
Patrick Thomas (@[email protected])
@coffeetocode
Followers
2K
Following
2K
Media
213
Statuses
3K
Software engineer to security consultant, now security partner at @Netflix. Infosec pragmatist.
SF Bay Area
Joined February 2010
"Penetration Test" is a crazy overloaded term. Important to start w/ discussion of goals and tradeoffs between testers and client team.
22
697
944
Thanks for the #BSidesSF Semgrep workshop @enncoded @LewisArdern @onefiftyman . You packed a *ton* into 2 hours. Really appreciate the work that went into it.
1
3
12
I love formal forecasting exercises (esp those run by @Magoo) because they really force you to slow down consider all the potentially relevant facts, and introspect your biases. FWIW I was 80% here, but I think I was undervaluing the "autopilot" nature of modern CI/CD.
That's what myself and 26 others sought to gather over the weekend. The panel we put together forecasted a 72.8% belief it would happen. Here's the spread of forecasts.
1
0
1
Hah, this makes me feel so much better about my small pile of aborted "I think I should write something about. " drafts.
Know how many blog posts I start writing but never finish? *HEAPS*! Sometimes the story just doesn't work out as expected, sometimes I calm down and change my mind, other times. I'm a busy guy 🤷♂️ Are there any here I really should finish?
0
1
2
RT @tqbf: I don’t think there’s a SOC2 rule against banking 50 pre-approved empty PRs for future use.
0
3
0
RT @aboodman: Chrome was delivered without any sprints at all. The team came in at 9 and left at 5 (figuratively, people actually kept thei….
0
2K
0
Congrats to @Resourcely! Clear, exciting product vision at that critical touchpoint of developer velocity, security, and cloud resources. Very pleased to have joined this round, and looking forward to seeing where @travismcpeak and @0xshellrider take this idea.
Hello world! We're on a mission to make cloud security easier for users. See our funding announcement ( and blog post ( for more details. We're #Hiring!.
1
0
8
Strong recommend for anyone thinking about sustainability, culture, and ultimately the humans in a security organization. @astha_singhal knows what she's talking about and delivers it so well. 🙌.
This year I got the amazing opportunity to deliver the keynote at one of my favorite security conferences, @BSidesSF. You can now check out my talk on "Building Sustainable Security Programs" here:
0
0
4
Strong recommend. Some great examples that improve both risk and user experience, and also give metrics that make the wins feel real.
@workingrach and my @BSidesSF preso is uploaded to Youtube!.
1
0
4
RT @manicode: Brilliant talk from @coffeetocode on bonding security to developer productivity.
0
6
0
When it literally rains on your parade at @LocoMocoSec with @ropnop @SammyHep @ndm @h4ck3rky13 and @coffeetocode #stillHavingFun
0
0
5
RT @manicode: When it literally rains on your parade at @LocoMocoSec with @ropnop @SammyHep @ndm @h4ck3rky13 and @coffeetocode #stillHaving….
0
4
0
Woo! @LocoMocoSec has been on my list since it started; I'm finally here and so excited! Looking forward to meeting folks. Just hanging out today/tomorrow if anyone else in early wants to meet up!.
Aloha @LocoMocoSec 😎 so excited to be here - have wanted to attend this con for a long time! Really looking forward to learning a lot, talking prodsec and meeting new friends. Anyone else gonna be here? And can’t wait to catch up @coffeetocode been too long!
3
1
13
Woot! Let's do this! I'm really looking forward to sharing this.
Patrick Thomas, Senior Security Partner @netflix, is speaking @LocoMocoSec next week!. Register now to see his talk 'Productizing Security For Leverage and Scale' on June 30th🤙. ⛵ Waikīkī Marriott Resort.🏝️ O'ahu, Hawai'i.☀️ June 27-30th. 🌟 @coffeetocode
1
2
16