About us
Follow us on Twitter: @DevOpsZH
Our meetup group is a community platform for everyone interested in DevOps. No matter if you are a front-end designer, backend developer, tester, team lead or system administrator – if you’re passionate about the DevOps movement you are welcome! We want to share experiences, new information and learnings. Our focus will be on DevOps topics ranging from implementing DevOps culture, DevOps in a legacy system or DevOps in Leadership to scaling DevOps, DevOps Enterprise, and ITSM and DevOps. If you’re in and around Zurich and interested in a DevOps Community, come by!
We do not want any sales pitches on our site, as we want this to be a healthy exchange of experiences and focus on the community aspect. For this reason, please contact one of the organisers before posting something on our dashboard. We will check if it complies with our guidelines and get back to you!
Upcoming events
8

Your Container is the Attacker's Toolbox & Flight Levels to Reduce Lead Times
Smallpdf, Steinstrasse 21, 8003 Zürich, CHThis meetup brings together two seemingly unrelated talks that ultimately address the same question: how do we build technical and organisational systems that can withstand pressure? First, we'll take a hands-on look at container security, watching a real exploit chain unfold and then being shut down step by step through smarter image builds and network controls.
Next, we will take a broader view of how teams and organisations function, examining real-world examples of reducing lead times through improved cross-team collaboration.
Grab a drink, meet some sharp people, and stick around to keep the conversation going afterward — this one's worth clearing your calendar for.Here's what's planned for the evening:
17:30 - 18:00 - Arrival and first drinks
18:00 - 18:45 - Your Container is the Attacker's Toolbox by Mark Anthony Attard & Miguel Ángel Hernández Ruiz
18:45 - 19:30 - Flight Levels to Reduce Lead Times by Stephan Obbeck
19:30 - 20:30 - Networking, Open Space & More drinks*Your Container Is the Attacker's Toolbox, Stop Shipping It.
Remote code execution in an application is usually treated as game over. It doesn't have to be. Whether an RCE becomes a breach is determined not by the vulnerability itself, but by what the attacker finds inside the container and whether they can call home.This session is built as a progressive live demonstration. We start with a conventional application image and exploit a vulnerability to obtain a fully interactive reverse shell, then move laterally to show the realistic blast radius. We then shrink the image and repeat the exploit: the payload changes, but as long as any interpreter remains a shell, Python, Perl, even a linker and a handful of coreutils the attacker adapts and the shell comes back.
Finally, we rebuild the same application using a multi-stage Docker build with `scratch` as the destination image, shipping only a statically linked binary. The vulnerability is still there and still triggers. The reverse shell is not, because there is nothing left to execute it.
We close the remaining gap with egress control: a default-deny outbound policy that removes the attacker's command-and-control channel entirely and converts every blocked connection attempt into a high-fidelity detection signal rather than silent exfiltration.
Attendees will leave with the reasoning, the build patterns, and the operational trade-offs behind both controls including static compilation constraints, debugging and observability without a shell, health checks, TLS trust stores, and the migration path for teams that cannot go to `scratch` on day one.
Mark Anthony Attard
Mark Anthony Attard is an Engineering Manager at Smallpdf, where he leads DevOps and Security for a product used by 60 million+ people each month. With more than 10 years of experience across data centers, cloud infrastructure, automation, reliability, and security, he brings a practical, hands-on perspective on building secure and reliable systems that teams can trust.As an Engineering Manager, he is passionate about growing people, strengthening teams, and creating an environment where engineers can do their best work. He enjoys helping teams collaborate effectively, develop confidence, and deliver secure, resilient platforms with clarity and purpose.
Miguel Ángel Hernández Ruiz
Miguel Ángel Hernández Ruiz — also known as WhiteTie — is Lead Security Engineer at Smallpdf, where he owns security for one of the most widely used PDF SaaS platforms on the internet. Over nearly twenty years he has worked both sides of the table: penetration testing and offensive research at IBM Watson Health and Sopra Steria (EUIPO, AXA, GDF-Suez), cloud-native security consulting at ControlPlane for regulated clients including Lloyds Bank, and building a CSIRT from scratch in the public sector.He holds OSCP, CEH, CKA, IBM SF, CISA and CISM among his 23 professional certifications, has published research on event-driven intrusion detection, and has served as a court-appointed digital forensics expert witness. A regular international speaker at BSides Krakow, BalCCon, EuroSTAR, OWASP Barcelona and many others, his current obsession at the moment is AI in security as target, as tool, and as defense.
Optimize Flow, Not Teams – How Flight Levels Reduce Lead Times and Build Resilience
Many organizations focus on optimizing individual teams, often by adopting agile practices. However, truly sustainable and impactful improvements only emerge when we move beyond the team level and start optimizing products and value streams as a whole.Flight Levels provides a powerful thinking model for making organizational workflows visible, improving collaboration across teams, and creating the conditions for resilient product development. In this session, Stephan shares insights from real-world engagements where Flight Levels helped reduce lead times from 335 to 68 days. He demonstrates the simple yet effective steps that made this possible and explains how resilient product development enables organizations to navigate change and thrive in challenging times.
Stephan Obbeck
Stephan Obbeck has been working in the IT industry for nearly 30 years, first as a project manager and later as an agile coach. Throughout most of his career, he operated as an external consultant, gaining deep insights into a wide range of companies and becoming familiar with a diverse spectrum of agile approaches. As a private pilot, his passion for Flight Levels comes naturally – and he has successfully applied the concept in several real-world projects.Beginning of 2026 Stephan joined Boardwise GmbH as a program manager and Agile Coach and is responsible for the product and strategic projects department.
Many thanks to our sponsor:
- Catering & Location Sponsor: Smallpdf https://smallpdf.com/
* contact us min. 3 days prior to the event if you prefer a vegan option.
2 attendees
Past events
105





