In the fast-paced DevOps environments, security must keep up. But how? This talk presents the expanded attack surface in CI/CD workflows, highlights frequently observed security risks, and discusses practical mitigation. Audience will walk away with a holistic view of security in DevOps ecosystems.