Definition. A way of working in which security requirements, tooling and responsibility are treated as an integral part of development and operations, not as a downstream audit step. In practice this means SAST/DAST in the pipeline, secret scanning, signed artefacts, policy as code, runtime detection and reviewable security changes, among other things.
Why it matters. At mid-sized companies, development often moves faster than classic security reviews can keep up with. DevSecOps moves checks early into the pipeline instead of placing them at the end as a blocker. This preserves delivery speed and still closes the most important gaps.
Related. Runtime Security, Threat Detection, Kernel Hardening, Platform Engineering