From Projects to Products: Delivering Software at the Speed of the Mission

Presented by Carahsoft

DevSecOps is often described through tools, pipelines and development practices, but its real value is the secure mission capability it helps deliver. Dave Raley, Chief Digital Services Officer for Operation StormBreaker at the U.S. Marine Corps, explains that faster software delivery is increasingly tied to operational advantage in an environment where digital capability is inseparable from modern warfare.

Screenshot 2026-08-04 at 10.25.03 AMThe ability to build, secure, deploy and improve software faster than an adversary can make a meaningful difference. Traditional waterfall approaches often separate requirements, acquisition, development, cybersecurity and operations into sequential phases. When security is added near the end, teams can spend years moving from an initial requirement to a production capability. Calling the final development stage “agile” does not change the larger process if users and mission owners were not continually involved.

A genuine DevSecOps model brings development, security and operations together. Teams can build a working capability, secure it, place it into production, collect real user feedback and release improvements quickly. Operation StormBreaker was constructed as a cloud-native capability based on Department of Defense DevSecOps and continuous authorization principles to support that iterative approach.

Technology alone, however, cannot create the needed speed. Raley identifies product ownership as a potentially transformative model for defense organizations. A product owner represents the mission or business need and guides the capability throughout its lifecycle. That sustained accountability differs from a project structure defined by a beginning, an end and predetermined deliverables.

A product should continue to evolve for as long as it provides mission value. Organizing around products encourages teams to focus on outcomes instead of schedules, compliance documents or static requirements. It also changes how developers, operators, security professionals and users collaborate.

For defense organizations, a product-centered approach can shorten feedback loops, keep software aligned with changing operational demands and turn DevSecOps into a sustained mission advantage. The pipeline is important, but the ultimate objective is secure capability in the warfighter’s hands when it matters.

Key Takeaways

  • DevSecOps should be measured by how quickly it delivers secure, useful capability to the warfighter.
  • Cloud-native platforms and continuous authorization enable iterative delivery through production.
  • Product owners create sustained accountability for mission outcomes beyond the fixed lifecycle of a project.