Hey, wanted to reply and drop you a note. I'm a co-founder at Aptible, and we spend a lot of time thinking about how to help developers in your situation.
In terms of general reading, I'd suggest:
--------------
Blogs:
Bruce Schneier [0]
Brian Krebs [1]
--------------
Whitepapers:
- Google's BeyondCorp paper touches on issues that most cloud-first companies will find familiar [2]
- AWS has a few that are good for seeing how a large company communicates the scope of it's security program to customers and potential customers. [3] I'd start with "Introduction to AWS Security Processes" aka "Overview of Security Processes" and "AWS Risk and Compliance".
- Verizon's Data Breach Investigations Reports [4]
--------------
Standards:
- Request your IaaS provider's SOC 2 Type II report
- ISO 27001 is worth buying
- The Cloud Security Alliance's CCM tries to cross-map different frameworks, and is a good reference for a high-level rundown of various security management controls and activities [5]
--------------
In terms of books, conferences, and meetups, I'm sure there is good stuff out there that I'm not aware of because of limitations on my time, sorry.
I hope this is helpful. Good luck! You (or anyone reading) can reach out to me at the email in my profile to chat about any of this.
p.s. Shameless plug: We are launching a product for managing infosec + compliance programs at companies like yours.
--------------
[0] https://www.schneier.com/
[1] https://krebsonsecurity.com/
[2] https://static.googleusercontent.com/media/research.google.c...
[3] https://aws.amazon.com/security/security-resources/
[4] http://www.verizonenterprise.com/verizon-insights-lab/dbir/
[5] https://cloudsecurityalliance.org/group/cloud-controls-matri...