Caching, Workers, and Performance
Application performance under repeated work and bursts: cache authority and freshness, worker scheduling and failure control, load distribution, scaling, and evidence-driven diagnosis across the request path.
TRACKS
Application performance under repeated work and bursts: cache authority and freshness, worker scheduling and failure control, load distribution, scaling, and evidence-driven diagnosis across the request path.
Platform-level security foundations for zero-trust service platforms: workload identity, artifact provenance, secure defaults, runtime guardrails, tenancy, audit evidence, and trust-degradation response.
Load envelopes, queuing trade-offs, forecasting, and the methods used to plan system growth before painful saturation.
Incident response as an operational learning system: paging signals, roles, triage, communication, runbooks, mitigation, postmortems, corrective actions, on-call training, and durable organizational memory.
Canaries, feature gates, rollback design, change safety, and the release controls that reduce production risk.
SLIs, SLOs, failure budgets, operational trade-offs, and the core mental models behind production reliability work.
Failure injection, resilience drills, blast-radius control, and experiment design for hardening systems before real incidents.
Input validation, auth flaws, data exposure, secure defaults, and the design patterns that reduce common application risks.
Image provenance, runtime isolation, dependency trust, and the controls used to secure modern cloud software supply chains.
Cryptographic primitives, secret rotation, key hierarchy, and the operational discipline needed to use cryptography safely.
Identity boundaries, token flows, authorization models, policy engines, and the auditability of trust decisions in software systems.
Draft track for lineage, retention, deletion workflows, policy enforcement, auditability, and privacy-aware data operations.
A practical foundation for turning system diagrams, assets, trust boundaries, adversary assumptions, and abuse paths into prioritized security requirements, verifiable controls, and living threat models.
Security telemetry, investigation workflows, triage, containment, and the evidence-handling needed after active compromise.
Understand software from the outside inward: binaries, protocols, traces, decompilers, symbols, patching, and ethical analysis.
A compact, defense-oriented practice for challenging assumptions, tracing realistic attack chains across technical and human workflows, mapping attacker behavior to controls and signals, and reporting findings responsibly.
Production observability depth for backend systems: OpenTelemetry propagation, Prometheus cardinality, logs, sampling, traces, profiling, service maps, and incident evidence.