Preview of talk: Gotcha! Hard-Won Lessons in Identity Automation
Preview of talk: The Security Policy Rollout Survival Guide
Preview of talk: BSidesSF plays incident response

BSidesSF plays incident response

BSidesSF 2025 · San Francisco

with Whitney Merrill

  • Incident Response

As Incident Commander, team up with your product and privacy leads to navigate the response. You decide what to do in this choose-your-adventure talk.

Preview of talk: When authn breaks: real world failures
Preview of talk: The evolution of auth, from users to AI agents
Preview of talk: Panel: Mastering the Technical Requirements for FedRAMP
Preview of talk: OAuth Works for AI Agents, but Scaling Is Another Question
Preview of talk: What sucks in security?

What sucks in security?

SnooSec · San Francisco

  • Market research

I interviewed 57 security leaders about what sucks in security. Top pain points: inconsistent access management, vulnerability remediation, and SaaS logs.

Preview of talk: Panel: Secrets and Policies — Automating Cybersecurity
Preview of talk: 5 security startup pitches to raise money and eyebrows
Preview of talk: How Tailscale Builds for Users of All Tiers

How Tailscale Builds for Users of All Tiers

Screaming in the Cloud · Virtual

  • Product management
  • Open source
  • Podcast

Maya shares insights on Tailscale’s product approach and how it serves users from free tier to enterprise, exploring what makes their approach distinctive.

Preview of talk: So what does a product manager do, exactly?
Preview of talk: Lead a Team in Fast Product Launches

Lead a Team in Fast Product Launches

Product School · Virtual

  • Product management

Product launches are both exciting and nerve-wracking. Learn how to find the sweet spot between rapid shipping and sustainable quality for your team.

Preview of talk: Building a Security Team that Doesn’t Slow Down your Developers
Preview of talk: The Importance of Cutting-Edge Security and How To Combat Data Breaches
Preview of talk: Securing user to server access in Kubernetes

Securing user to server access in Kubernetes

CloudNativeSecurityCon NA 2023 · Seattle

with Maisem Ali

  • Container security
  • Remote access

How should you secure access to internal Kubernetes services? We’ll explore authentication, authorization, load balancing, and encryption options.

Preview of talk: Cloud-Native Network Security Panel

Cloud-Native Network Security Panel

Tailscale and ControlPlane meetup · London

  • Container Security
  • Remote access
  • Panel

A panel discussion exploring cloud-native network security, featuring insights from engineering and security leaders at Tetrate, Tailscale, and ControlPlane.

Preview of talk: Zero Config VPNs

Zero Config VPNs

The Cloudcast · Virtual

  • Remote access
  • Network security
  • Encryption
  • Podcast

Maya Kaczorowski (@MayaKaczorowski, Product @Tailscale) talks about the new world of remote systems access, zero-config VPNs, and why everyone loves using Tailscale.

Preview of talk: Demistifying Risks for Dev-Focused Companies

Demistifying Risks for Dev-Focused Companies

Accel DX 2022 · San Francisco

  • Supply chain security
  • Infrastructure security
  • DevOps
  • Panel

With the movement towards CI/CD, new code written by developers is deployed continuously at sophisticated companies. However, security practices haven’t kept up. As leaders in the space, Chainguard’s Kim Lewandowksi, Snyk’s Randall Degges, and Tailscale’s Maya Kaczorowski are not strangers to these challenges. In a panel moderated by Accel’s Casey Aylward, they will discuss security resources for developers, and how to understand and effectively apply them before it’s too late.

Preview of talk: Tailscale SSH Aims To Simplify And Secure Remote Connections

Tailscale SSH Aims To Simplify And Secure Remote Connections

TFiR Let's Talk · Virtual

  • Remote access
  • Podcast

In this episode of TFiR Let’s Talk, Swapnil Bhartiya sits down with Maya Kaczorowski, Product Manager at Tailscale, to discuss Tailscale SSH in beta and how it simplifies remote connections, taking away the need for SSH keys. She explains the motivation behind creating Tailscale SSH and what sticking points it is tackling.

Preview of talk: The Past, Present, and Future of Supply Chain Security
Preview of talk: WireGuard from the ground up

WireGuard from the ground up

BSidesSF 2022 · San Francisco

with David Crawshaw

  • Remote access
  • Encryption

Understand WireGuard’s end-to-end encrypted traffic, protocol implementation and cryptography, with comparisons to IPsec, ngrok, and OpenVPN.

Preview of talk: The road to BeyondCorp is paved with good intentions
Preview of talk: Blue team panel discussion
Preview of talk: Remote development can improve your developers remote work experience
Preview of talk: What’s Next for DevOps?

What’s Next for DevOps?

GitHub Talk · Virtual

  • DevSecOps

DevOps goals haven’t changed, but everything else has — our tools, infrastructure, and how we work. Here’s how to prepare for what’s next.

Preview of talk: Software Composition Analysis

Software Composition Analysis

OWASP DevSlop · Virtual

  • Supply chain security
  • DevOps

Software composition analysis identifies dependencies in shipping software — learn about finding vulnerabilities, licenses, and metadata in your code.

Preview of talk: The State of Security in the Octoverse

The State of Security in the Octoverse

.NET Rocks! · Virtual

  • Podcast
  • Open source security

How secure is your software? Carl and Richard talk to Maya Kaczorowski of GitHub about The State of the Octoverse Security Report — one of three annual reports coming from GitHub about how software is being built.

Preview of talk: Dependabot

Dependabot

GitHub Checkout · Virtual

  • Supply chain security

One library in your manifest can bring in a huge dependency tree. How do we track vulnerabilities and keep dependencies up to date?

Preview of talk: Security for open-source maintainers
Preview of talk: Dependency Review

Dependency Review

GitHub Checkout · Virtual

  • Supply chain security

Dependency Review shows you a rich diff of dependency manifest changes while reviewing pull requests, letting you see exactly what’s changed.

Preview of talk: Catching vulnerabilities early with GitHub

Catching vulnerabilities early with GitHub

GitHub Universe 2020 · Virtual

with William Bartholomew

  • Supply chain security

Want to catch security issues earlier? Learn how GitHub’s Dependency Graph and Dependabot help you shift left and stay on top of vulnerabilities.

Preview of talk: DevSecOps panel

DevSecOps panel

Snykcon · Virtual

  • DevSecOps
  • Panel

A panel that doesn’t suck about security, from multiple perspectives. Categories, organisations and security practices are being reinvented, but what does it look like from the practitioner perspective?

Preview of talk: How Mettle uses GitHub to secure their software supply chain

How Mettle uses GitHub to secure their software supply chain

GitHub Talk · Virtual

with Mikail Tunç

  • Supply chain security

Following DevSecOps means approaching security as an ongoing part of software development — and staying up to date on the code your software depends on. Join Mikail Tunç, Principal AppSec Engineer at Mettle, and Maya Kaczorowski, GitHub Product Manager for an in-depth conversation into how Mettle uses GitHub’s application security capabilities to understand which dependencies they use, their vulnerabilities, how to patch them — and get back to work.

Preview of talk: La sécurité dans tous ses états — la chaine d’approvisionnement logicielle et l’open source

La sécurité dans tous ses états — la chaine d’approvisionnement logicielle et l’open source

Electro Monkeys · Virtual

  • Podcast
  • Container security
  • Supply chain security
  • Open source security
  • French

La sécurité est un aspect fondamental et pourtant souvent négligé de nos systèmes d’information. Le code est la base de code sont aujourd’hui au coeur de toute entreprise technologique. Mais alors quels sont les problèmes soulevés, quelles solutions y apporter et avec quels outils ?

Preview of talk: How Nutanix uses GitHub to secure their software supply chain

How Nutanix uses GitHub to secure their software supply chain

GitHub Talk · Virtual

with Jon Kohler

  • Supply chain security

Following DevSecOps means approaching security as an ongoing part of software development — and staying up to date on the code your software depends on. Join Jon Kohler, Nutanix Technical Director, and GitHub Product Manager Maya Kaczorowski for an in-depth conversation into how Nutanix uses Dependabot and the GitHub dependency graph to understand which dependencies they use, their vulnerabilities, how to patch them — and get back to work.

Preview of talk: Software Supply Chain Security and Puzzles
Preview of talk: Hardening your soft software supply chain

Hardening your soft software supply chain

DevSecCon 2020 · Virtual

  • Supply chain security
  • DevSecOps

Open source code means anyone can contribute — even attackers. Learn about real supply chain attacks and how to secure your dependencies.

Preview of talk: Security and GitOps

Security and GitOps

GitOps Days 2020 · Virtual

  • DevSecOps

Maya joins Cornelia’s keynote to share key ways in which GitOps can contribute to your security needs.

Preview of talk: Securing the software supply chain together

Securing the software supply chain together

GitHub Satellite 2020 · Virtual

  • Supply chain security

Learn how GitHub helps teams understand code vulnerabilities and manage patches to secure their software supply chain, with practical steps to get started.

Preview of talk: The threat is real: software supply chain vulnerabilities
Preview of talk: Cryptic Dependencies & Cryptic Crosswords

Cryptic Dependencies & Cryptic Crosswords

PancakesCon 2020: Quarantine Edition · Virtual

  • Supply chain security
  • Puzzles

How do you determine your code’s cryptic dependencies, and what should you do when a new vulnerability is discovered? And how do you solve cryptic crosswords?

Preview of talk: Checking your —privileged container

Checking your —privileged container

BSidesSF 2020 · San Francisco

with Sam "Frenchie" Stewart

  • Container security

A look under the hood at Docker’s —privileged flag: how Docker isolation really works, what happens when it’s disabled, and why it leads to container escapes.

Preview of talk: Container and orchestration security

Container and orchestration security

Application Security Podcast · Virtual

  • Podcast
  • Container security

Maya joins us to discuss how containers improve security, a high-level threat model of containers and orchestration, and tips for enhancing security as you role out containers and Kubernetes.

Preview of talk: How Kubernetes Components Communicate Securely in Your Cluster

Shifting Cloud Native Security All the Way Left

The New Stack Pancake Breakfast at KubeCon · San Diego

  • Container security
  • Panel

Many IT teams begin moving their applications to containers and Kubernetes after their managers mandate the switch. Then in the rush to deploy they may forget, or simply delay, some fundamentals. Only six to 12 months later does integrating security into their CI/CD pipeline becomes a priority. This gradual evolution toward cloud native security best practices is worrisome, but it’s the norm among organizations adopting Kubernetes today. This is what we learned from a panel of cloud native security experts at The New Stack’s pancake and podcast from KubeCon+CloudNativeCon North America this week.

Preview of talk: Securing open-source

Securing open-source

Open Source Summit Europe 2019 · Lyon

  • Open source security

Who’s responsible when open source security goes wrong? See how mature projects handle dependencies, incidents, vulnerabilities and bug bounties.

Preview of talk: Can You Prevent Brain Freezes?
Preview of talk: Containers can actually improve your security story
Preview of talk: Container security

Container security

Google Cloud at KubeCon · Barcelona

  • Container security
  • Interview

Google Product Manager, Dustin Kirkland interviews Google Product Manager, Maya Kaczorowski to discuss interesting vulnerabilities in the Kubernetes space.

Preview of talk: Container Forensics: What to do when your cluster is a cluster
Preview of talk: Exploring The Latest in Public Cloud Providers

Exploring The Latest in Public Cloud Providers

The New Stack at KubeCon · Barcelona

  • Container security
  • Interview

We’re live from #CloudNativeSecDay for a conversation with TNS Founder & EiC Alex Williams & Google Product Manager Maya Kaczorowski to explore all the latest in public cloud providers today from #KubeCon Barcelona.

Preview of talk: Container platform security

Container platform security

Software Engineering Daily · Virtual

  • Podcast
  • Container security

In today’s show we discuss the attack surface of a managed Kubernetes service.

Preview of talk: Container Security

Container Security

BMC Run and Reinvent · Virtual

  • Container security
  • Podcast

Listen to this very insightful episode with special guest from Google, Maya Kaczorowski, as she discusses container security with BMC Solutions Architect, Ajoy Kumar.

Preview of talk: Who Protects What? Shared Security in GKE

Who Protects What? Shared Security in GKE

Google Cloud Next '19 · San Francisco

with Jesse Endahl

  • Container security

In GKE, the control plane is managed by Google, and the nodes by users — how does this split responsibility apply for security updates and incidents?

Preview of talk: What containers are and how they change your security model
Preview of talk: You might still need patches for your denim, but you no longer need them for prod
Preview of talk: This Year, It’s About Security

This Year, It’s About Security

KubeCon North America 2018 · Seattle

with Brandon Baker

  • Container security

Kubernetes has made giant strides in 2018 to improve security for end users. Here’s an overview of what’s happened in 2018.

Preview of talk: Learn how to use network security controls for your containers
Preview of talk: The State of your Supply Chain

The State of your Supply Chain

KubeCon China 2018 · Shanghai

with Andy Martin

  • Container security
  • Supply chain security

Dive deep into container software supply chain security tools, from Grafeas to Notary, including how to identify and automatically remediate vulnerable images.

Preview of talk: Turtles All the Way Down: Managing Kubernetes Secrets with Secrets
Preview of talk: Embracing Containers Without Fear

Embracing Containers Without Fear

Palo Alto Networks streamcast · Virtual

  • Container security

Containers are making it easier for developers to build and deliver applications in the cloud. However, managing risk around container deployments remains a significant challenge for security teams. Join this session to learn about the security challenges around container deployments and best practices to follow while securing containers.

Preview of talk: Unravel the mystery of container security

Unravel the mystery of container security

Cloud OnAir · Virtual

with Sandra Guo and Juan Oviedo

  • Container security

Containers are increasingly used to deploy applications, with benefits of portability, scalability and lower management. Yet their security remains unclear.

Preview of talk: Container security

Container security

GCP Podcast · Virtual

  • Podcast
  • Container security

Let’s talk container security! This week, Melanie and Mark learn all about the three main pillars of container security and more with our guest, Maya Kaczorowski.

Preview of talk: Google Infrastructure Security

Google Infrastructure Security

Video tour · San Francisco

  • Infrastructure security
  • Encryption
  • Interview

Did you know that Google has invested $30.9 billion to build out our global infrastructure over the past 3 years? Learn more about Google’s infrastructure security through a tour with product manager Maya Kaczorowski and developer advocate Cassie Kozyrkov.

Preview of talk: How Google Protects Your Data at Rest and in Transit
Preview of talk: Kubernetes for Enterprise Security Requirements

Kubernetes for Enterprise Security Requirements

Google Cloud Next '18 · San Francisco

with Jesse Endahl

  • Container security

Learn how enterprises meet security requirements for container workloads in production, with examples from Kubernetes features and Fleetsmith’s approach.

Preview of talk: Google Infrastructure Tour

Google Infrastructure Tour

Google Cloud Next '18 Showcase · San Francisco

  • Infrastructure security
  • Encryption
  • Interview

Follow our Showcase reporters they tour the venue and get the inside scoop on Google Cloud Next ‘18 products.

Preview of talk: DevSecOps: Developers play security offense

DevSecOps: Developers play security offense

Threat Actions This Week · Virtual

  • Podcast
  • Panel
  • DevSecOps

We look for the balance between developers’ security responsibility and the security team. Maya Kaczorowski from Google, Shannon Lietz from Intuit and Larry Maccherone from Comcast help weigh the options.

Preview of talk: Security

Security

Kubernetes Podcast · Virtual

  • Podcast
  • Container security

On this week’s Kubernetes Podcast, your hosts talk to Maya Kaczorowski from Google Cloud about Kubernetes security, and look at announcements from Microsoft, Docker, Cisco and Spotify.

Preview of talk: Container security

Container security

Software Engineering Daily · Virtual

  • Podcast
  • Container security

Maya Kaczorowski works on container security at Google. In a recent talk at KubeCon, Maya discussed runtime security of containers on Kubernetes. Maya joins the show to discuss container security, and what it means to software developers and operators.

Preview of talk: Engineering Container Security: Addressing the Unique Security Challenges of Containers at Scale in a Multi-Cloud World

With container adoption on the rise, new security strategies are needed to address the unique challenges that containers represent. In this panel discussion, container experts will discuss the security risks of containers and briefly examine many of the multiple approaches that can be taken to achieve security in a container-based environment and a hybrid cloud world.

Preview of talk: Container infrastructure keynote: Containers Should Contain …Right?
Preview of talk: Container Security

Container Security

Women in Tech Podcast · Virtual

  • Podcast
  • Women
  • Container security

As public cloud adoption continues to accelerate, security becomes a top priority for many organizations. Maya Kaczorowski, Product Manager at Google Container Security explains what security consisted of in legacy systems. We then talked about the security panorama in the cloud, specifically in containerized applications. Maya explained various security risks in these applications as well as solutions. One of these is gVisor, a new open source sandbox that provides secure isolation for containers.

Preview of talk: Kubernetes Runtime Security: What Happens if a Container Goes Bad?
Preview of talk: Modern App Security Requires Containers

Modern App Security Requires Containers

KubeCon Europe 2018 · Copenhagen

  • Container security
  • Panel

Using containers, enterprises now have strong, secure-by-default primitives available for deploying apps to their infrastructure. Containers are enabling organizations to adopt better engineering practices like immutable infrastructure — increasing deployment agility and reducing mean time to patch. Companies are thinking strategically about to securely manage their software supply chains. Moderated by eWeek’s Senior Editor, Sean Michael Kerner, collaborators in the container ecosystem will share how containers are revolutionizing the way apps are secured and how we can expect container security to evolve in the future. The panel will also touch on open source projects Notary, TUF, SPIFFE, and OPA.

Preview of talk: Cloud SCC container security partners

Cloud SCC container security partners

Google Cloud at KubeCon · Copenhagen

  • Container security
  • Interview

At KubeCon + CloudNativeCon Copenhagen we announced that five container security companies have integrated their tools with the Cloud Security Command Center to help you better secure the containers you’re running on Kubernetes Engine. Our PM in container security, Maya Kaczorowski, will meet them to discuss their technical integrations.

Preview of talk: Securing #Kubernetes

Securing #Kubernetes

The New Stack Pancake Breakfast at KubeCon · Copenhagen

  • Container security
  • Panel

To do cloud-native computing, you need to identify all your workloads, and, more importantly, they need the ability to identify each other, so they can work together in automated chains. To aid in this task, the Cloud Native Computing Foundation has adopted the open source SPIFFE specification, and its associated SPIRE runtime. SPIFFE provides a standard for securely identifying software components in heterogeneous IT systems and SPIRE is the engine that can make it happen (and, in this setup, CNCF’s Open Policy Agent [OPA] can enforce the authorization duties).

Preview of talk: Exploring Container Security: detect and manage an attack

Exploring Container Security: detect and manage an attack

Google Cloud at KubeCon · Copenhagen

  • Container security
  • Interview

You’ll soon be able to manage security alerts for your clusters in Cloud Security Command Center (Cloud SCC), a central place on Google Cloud Platform (GCP) to unify, analyze and view security data across your organization. Further, even though we just announced Cloud SCC a few weeks ago, already five container security companies have integrated their tools with Cloud SCC to help you better secure the containers you’re running on Google Kubernetes Engine.

Preview of talk: Women in Google Cloud

Women in Google Cloud

Google Cloud at KubeCon · Copenhagen

  • Women
  • Panel

Join this panel for a discussion with women product managers and engineers working at Google Cloud in infrastructure and containers.

Preview of talk: Securing your infrastructure using open-source tools
Preview of talk: Securing containers in production

Securing containers in production

Google Cloud Security Talks at RSA 2018 · San Francisco

  • Open source security
  • Panel

A discussion of container security responsibilities throughout the lifecycle, from deployment to runtime, with practical tips for production environments.

Preview of talk: Managing secrets in your cloud environment

Managing secrets in your cloud environment

BSidesSF 2018 · San Francisco

with Evan Johnson

  • Secret management
  • Encryption

Applications need secrets at build or run time. Cloud developers have many storage options — in code, environment variables, or purpose-built solutions.

Preview of talk: Security overview

Security overview

Google Cloud Montreal region opening · Montreal

  • Infrastructure security
  • Encryption
  • French

Maya Kaczorowski, Google Cloud Security & Privacy Product Manager, speaks at the opening of the Google Cloud region in Montréal.

Preview of talk: Google Cloud Encryption at rest

Google Cloud Encryption at rest

Marketing video · Virtual

  • Encryption

At Google Cloud, customer data is encrypted at rest by default. Check out our video to learn all about the mechanisms used by Google to encrypt data at rest.

Preview of talk: Google Cloud Encryption in transit
Preview of talk: Les leçons apprises de la sécurisation de Google et Google Cloud

Les leçons apprises de la sécurisation de Google et Google Cloud

Google Cloud Summit Paris · Paris

with Fenitra Ravelomanantsoa

  • Infrastructure security
  • Encryption
  • French

La protection des données personnelles, la conformité et le GDPR sont des sujets centraux dans lesquels Google investit pour la sécuration des applications Google et de ses utilisateurs. Découvrez plus en détails ce que Google fait en termes de sécurité.

Protecting data in Google’s Cloud

Les Assises de la sécurité · Monaco

with Julien Blanchez

  • Infrastructure security
  • Encryption
  • French

Maya et Julien parlent de la manière dont Google protège la sécurité des données, et d’autres protections abordées aux données.

Preview of talk: What’s Next in Cloud Security?

What’s Next in Cloud Security?

NTT Security World · Frankfurt

  • Infrastructure security
  • Keynote

Learn more about Google’s infrastructure security, including encryption, network protections, and containers.

How Google encrypts data at rest at scale

Mundo Hacker Day 2017 · Madrid

with Julien Blanchez

  • Infrastructure security
  • Encryption

Maya and Julien talk about how Google encrypts data at rest, and other data security protections in the cloud.

Preview of talk: Managing encryption of data in the cloud

Managing encryption of data in the cloud

Google Cloud Next '17 · San Francisco

  • Encryption

Can management of encryption keys be easier in the cloud than on-premise? During this video, Maya Kaczorowski discusses the continuum of encryption options available, from encryption of data at rest by default, to Cloud Key Management System, to Customer Supplied Encryption Keys. You’ll learn how our encryption tools allow management of your own keys, including generation, rotation and destruction of those keys. She also shares best practices for managing and securing secrets.

Preview of talk: How data at rest is encrypted in Google’s Cloud, at scale

How data at rest is encrypted in Google’s Cloud, at scale

Cloudflare Crypto Meetup · San Francisco

  • Encryption

How does Google encrypt data at rest? This talk will cover how Google shards and encrypts data by default, Google’s key management system, root of trust, and Google’s cryptographic library. Google Cloud Platform encrypts customer content stored at rest, without any action from the customer, using one or more encryption mechanisms. We will also discuss best practices in implementing encryption for your storage system(s).

Preview of talk: Encryption

Encryption

Google Cloud Security Talks at RSA 2017 · San Francisco

  • Encryption

Maya talks about how Google encrypts data, Google’s key management system, root of trust, and Google’s cryptographic library.

Preview of talk: How data at rest is encrypted in Google’s Cloud