Rockstar shopping is inherently unsafe (2015)
graham.posthaven.com
graham.posthaven.com
1. I made some mistakes (my general response to said mistakes was to work to ensure the CI tool guaranteed said mistakes couldn't be repeated. Included kicking up CI into the process in the first place by fixing their test rot and enabling someone else to bring jenkins into the mix). One of those mistakes did cause a recoverable partial outage.
2. The extensive unfucking of the backend I performed still hasn't been applied, despite pretty clear demonstration of the safety of said changes . One of which if eventually applied will reduce their AWS bill by 10-20% - I produced a demo that this was safe bug-for-bug. A spectacular security hole that was there is gone, so that's a plus.
I got retrenched (made redundant with a small payout once I pointed out that was what was needed). I went into the conversation to say "I'm going to need more money and we need to work out a process where my work gets applied", but the retrenced bit happened really early, so I never got to propose that :) . I had an offer within an hour of being retrenched. Currently I unfuck code at a similar scale for a larger concern and get reasonable career development opportunities. The place I was working for has been hiring junior devs like crazy, so I do worry about the health of their codebase - having said that when in their comfort zone the senior guys there are pretty good. I think the problem was that I was getting the senior guys out of their comfort zone, and I didn't take a sufficiently gentle approach. However I learned heaps, so all good. Can't imagine I'll be going back their though.
Security is very multi-faceted. Securing your internal/IT applications is very different than writing secure code which in turn may be different than some other specialized situation. Ideally you already have some people who have some clue and/or have seen something that works somewhere else from an organizational perspective (or have seen things that don't work that you don't want to repeat). E.g. you may have some IT person who isn't a security expert who has worked in a team that had a stronger security bias/expertise and has seen how that team worked/was structured. You may have a senior coder who has pretty solid ideas about security but it's not his main expertise. Leverage that stuff! Talk to those guys about how to build the team...
Prince saying "I need a camel" in the middle of the night on Chanhassen, MN?