DevConf.US 2025

Keys, Certs and Vault: From DevSecOps to Post-Quantum
2025-09-19 , 101 (Capacity 48)

As security threats evolve and compliance mandates tighten, developers and platform engineers are increasingly expected to bake security and crypto agility into their workflows from the start. In this talk, we'll explore how the open source HashiCorp Vault Community Edition can serve as a powerful cryptographic control plane not just for secrets, but for managing the full lifecycle of cryptographic assets including encryption keys, certificates, and algorithm policies. We'll discuss real-world scenarios where Vault enables centralized key management, streamlined certificate issuance and renewal, and integration with CI/CD pipelines for automated crypto operations.
The session will also unpack why Post-Quantum Cryptography (PQC) matters now not later and how open source communities and forward-looking practitioners can extend Vault to experiment with PQC algorithms, support multiple cryptographic backends, and plan for seamless algorithm transitions.
Whether you're a security-minded developer, a compliance lead, or an SRE looking to future-proof your infrastructure, this session will provide a practical blueprint for using community-driven tools to solve enterprise-scale security challenges without vendor lock-in.


What level of experience should the audience have to best understand your session?

Beginner - no experience needed

Product Leader at IBM | Data Security & Crypto Agility Expert

Chaitanya Challa is a product leader at IBM with a deep expertise in data security, threat management ,encryption, and crypto agility. Her career began as a developer and technical lead, where she honed her skills in software engineering and architecture, contributing to major projects such as IBM Sterling OMS and IBM Kenexa BrassRing.
Transitioning into product management, Chaitanya’s journey led her to take on critical leadership roles within IBM’s QRadar and Guardium teams, where she focused on developing and delivering security solutions that help organizations protect their most sensitive data. Over the years, she has played a pivotal role in driving innovation in areas like data discovery, classification, key lifecycle management, and post-quantum cryptography (PQC) readiness.
Her leadership on the Guardium by introducing Mainframe Security Posture Management and Quantum Safe further solidified her expertise in managing complex security products at scale. Most recently, Chaitanya has been leading efforts to enhance IBM's encryption and crypto agility strategy, working on building future-proof solutions in the face of quantum threats.
At RSA Conference 2025, she presented a session on a modernized approach to key management in the post-quantum era, focusing on how organizations can adopt crypto agility to stay ahead of regulatory and technological challenges.
With a passion for helping teams build secure, compliant, and future-ready products, Chaitanya has been recognized as one of IBM’s top 1% technical talents. She also participated in IBM Tech 2024 in San Diego, sharing her knowledge of security practices and emerging technologies.
Chaitanya's journey from software development to product leadership gives her a unique perspective on both the technical and business aspects of building and delivering innovative data security solutions.