Skip to content
all episodes
Code of Leadership · episode 15

Security: Vulnerabilities Are Born in Architecture

49:32

Episode participants

Conversation

What we discussed on the recording

Roman Lebed is a security architect at Tinkoff working across secure development, DevSecOps, and the external perimeter. His teams build assessment tools, contribute to the Spirit platform, and transfer architectural expertise to other engineers rather than centralizing every security decision.

The main shift is from equal control of every service toward secure platform components and critical systems. Zero Trust reduces reliance on a network boundary, while a security architect in the design phase catches problems before implementation. Antipatterns and solutions live in an internal Shift Left Security Book.

To avoid becoming a bottleneck, the expert team timeboxes reviews, works in short iterations, and moves repeatable expertise into code. Research and development explores work that cannot yet scale manually, while education gives developers tools for independent decisions. A product model connects security effort with customer value and measurable outcomes.

The episode also examines the information-security profession and its overlap with engineering roles. Secure coding, infrastructure, secrets, and administration become part of several career tracks. One new direction is an AI assistant that explains a vulnerability and proposes a repair without breaking business logic.

Engineering managementTeams & cultureHiring & growthArchitectureProduct