Cybersecurity Starts with Risk Aware Engineers!
How do you get your DevOps engineers on board for IT Risk? How do you avoid the pitfall of making it all about documentation? How do you keep it light and fun, so they don?t actually hate working on IT Risk?
Your answer: by organizing Risk Awareness days! We will tell you how!
Jan-Joost stumbled into IT almost 20 years ago, starting on a temp job for 5 days that lasted 7 years. During these 20 years he has been mostly on the functional and process side of things, having worked as tester, designer, information analyst, project manager, application manager, change manager and process owner of the ITIL change management process at ING. More recently he switched to Risk Management in a role of SOx IT control testing coordinator, with an emphasis on Identity and Access Management.
During the early years of DevOps adoption at ING he was also the self appointed DevOps evangelist and community leader at ING, facilitating his co-workers to make the transition to DevOps and Continuous Delivery and have fun with it at the same time!
In his spare time he enjoys traveling the world to watch birds, or cooking, but rarely at the same time.
Leon Janson has been working within Risk management and IT at ING since the late nineties. He started at Credit Risk management where he developed and implemented a world-wide Credit Risk Reporting data warehouse. Next he managed several IT Operations teams within the Retail bank. During this time period, he facilitated the implementation of Agile and transition to DevOps for these teams while "running the bank". As of 2015, Leon became responsible for all IT risks within ING Domestic Bank directly reporting to the CIO. The purpose of his Risk&Control team is facilitate to create impact on IT Risk. The underlying objective is to create a safer and more secure bank, focusing on creating Risk Awareness, on User Access, and by helping engineers implement minimum standards and solve risk and security issues. He has been one of the architects of the IT risk measurement model that describes how the ING DevOps organisation needs to handle IT Risks. Next to this, he has been one of the driving forces behind an effective implementation of an Operational Control Dashboard providing engineers insight in the status of their IT risks on a daily (almost real time) basis.
Since 2017, Leon is organizing Risk Awareness Days, which has grown to a cross-domain, cross-border event in which several hundreds of DevOps teams (3000+ engineers) participate. He applies his professional skills as a coach and leader also in his personal life where he coaches his son's football (soccer) team and regularly referees for his daughter's field hockey team and is always looking for ways to make things better and more fun!
Jan-Joost Bouwman
Risk Manager, ING
Leon Janson
Manager Risk & Control, ING