Loading…
Type: 1-Day Training clear filter
arrow_back View All Dates
Wednesday, November 4
 

9:00am PST

1-Day Training: Building Continuous SaaS Integration Security: Signals, Least Privilege, and Evidence Automation
Wednesday November 4, 2026 9:00am - 5:00pm PST
1-Day Training: November 4, 2026
Level: Intermediate
TrainersPranav Saji

To register, please purchase your training ticket here. Training and conference are two separate ticket purchases.

SaaS integrations are now a primary path for privilege creep, token sprawl, and silent exposure across an organization. In this hands-on training, participants learn how to assess and continuously monitor SaaS integrations using practical security signals such as over-scoped OAuth grants, non-expiring API tokens, dormant but valid credentials, admin privilege duration, environment token reuse, and public sharing risk.

We will turn these signals into an actionable review rubric and then into automation: how to pull audit-ready evidence from common SaaS APIs, normalize it into a consistent model, and generate security findings that are explainable to engineering and compliance teams. Participants will leave with a reusable signal checklist, a prioritization approach, and reference architectures to operationalize continuous monitoring without breaking least-privilege principles.
Speakers
avatar for Pranav Saji

Pranav Saji

Head of AI Security, Symosis Security
Pranav Saji is the Head of AI at Symosis Security, where he leads AI driven security and compliance initiatives focused on building production ready automation for SaaS integration risk signals and continuous evidence collection. His work helps security teams move from manual, periodic... Read More →
Wednesday November 4, 2026 9:00am - 5:00pm PST

9:00am PST

1-Day Training: How to build a Successful Security Champions Program
Wednesday November 4, 2026 9:00am - 5:00pm PST
1-Day Training: November 4, 2026
Level: Intermediate
Trainers: Juliane Reimann and Marisa Fagan

To register, please purchase your training ticket here. Training and conference are two separate ticket purchases.

Do you feel a disconnect between your cybersecurity efforts and engineering activities? If so, a Security Champions Program could bridge the gap. By involving engineers in security topics that align with their work, a Security Champions program not only enhances security awareness but also fosters a culture of security across your organization. However, creating such a program requires careful planning, innovative strategies, and a solid understanding of what drives individuals to champion security initiatives.

This training will equip you with practical tools and actionable insights to design and launch a successful Security Champions Program. You'll explore key concepts, including how to:
- Develop a foundational understanding of what a Security Champions Programs is
- Plan and navigate the phases of program development, from launch to long-term growth.
- Learn about strategies to engage and motivate diverse personality types within the organization
- Acquire practical tools and a structured approach to establish a scalable and trackable Security Champions Program

Whether you're a security engineer, architect, or manager, this training will provide you with the tools and frameworks to collaborate effectively with your engineering teams and establish a thriving Security Champions Program.

The session is highly interactive, featuring hands-on exercises and team-based activities to encourage collaboration and networking with fellow professionals. Join us to gain the confidence and strategies you need to kickstart your journey toward a more secure organization.
Speakers
MF

Marisa Fagan

Head of Product, Katilyst
avatar for Juliane Reimann

Juliane Reimann

Founder and Security Community Expert, Full Circle Security
Juliane Reimann works as cyber security consultant for large companies since 2019 with focus on DevSecOps and Community Building. Her expertise includes building security communities of software developers and establishing developer centric communication about secure software development... Read More →
Wednesday November 4, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

1-Day Training: OWASP AI Testing Guide (AITG): Enabling Trustworthy AI Through Structured Validation
Wednesday November 4, 2026 9:00am - 5:00pm PST
1-Day Training: November 4, 2026
Level: Intermediate
Trainers: Marco Morana and Matteo Meucci

To register, please purchase your training ticket here. Training and conference are two separate ticket purchases.

The OWASP AI Testing Guide (AITG) provides a structured, comprehensive framework for validating Trustworthy AI systems across their entire lifecycle. Designed to support QA teams, security engineers, developers, auditors, and governance stakeholders, AITG establishes practical testing methodologies to assess AI security, privacy, and responsible AI behaviors.

The framework defines Trustworthy AI as the integration of:
1) Security AI (SecAI): Testing resilience against adversarial attacks such as prompt injection, model poisoning, evasion, and extraction.
2) Privacy AI (PrivacyAI): Validating protection against sensitive data leakage, membership inference, and model inversion risks.
3) Responsible AI (RespAI): Assessing fairness, safety, harmful output prevention, hallucination risks, explainability, and alignment with ethical policies.

AITG organizes testing coverage across four core AI product domains:
1. Application & Agent Testing
2. Model Testing
3. Infrastructure Testing
4. Data Testing

This structured approach ensures that AI systems are evaluated holistically, not just at the model layer, but across agents, RAG pipelines, APIs, infrastructure components, and data flows.

The AITG Comprehensive AI Testing Suite maps AI-specific threats to recognized standards such as OWASP Top 10 for LLMs and the OWASP AI Exchange, providing actionable, test-driven validation methods rather than abstract principles.

By combining adversarial testing, privacy validation, and responsible AI assessments, supported by governance, transparency, and monitoring, AITG enables organizations to transition from experimental AI deployments to validated, production-ready, and defensible AI systems.
Speakers
avatar for Matteo Meucci

Matteo Meucci

Founder and CEO, Synapsed.ai
Matteo Meucci is the founder and CEO of Synapsed.ai, bringing over 23 years of experience in application security (AppSec) and AI systems development. Matteo has played a pivotal role in shaping the global security community, particularly through his work with OWASP, where he founded... Read More →
avatar for Marco Morana

Marco Morana

Founder, Threat Modeling Academy | Field CISO | Author & Instructor, Avocado Systems Inc

Marco Morana is the Founder of Threat Modeling Academy, a global training initiative dedicated to advancing threat modeling and secure-by-design engineering for AI, cloud, blockchain, and FinTech systems. He also serves as Field CISO at Avocado Systems Inc., where he advises enterprises... Read More →
Wednesday November 4, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

1-Day Training: Secure Code with AI: Building a Trustworthy Spec-Driven AI Code Workflow
Wednesday November 4, 2026 9:00am - 5:00pm PST

1-Day Training: November 4, 2026
Level: Beginner
Trainer: Jim Manico

To register, please purchase your training ticket here. Training and conference are two separate ticket purchases.

AI coding assistants are rapidly becoming the core of modern software delivery. They can accelerate development, generate tests, explain unfamiliar code, and assist with security review. They can also introduce insecure patterns, mishandle secrets, overreach with dangerous permissions, and produce code that appears correct while quietly violating security requirements.
This one-day, hands-on workshop shows developers and security professionals how to take control of AI-assisted development by building a trustworthy, spec-driven secure coding workflow.
Jim Manico walks participants through setting up a secure Claude Code and Codex environments from scratch, including permission controls, project-level security rules, hook configuration, and sandboxing. Participants will learn how to load secure coding prompts, define security requirements before code is generated, and use Claude Code and Codex side by side for secure code generation, security review, test creation, and vulnerability detection.
The session is fast-moving, demo-driven, and grounded in real codebases. Attendees will leave with practical workflows they can apply immediately to make AI coding assistants a security asset rather than an uncontrolled source of risk.
What You’ll LearnBy the end of this workshop, participants will be able to:
  • Configure a safer Claude Code environment using permission controls, CLAUDE.md security rules, hooks, and sandboxing.
  • Use secure coding prompts and project-level rules to guide AI tools toward secure-by-default output aligned with OWASP guidance.
  • Apply spec-driven AI development techniques so security requirements are defined before code is generated.
  • Use Claude Code and Codex together for code generation, independent review, vulnerability detection, and test creation.
  • Identify common insecure patterns produced by AI coding assistants, including weak authorization, injection flaws, insecure secret handling, unsafe dependencies, and insufficient validation.
  • Build repeatable AI-assisted workflows that developers, security engineers, and technical leads can bring back to their own teams.
Who Should AttendThis course is designed for:
  • Developers using or evaluating AI coding assistants who want to ship secure code from the start.
  • Security engineers who need to understand how AI tools generate insecure code patterns and how to detect, review, and fix them.
  • Application security professionals building secure development workflows for AI-assisted engineering teams.
  • Tech leads and architects evaluating how AI coding tools should be adopted safely across their organizations.
RequirementsParticipants should bring a laptop suitable for software development and be comfortable working with command-line tools, source code, and Git. An OpenAI or Anthropic account is needed to participate which we can set up in class. Prior experience with AI coding assistants is helpful but not required. The course is designed for developers and security professionals who want practical, repeatable workflows for using AI safely in real engineering environments.

Speakers
Wednesday November 4, 2026 9:00am - 5:00pm PST
TBA
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -