DevSecOps integrates security into every phase of software development: Design (threat modeling), Code (SAST scanning), Build (dependency analysis), Test (DAST, penetration testing), Deploy (infrastructure security), and Monitor (SIEM/EDR). The architect designs the security tooling pipeline that feeds events from each phase into Splunk.
Container and Kubernetes security is a growing focus. The architect ensures Kubernetes audit logs, container runtime events (from Falco or similar), and image scan results flow into Splunk. Detections for container escape, privilege escalation in pods, and lateral movement via the Kubernetes API are essential in modern cloud-native environments.