Loading…
13 - 15 April, 2026 Toronto, Canada
View More Details & Registration
Note: The schedule is subject to change.

The Sched app lets you build your schedule, but it is not a substitute for event registration. You must be registered for Open Source in Finance Forum Toronto 2026 to participate in the sessions. If you have not registered but would like to join us, please visit the event registration page to purchase a ticket.
Tuesday April 14, 2026 3:55pm - 4:10pm EDT


    In regulated industries, delivering software quickly and securely is a constant balancing act. Compliance requirements introduce friction, making automation and security more complex. Traditional DevSecOps approaches struggle to keep up with evolving regulatory demands, leading to fragmented tooling and processes that slow innovation and frustrate developers.

    To secure the SDLC without compromising DevEx, this talk focuses on defining and implementing control points across the CI/CD lifecycle where security and compliance can be enforced and release evidence can be collected.

    We'll show how these control points can be implemented using GitLab and Flux, providing a real-world example of everything-as-code, policy-driven workflows and compliance reporting that improves developer experience and allows internal and external audits to verify compliance.
    - Break down common compliance challenges across the SDLC
    - Map key control points to each phase
    - Walk through real-world examples of secure CI/CD pipelines in regulated environments
    - Share strategies to automate release evidence generation and policy enforcement
    - Discuss standard reporting for internal and external audits


In order to facilitate networking and business relationships at the event, you may choose to visit a third party's booth or access sponsored content. You are never required to visit third party booths or to access sponsored content. When visiting a booth or participating in sponsored activities, the third party will receive some of your registration data. This data includes your first name, last name, title, company, address, email, standard demographics questions (i.e. job function, industry), consenting to receipt and use of such data by the third-party recipients, which will be subject to their own privacy policies. 
Speakers
avatar for Jason Morgan

Jason Morgan

Strategic Account Executive, GitLab
Jason Morgan has been building and breaking things in tech since 2003, leading infrastructure and platform work in some genuinely demanding environments — from the US Army in Afghanistan to early containerization and GitOps in production before established patterns existed. Since... Read More →
Tuesday April 14, 2026 3:55pm - 4:10pm EDT
Giovanni Room

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link