RL Blog

Spectra Assure Free Trial

Get your 14-day free trial of Spectra Assure for Software Supply Chain Security

Get Free TrialMore about Spectra Assure Free Trial
Blog
Events
About Us
Webinars
In the News
Careers
Demo Videos
Cybersecurity Glossary
Contact Us
reversinglabsReversingLabs: Home
Privacy PolicyCookiesImpressum
All rights reserved ReversingLabs © 2026
XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBlueskyRSSRSS
Back to Top
The inaugural Gartner® Magic Quadrant™ for Software Supply Chain Security is outGET THE REPORT
Skip to main content
Contact UsSupportBlogCommunity
reversinglabs
ReversingLabs: Home
Solutions
Secure Software OnboardingSecure Build & ReleaseVerify AI Supply ChainIntegrate Safe Open SourceGo Beyond the SBOM
Increase Email Threat ResilienceDetect Malware in File Shares & StorageAdvanced Malware Analysis SuiteICAP Enabled Solutions
Scalable File AnalysisHigh-Fidelity Threat IntelligenceCurated Ransomware FeedAutomate Malware Analysis Workflows
Products & Technology
Spectra Assure®Software Supply Chain SecuritySpectra DetectHigh-Speed, High-Volume, Large File AnalysisSpectra AnalyzeIn-Depth Malware Analysis & Hunting for the SOCSpectra IntelligenceAuthoritative Reputation Data & Intelligence
Spectra CoreIntegrations
Industry
Energy & UtilitiesFinanceHealthcareHigh TechPublic Sector
Partners
Become a PartnerValue-Added PartnersTechnology PartnersMarketplacesOEM Partners
Alliances
Resources
BlogContent LibraryCybersecurity GlossaryConversingLabs PodcastEvents & WebinarsLearning with ReversingLabsWeekly Insights Newsletter
Customer StoriesDemo VideosDocumentationOpenSource YARA Rules
Company
About UsLeadershipCareersSeries B Investment
Events
Press ReleasesIn the News
Pricing
Software Supply Chain SecurityMalware Analysis and Threat Hunting
Request a demo
Menu
Dev & DevSecOpsAugust 27, 2025

How DPE boost development — and AppSec

Developer Productivity Engineering provides a framework to boost code production and creativity — and can help to improve application security.

Todd R. Weiss, Freelance writer.Todd R. Weiss
FacebookFacebookXX / TwitterLinkedInLinkedIn

More Blog Posts

Main Story

IntroDPE’s security value-add for enterprisesMaking security a key ingredient, not an afterthoughtDPE can help dev teams be better students
blueskyBluesky
Email Us

Main Story

IntroDPE’s security value-add for enterprisesMaking security a key ingredient, not an afterthoughtDPE can help dev teams be better students

Developers have seen plenty of tools and methods come and go. Agile development was followed by DevOps and then by platform engineering, all of them aiming to make it easier  code efficiently, creatively, and securely.

Now comes developer productivity engineering (DPE), which promises to help developers speed up and automate tasks — while also removing friction in development processes — so that they can produce better code with fewer hassles.

In a recent ReversingLabs webinar titled “Ship Fast, Stay Secure: A Developer’s Guide to Productivity,” two security experts explained that DPE also has a valuable role in helping developers and enterprises improve the security of their applications.

Baruch Sadogursky, head of developer relations at Tuxcare, said DPE “makes secure development practical rather than aspirational.”

And in the world of critical application security (AppSec) requirements, this is a major side benefit of DPE, especially when developers are focused on speed even at companies that are security-conscious, Sadogursky said. 

While DPE’s core mission is productivity, security benefits emerge naturally from better feedback loops, automated checks, and reproducible builds, Sadogursky said. One of developers’ biggest needs is reducing friction at every step, which is a key benefit of DPE. 

[DPE] reduces waiting, manual toil, flaky tests, bad feedback loops, and cognitive load. It is about delivering a smoother, faster, smarter dev experience.

Baruch Sadogursky

See webinar: Ship Fast, Stay Secure: The Developer's Guide to Productivity

DPE’s security value-add for enterprises

DPE also is capable of dramatically improving code security as it is being written, Sadogursky said. “DPE helps operationalize secure practices by automating them, shifting them left, and making them faster and more consistent.”

DPE does not replace other security steps, however. “You still need to integrate [application security testing] tools into your builds and pipelines; secure your caches, runners, and dev environments; and track supply chain risks,” said Sadogursky. “DPE provides you with the platform, but you still need to integrate the right security tools.”

While platform engineering provides developers with curated and managed tool packages to use in creating their code, DPE is focused on development loop optimization that speeds up feedback, making coding, testing, and building applications friendlier, Sadogursky said. 

Platform engineering is what to build on. Developer productivity engineering is how fast and well you can build with it.

Baruch Sadogursky

So how does DPE directly help with improving AppSec? By reducing resistance to secure workflows, Sadogursky said. “When security does not slow down developers, it gets adopted. That is where developer productivity engineering shines.” 

Ultimately, one of the values of DPE is that it helps companies scale quality and security without slowing down their development teams, which is a critical capability, he said. 

It creates a system where good practices are built in, not bolted on. That is how DPE turns productivity gains into security wins.

Baruch Sadogursky

Development teams, administrators, and enterprises that use DPE should not turn a blind eye to security after adopting it, said Sadogursky. 

It is not set and forget. You need ownership, iteration, and observability. Instead, DPE success equals tooling plus culture plus feedback loops. Not all development organizations are ready for it, so you need some baseline process maturity to achieve the full value.

Baruch Sadogursky

Making security a key ingredient, not an afterthought

Umbrella Security Operations CEO and co-founder Valdet Camaj, who also participated in the webinar, said that DPE helps improve the security and management of software, which makes it a smart choice for development teams today.

From my perspective, you can manage [development] easier. You have a dedicated pool of resources, a pool of applications where … it is simpler, easier, more modern.

Valdet Camaj

DPE also allows organizations to think about security throughout the development process, rather than being just an afterthought, Camaj said. “Traditionally, security is often thought of by developers as a last step, which can cause problems for enterprises,” he said.

Using DPE can help prevent that by bringing security to the fore and building it in as the code is assembled, he said. “So having a great plan is a good plan.”

This is beneficial for both developers and their managers, Camaj said. 

So there is security on the top … And then we create a culture in our company where all people start to think like that.

Valdet Camaj

DPE can help dev teams be better students

Sadogursky said that DPE also helps developers and their admins and managers produce safer code because it can reduce their manual security burdens. “Security is complicated, and most developers are usually not experts in security,” he said.

How can we maintain productivity when we have those security threats looming in our work? Security is particularly hard to like. It is a curveball into our productivity routine because of how complicated and multifaceted it is for us.

Baruch Sadogursky

But DPE helps developers gain an upper hand, Sadogursky said.

A lot of companies are invested in DPE, including LinkedIn, Spotify, Netflix, and Meta, he said. “There are a number of interesting research [studies] that actually prove that both the quality and dependence of DPE-produced code that is released are improved dramatically for the companies. They are really on the frontier of DPE.”

Sadogursky said DPE is the missing link in the software development process. 

It connects the developer experience with business outcomes by removing friction, enabling speed, and scaling good practices. It is about building better software faster while empowering developers.

Baruch Sadogursky
Tags:Dev & DevSecOps
man in glasses and suit

Follow us

XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBluesky

Subscribe

Get the best of RL Blog delivered to your in-box weekly. Stay up to date on key trends, analysis and best practices across threat intelligence and software supply chain security.

DPE can speed development and boost AppSec

Join the free Spectra Assure Community today to get hands-on with RL's binary analysis-based software supply chain security platform.

Keep learning

  • Get up to speed on the agentic SOC in this webinar: Autonomy, Not Autopilot: Talking Agentic SOC. Plus: Learn about the new Agentic SOC Alliance.
  • Learn how Gartner® named RL a supply chain security 'visionary.' Download: Gartner® Magic Quadrant™ for Software Supply Chain Security.
  • Update you understanding of the Agentic Development Security tools landscape in this webinar with Forrester Sr. Analyst Janet Worthington.
  • Take a deep dive on the state of software security with RL's Software Supply Chain Security Report 2026. Plus: See the the webinar discussing the findings.

Explore RL's Spectra suite: Spectra Assure for software supply chain security, Spectra Detect for scalable file analysis, Spectra Analyze for malware analysis and threat hunting, and

Spectra Intelligence
for reputation data and intelligence.

Related

Can Lean improve security for AI-coded software?Security teams ditch AI-only pen testing‘Download pumping’ joins the trust-abuse bandwagon

Topics

All Blog PostsAppSec & Supply Chain SecurityDev & DevSecOpsProducts & TechnologySecurity OperationsThreat Research

Can Lean improve security for AI-coded software?

AI coding requires the stack be reconstructed with mathematical proofs built in — a task well suited to the Lean language. Here’s the reality.

Learn More about Can Lean improve security for AI-coded software?
Can Lean improve security for AI-coded software?

Security teams ditch AI-only pen testing

A new report finds weakening trust in AI-only testing — and more willingness to keep humans in the loop. Here's why.

Learn More about Security teams ditch AI-only pen testing
Security teams ditch AI-only pen testing

‘Download pumping’ joins the trust-abuse bandwagon

While this repository vector is not new, researchers have uncovered a new twist for exploiting trusted metrics to hide malicious code.

Learn More about ‘Download pumping’ joins the trust-abuse bandwagon
‘Download pumping’ joins the trust-abuse bandwagon
Lean Language
Human in the loop
Trust abuse