnership with Virginia’s Center for Innovative Technology (cit.org) and CIT GAP Funds, advising founders and leaders of emerging cyber technology firms on product development, market positioning, and business strategy.
Mr. Volovich has worked with and advised some of the world’s leading firms including United States Postal Service, Schneider Electric, Invensys, Microsoft, MSN, IBM, Altria/Philip Morris, Standard & Poors, AT&T Wireless, Freddie Mac, FINRA, Estée Lauder, US Department of Defense, US Department of Labor, British Telecom, Pep Boys, Toyota Financial, Aviva, Asurion, as well as tech startups such as Romad Cyber, TeraBeam Networks, eCharge, and LivingSocial.
Mr. Volovich holds the CISSP designation from ISC², Certified in Risk Controls (CRISC), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA) designations from the Information systems Audit and Control Association (ISACA), and the Certified Information Privacy Professional (CIPP) certification from the International Association of Privacy Professionals (IAPP).
Mr. Volovich is a member of ISC², ISACA, InfraGard, NIST Cloud Forensics Working Group, US DHS ICS‐CERT, Alliance for Gray Market and Counterfeit Abatement (AGMA Global), and the Airborne Law Enforcement Association (ALEA). In addition to his professional work, Mr. Volovich volunteered as a Flight Officer with Virginia Airborne Search and Rescue Squad, serving the Northern Virginia and DC area communities, attaining the rank of Lieutenant, and serving as Chair of the Membership Committee and a Fundraising Committee member.
Speaker
Karl Mattson
CISO
Noname Security
Speaker
Esmond Kane
CISO
Steward Health Care System
Speaker
Todd Gordon
CISO
EisnerAmper
Speaker
Gary Eppinger
VP of Technology & CISO
CSX Corporation
Speaker
Ken Foster
Head of Global Cyber Risk Governance
Fiserv