From Compliance Tax to Engineering Accelerator

Security and compliance initiatives often begin with good intentions but end up creating friction for engineering teams. Developers encounter new scanning tools, security gates, governance requirements, and approval processes that slow delivery and are frequently perceived as obstacles rather than enablers. The result is a familiar tension between security teams trying to reduce risk and developers trying to ship software.

This session shares practical lessons from transforming security compliance into a developer-friendly platform capability. Drawing from real-world experience modernizing enterprise-scale DevOps environments, we’ll explore how secure software development practices were embedded directly into engineering workflows through automated policy enforcement, code analysis, secure build validation, identity modernization, and self-service pipeline templates.

Rather than relying on manual reviews and compliance checklists, the approach focused on making security controls transparent, automated, and integrated into the developer experience. We’ll discuss the technical and organizational challenges of driving adoption across hundreds of repositories, reducing resistance to change, and balancing governance with engineering velocity.

Attendees will learn how platform engineering principles can help scale security initiatives, how to measure success beyond compliance metrics, and how to create a culture where developers view security tooling as an accelerator rather than a bottleneck.

This talk is not a product demonstration or a theoretical framework. It is a practical case study covering what worked, what failed, and the lessons learned while building secure-by-default DevOps practices at scale.

Speaker

lalith-mangalagiri

Lalith Chaitanya Mangalagiri


Lalith Chaitanya Mangalagiri is a Senior Software Development Engineer at Microsoft, specializing in DevOps, cloud infrastructure, and CI/CD automation for the last 15+ years. With deep experience in ...