IT Salary Survey 2017: Highlights

Key findings from Computerworld’s survey of nearly 2,800 IT professionals, including salary trends, hot skills, job satisfaction, career outlook, biggest concerns and more.

Salaries are rising, but at a slower pace

Tech pros who responded to Computerworld’s 31st annual IT Salary Survey showed an interesting mix of optimism and anxiety. We polled 2,782 IT professionals — 55% technical staffers and 45% IT managers — asking them about their compensation, workloads, long-term career prospects and much more. Read more..

2017 DevOps Conferences: Your Guide to Top DevOps Conferences

DevOps Confernces 2017
If you are looking for the best DevOps conferences to learn what’s new in DevOps world. We’ve put together few top conferences to help you choose the ones you want to attend in 2017.

DevOps Enterprise Summit

Web: events.itrevolution.com/us
Date: Nov. 13-15
Location: San Francisco, California.

DevOps Enterprise Summit is a conference for the leaders of large, complex organizations implementing DevOps principles and practices. The event programming emphasizes both evolving technical and architectural practices and the methods needed to lead widespread change efforts in large organizations. The goal is to give leaders the tools and practices they need to develop and deploy software faster and to win in the marketplace.

DockerCon

Web: 2017.dockercon.com
Date: April 17-20
Location: Austin Convention Center, Austin, Texas

DockerCon is the community and container industry conference for makers and operators of next generation distributed apps built with containers. The three-day conference provides talks by practitioners, hands-on labs, an expo hall of Docker ecosystem innovators and great opportunities to share your experiences with other virtual container enthusiasts.

Velocity Conference

Web: conferences.oreilly.com/velocity/vl-ca
Date: Training, June 19-20; tutorials and conference, June 20-22
Location: San Jose, California

The O’Reilly Velocity Conference: Build resilient distributed systems.
Our industry is evolving rapidly, shifting to a distributed systems stack that spans the application layer all the way down through compute, storage, networking, to the data center (whether yours is in the cloud or not). At Velocity, we’ll delve into these domains, helping you focus on engineering performance and operations from the bottom of the stack right up to the customer.

DevOps Days

Web: devopsdays.org
Date: Varies
Location: Held throughout the year in multiple cities.

Devopsdays is a worldwide series of technical conferences covering topics of software development, IT infrastructure operations, and the intersection between them. Topics often include automation, testing, security, and organizational culture.

ChefConf

Web: chef.io/chefconf
Date: May 22-24
Location: Austin, Texas

Chef comes alive when nearly 2,000 passionate leaders, practitioners, and innovators from the DevOps community converge upon Austin, Texas. We’ll present an invigorating blend of technology and local Austin experiences to engage and energize both technical practitioners and corporate leaders.

Jenkins World

Web: cloudbees.com/jenkinsworld
Date: August 28-29, training and workshops; August 30-31, conference
Location: Marriott Marquis, San Francisco, California

Jenkins World will bring together the largest gathering of Jenkins® users in the world, including Jenkins experts, continuous delivery thought leaders and companies offering complementary technologies for Jenkins. Jenkins World will provide opportunities for attendees to learn, explore and network face-to-face, as well as to help shape the future of Jenkins. Secure your spot now by registering today!

PuppetConf

Web: puppet.com/puppetconf
Date: October 10-12
Location: Hilton San Francisco Union, San Francisco, California

PuppetConf 2017 is your path to sharpening Puppet skills by learning from industry experts, enthusiasts, community members, and Puppet employees. Explore how to drive change across your infrastructure, team, and organization’s culture.

IT/Dev Connections

Web: devconnections.com
Date: October 23-26
Location: Hilton Union Square, San Francisco, California

The IT/Dev Connections teams work hard in the background to bring a seamless and valuable experience each year so all you have to do is show-up.
One of those teams is responsible for the content. Called Track Chairs, these individuals sift through the submitted session proposals to hand-select just the right content and just the right speakers. There’s no question that the content provided at IT/Dev Connections is just right. Our content provides deep technical education without even a hint of marketing or keynote fluff. Developing great and valuable content like we have each year for IT/Dev Connections takes a lot of work, but the effort gets a lot easier when we have the right people on the content team.

Agile Dev West

Web: adcwest.techwell.com
Date: June 4-9
Location: Caesar’s Palace, Las Vegas, Nevada

Discover the latest in agile methods, technologies, tools, and leadership rinciples.
Whether you’re new to the agile process and need to get up to speed quickly, or you’re experienced and ready to take your team or organization to the next level, our hands-on, in-depth workshops have you covered. Plus, all Agile Dev West is held in conjunction with Better Software West and DevOps West conferences, allowing you to choose from three distinct programs.

Agile Dev East

Web: adceast.techwell.com
Date: Nov. 5-10
Location: Hilton Orlando Lake Buena Vista, Orlando, Florida

Discover the latest in agile methods, technologies, tools, and leadership principles.
Whether you’re new to the agile process and need to get up to speed quickly or you’re experienced and ready to take your team or organization to the next level, our hands-on, in-depth workshops have you covered. Plus, Agile Dev East is held in conjunction with Better Software East and DevOps East, allowing you to choose from three distinct programs.

11 Cyber-Security Predictions for 2017

A new forecast predicts that automated malware attacks will have a devastating effect on the internet of things (IoT). It also predicts the rise of the Shadownet (IoT botnets that can’t be seen or measured using conventional tools), cloud poisoning, more growth of Ransomware as a Service, and attacks on smart buildings. The report, “Fortinet 2017 Cyber-Security Predictions: Accountability Takes the Stage,” based its predictions on cyber-security trends this year. The digital footprint of businesses and individuals has expanded, thus increasing the potential attack surfaces; everything is a target and anything can be a weapon; threats are becoming intelligent, can operate autonomously and are increasingly difficult to detect; and old threats are returning but are enhanced with new technologies. According to the report, “This demand for connectivity, and the need to address its associated risks, will create serious challenges for emerging countries, traditionally disconnected markets, and smaller companies adopting digital business strategies for the first time.” Some key predictions are highlighted here. Read more..

dockercon17

Date : April 17-20, 2017

Location : Austin, TX

Venue : Austin Convention Center | 500 E. Cesar Chavez St. Austin

DockerCon is the community and container industry conference for makers and operators of next generation distributed apps built with containers. The three-day conference provides talks by practitioners, hands-on labs, an expo hall of Docker ecosystem innovators and great opportunities to share your experiences with other virtual container enthusiasts.

ACTIVITIES

. 3 Keynotes & 7 Tracks . 60+ Breakout Sessions . Community Presentations . Hands-on Lab . Ask The Experts . Workshops . Birds-of-a-feather . Hosted Happy Hours . After Party . Ecosystem Expo
[REGISTER NOW]

Security Testing: An insight

secutiy testing
You will never want to implement software that bugs up every fortnight and annoys your customer. Security testing is so, an inevitable step prior to software deployment in client’s place. In this article, we shall bring an insight to the security testing and state why it is so important web applications.

What is security testing?

Security testing forms an integral part of software testing that is done to identify weaknesses and vulnerabilities of a software application. The main objective is to identify the vulnerabilities of software and determine if the data and other resources are protected from foreign intruders. It is a way to verify whether or not a confidential data stays confidential or not.
Due to the notable explosion of the ecommerce websites in the world today, security testing has become all the more important. The testing is done once the application is developed and installed. To identify all the potent vulnerabilities, a network security testing is suggested.
Seven attributes the security testing needs to follow are:
• Authorization
• Authentication
• Confidentiality
• Integrity
• Availability
• Resilience
• Non-repudiation

The Security Testing “Terminology”

Penetration testing:

It is a type of testing that is done by evaluating the system and/or network using various malicious techniques. The purpose of this testing is to protect important data from users who do not have access to the system, like hackers. It is carried out after cautious notifications, considerations and planning.

Penetration testing is categorized into two types – Black Box Testing and White Box Testing. In White Box Testing, the tester has access to all vital information like Code, IP Address, Infrastructure Diagram, etc. In Black Box Testing, the tester doesn’t have any access to any sort of vital information. Black box testing tends to be the most accurate testing as the tester doesn’t have any access to any information, thereby, simulating the testing as a hacker.

Password cracking:

In Password crack testing, the system is tested to identify the weak passwords. Password Cracking tools are used for testing of this attribute. The end result is to ensure that users are adequately using strong password.

Vulnerability:

This is to identify the weakest attributes in the system which might lend easy paths for the malicious software to be attached by unauthorized users. Vulnerability can occur due to bug in software, inaccurate software testing or presence of malicious code. This phase requires fixes, patches to prevent the compromised integrity by malware or hackers.

URL Manipulation:

One of the popular ways to hack a website is URL manipulation where in hackers manipulate website URL query strings and get access to confidential information.

This usually takes place when the application makes use of HTTP GET to pass information between client & server. Information is passed via query string. The tester alters the query parameters to check if is accepted by the server.

An URL Manipulation testing ensures that database records are not accessed neither other vital information of the website by unauthorized users.

SQL Injection:

One of the other common ways picked by hackers to steal the vital information from the web, the SQL Injection testing ensures all the databases are safe and protected. It is a type of testing that takes the advantages of the loopholes that make the hackers easily pass into the system by passing all possible SQL queries to hack it.

They try to query the database using the SQL Injection statements to pull information and crash the system. Even the errors displayed while crashing the system will provide generous amount of important data to the hackers.

So, SQL Injection testing is purposed to take care of the input fields like comments, text boxes etc. Special characters are either handled or skipped from the input.

Cross Side Scripting (CSS):

It is a common application layer hacking technique. It is a vulnerability aroused in a web application by injecting HTML and Javascript code into the website pages. The attacks are generally done to inject malicious code web browsers. The code is then used to steal information present inside the cookies.

Security Testing Approach

• Following are the approaches taken for preparing and planning for security testing:
• Security Architecture Study: The first step is to comprehend the client’s requirements and security goals and objectives in compliance to the security need of the organization.
• Security Architecture Analysis: Comprehend the need of application under test.
• Classify security testing: Collect system set up information like operating system, technology and hardware to identify the list of vulnerabilities.
• Threat profile: Based on the information collected above, a threat profile is created.
• Test Planning: Based on identified threat, security risks and vulnerabilities, a test plan is drafted to address the issues.
• Traceability matrix preparation: A traceability matrix is prepared based on the identified threats and vulnerabilities.
• Security Testing Tool Identification: Identify the most suitable tool to test security test cases faster.
• Test Case Preparation: Prepare a test case document.
• Test Case Execution: Test case execution is done and the defect cases are fixed. Test case regressions are executed.
• Reports: Document a detailed report of Security Testing from step 1 to the final including the still open issues.

At Idexcel, we perform security testing for all our clients to ensure they enjoy a bug free application execution across various domains. Our standards, methodologies and experience help us deliver the best business value to customers.

We have a robust automation framework using SOAP UI open source tool.
Key Features of framework

• Data Driven Framework to test with multiple inputs.
• Supports Security and functional testing of Web Services.
• Affordable framework since we are using open source SOAP UI tool.
• Simple and ready to use framework
• Suitable for both SOAP and REST web services

Would you like to experience an error free execution of your application? Call us today!

ERE Recruiting Conference 17

Date : April 18-20, 2017

Location : San Deigo, CA

Venue : San Diego Marriott

Why ERE?

As a TA leader, I know you’ll only attend one or two or conferences this year, and choosing where to invest your conference dollars is not always easy.

To help your decision making, here are a few good reasons why we think ERE is the best conference for you this spring.

We know TA leaders

ERE’s agenda is built specifically for experienced TA and recruiting leaders like YOU. This is not a “how-to” or “Recruiting 101” conference.

You’ll attend sessions led by experts in the field on topics that matter:

Leadership & successful roadmaps
Future trends, emerging technologies and how to utilize them
Data, predictive analytics, and metrics that matter
The focus this spring is about current changes in the industry that are shaping the future role of talent acquisition. We are bringing together the people and companies that can help you the most in the road ahead. [Know more about the Conference]

Tailoring Your DevOps Transformation to Organizational Culture – Idexcel DevOps Roundup

devops team work

1. Tailoring Your DevOps Transformation to Organizational Culture

In the ‘2016 State of DevOps Report’ the Westrum Model [1] of organizational culture is proposed. It focuses on information flow, high cooperation and trust as predictive factors of DevOps success in a company. It is a perfect future state design tool which, however, tells little about where your company is at the moment. Moreover, it does not suggest how to influence an organizational culture and in which direction it should change. Read more…

2. How to Set Up a Continuous Delivery Environment

With the increasing popularity of microservices, more and more is being said about Continuous Delivery. There are many interesting books and articles about that subject. There are also many tools and solutions that can help set up a Continuous Delivery environment. Read more…

3. DevOps done right: Why work-life balance matters to digital transformation success

As enterprises in every industry grapple with digital transformation, and fixate on meeting user demands for always-on services, IT departments find themselves under growing pressure to perform and deliver. Read more…

4. Is DevOps security about behavior or process?

One of my main roles is improving the security of the software produced by my employer, and it was in that role that I attended the annual gathering of the security industry in San Francisco last week. The RSA Conference is one of the two global security conferences I attend, the other being Blackhat. While Blackhat has become more corporate, it’s still dominated by hackers and focuses more on vulnerabilities, whereas RSA is very much a corporate event focused on enterprise security and security policy. Read more…

5. Finance industry leading the way in DevOps implementations, research says

Financial services firms are embracing DevOps approaches and best practices more quickly than other industries, according to new research from managed services provider Claranet. Read more…