Loading…
Venue: Room: Bayview B (Bay Level) clear filter
arrow_back View All Dates
Friday, November 6
 

10:30am PST

From IC to Leader: A Field Guide to Building High-Performing Security Teams
Friday November 6, 2026 10:30am - 11:15am PST
Most security leaders are exceptional technologists, but building and managing a high-performing security team requires an entirely different skill set - one that is rarely taught and almost never documented. This talk closes that gap.

Drawing on 20+ years spanning Big 4 consulting, multiple security org builds from scratch, and security leadership roles across fintech, banking, and SaaS, this expanded session delivers a comprehensive, practitioner-tested playbook for security team leadership.

Attendees leave with actionable frameworks across the full leadership lifecycle: crafting job descriptions that attract elite talent, structured onboarding plans that accelerate time-to-contribution, Agile practices purpose-built for security teams, performance management grounded in four concrete pillars, a live case study walking through how these frameworks interact in practice, and managing up to executives with clarity and confidence.

Beyond the operational mechanics, the talk addresses the human dimensions of leadership that often go unspoken: building psychological safety, navigating conflict, developing a culture of continuous learning, and supporting team well-being to prevent burnout, a persistent challenge in a high-pressure field.

Whether you are a first-time security manager, a seasoned CISO, or a practitioner preparing to lead, this session delivers real-world guidance, not theory. Every framework presented has been used in production at companies ranging from 10-person startups to public companies. Come prepared to take notes, the slides include reusable templates you can apply to your team on Monday.
Speakers
avatar for Anshu Gupta

Anshu Gupta

Founder, Fixin Security
Anshu Gupta is a seasoned global cybersecurity executive with Fortune 500 advisory experience at EY and KPMG, working with companies including Microsoft, Salesforce, Cisco, and Adobe. He has built and led security programs at high-growth startups and fintechs, including Coupa, HelloSign... Read More →
Friday November 6, 2026 10:30am - 11:15am PST
Room: Bayview B (Bay Level)

11:30am PST

Shadow AI is the new Shadow IT
Friday November 6, 2026 11:30am - 12:15pm PST
Decades ago we identified Shadow IT as a major cybersecurity risk, and we realized that we can't secure what we don't see. As history likes to repeat itself, we are now back in exactly the same place with AI. And we are in a race against time, as currently AI adoption in most organizations is moving faster than their ability to govern it. This talk aims to shift the paradigm from AI as primarily a technology risk, to it being a governance challenge. And in doing so, to offer the audience a pragmatic, risk-based approach to governing AI without slowing innovation. We will visit current threats and emerging frameworks that can already be applied for bringing AI risk back under control. Because when an organization will have an AI security incident, the CISO will not have to answer about the AI technical failures, but rather about the lack of governance around it.
Speakers
avatar for Sebastian Avarvarei

Sebastian Avarvarei

Consulting CISO & Leadership Development Coach
With over 20 years of experience in cybersecurity at both strategic and operational levels, and a proven track record of building high-performing security teams, Sebastian takes a multi-faceted view on today's security challenges, successfully blending technical acumen with business... Read More →
Friday November 6, 2026 11:30am - 12:15pm PST
Room: Bayview B (Bay Level)

1:15pm PST

Why Developers Can and We Can't: Making Security Findings That Agents (and Humans) Can Act On
Friday November 6, 2026 1:15pm - 2:00pm PST
Coding agents went from novelty to daily driver in less than three years. Developers are now using AI to generate, test, and ship code as part of their normal workflow. But the way security communicates guidance has barely changed: findings buried in long documents, review comments that arrive after key decisions are already made, and requirements that are too vague for a developer to act on — let alone a coding agent.

The issue is not that developers do not care about security. It is that security intent often never reaches them in a form they can actually use.

So why did AI change the engineering workflow so quickly, while security reviews still look the same?

This talk looks at the structural reason behind that gap. Coding agents can only act on guidance that is specific, contextual, and executable. Most threat models and design review findings do not meet that bar. We will look at where review output breaks down in practice: findings that are technically true but not relevant, likelihood ratings that drift from reality, recommendations that are impossible to implement, and issues that no one knows how to translate into engineering work.

A human developer may be able to interpret a vague finding and make a judgment call. A coding agent will not. It will simply keep building without the missing security intent.

The second half of the talk focuses on what to do about it. We will present a practical framework for turning security review output into findings that are grounded in the real architecture, aware of existing controls, scoped to threats that actually apply, and written in a way that developers can act on.

Attendees will leave with a framework they can apply to their own design review or threat modeling process immediately, along with quality signals for measuring whether security findings are accurate, useful, and actually acted on.
Speakers
HM

Hai Maler

Head of Research, Clover Security
Hai Maler is Head of Research at Clover Security, where he drives research that brings advanced AI capabilities into practical product security workflows. He brings over 10 years of industry experience, from breaking systems and studying how they fail to building tools that help defenders... Read More →
Friday November 6, 2026 1:15pm - 2:00pm PST
Room: Bayview B (Bay Level)

2:15pm PST

From Consuming to Contributing: How We Built the Space That Was Missing
Friday November 6, 2026 2:15pm - 3:00pm PST
Many of us naturally drift from consuming OWASP resources to contributing to them. At some point you stop just reading the Top 10 and start showing up at a chapter, submitting a pull request, or volunteering at a conference. But what often gets lost is the "together" part. The shared strategy, the mutual encouragement, a place where experienced contributors can mentor others and people new to contributing can find their footing without having to figure it out alone.

It started when two of us ran into each other at the Boston Application Security Conference. Same organization, same department, had no idea the other was there. That conversation grew into three people, then a cross-regional group, and eventually an initiative with executive sponsorship built around a simple question: what if there was a structured space where people at all levels of OWASP engagement could come together, share what they know, coordinate where to show up, and help each other go deeper?

That is what we built. A space where seasoned contributors have a home for their work and a way to pass it on, and where people curious about OWASP but not sure where to start can learn, get mentored, and take their first real steps. Contribution gets tracked, progress gets shared, and the work gets recognized internally in ways it never was before.

In this talk we share our journey, what the initiative looks like in practice, what we have achieved together so far, and what you can take back to your own organization.
Speakers
avatar for Saquib Saifee

Saquib Saifee

AI Security Engineer, IBM
Saquib Saifee is an AI Security Engineer at IBM working at the intersection of AI security, software supply chain security, and offensive security. He contributes to the OWASP GenAI Security Project on securely using and building MCP servers, participates in the Linux Foundation AI... Read More →
avatar for Caroline Lee

Caroline Lee

Secuirty Engineer, IBM
Caroline is based out of Boston, Massachusetts, and works as a Security Engineer at IBM in CISO Remediation. She holds a Masters in Computer Science with a Specialization in Cybersecurity.
Previously, she has worked on CICD, Application Security, and Cloud Security initiatives in... Read More →
avatar for Gaurang Deshpande

Gaurang Deshpande

Software Developer, Cyber Defense, IBM
Friday November 6, 2026 2:15pm - 3:00pm PST
Room: Bayview B (Bay Level)

3:30pm PST

Breaking the Headcount Scaling Model: How GitLab's Product Security Teams Achieved Non-Linear Securi
Friday November 6, 2026 3:30pm - 4:15pm PST
Complete title that is cut by "Session Title" size limit: Breaking the Headcount Scaling Model: How GitLab's Product Security Teams Achieved Non-Linear Security Gains with AI

Engineering ships faster every quarter with AI assisted development, Security headcount grows slowly and the review backlog keeps growing at a rate you wish you didn’t know! This talk traces the struggles of building an AppSec function from scratch, through the scaling pain of supporting a fast-growing engineering organization, to the entirely new class of challenges created by the rise of AI-assisted software development.

And it starts with the pain. Building an AppSec function inside a fast-growing engineering org means years of playing catch-up: hiring into a market with a shortage of talent, onboarding people who take months to become productive and sitting at a security engineer-to-developer ratio of 1 to 2%(and 2& when you’re lucky!) that never meaningfully improves. Somewhere along the way, it can become the team that slows things down and that’s when engineering teams no longer want you onboarded and be part of their workflow.

Then AI changed the game much faster than anticipated and in ways we did not plan for: engineering velocity jumped, AI-generated code brought volumetric challenges at the “diff” level as well as at scale. And teams started building features on top of AI. This creates threat surfaces that weren’t present before and that threat actors have leveraged extensively since the beginning of the year. We are now fighting on two fronts: securing AI-powered features while keeping up with AI-accelerated development speed.

This talk covers how we responded with AI-powered (and non AI-powered) automations, and which hard decisions we had to take to enable those improvements to happen. We will explain the change in how we had to think about the solutions to match not only human expectations, but also work with AI-powered tools as well as the capacity cost of building these tools. We will also cover some of the challenges we faced (and are still facing) when we had to leverage AI solutions and how we think our team will evolve in the coming months.
Speakers
avatar for Vitor Meireles

Vitor Meireles

Senior Security Engineering Manager AppSec, GitLab

Vitor Meireles is a security professional with over 15 years of experience in the field. Currently serving as a Senior Security Engineering Manager at GitLab, he helps engineering teams build applications that are secure by design. Vitor has past experiences in the consulting, financial... Read More →
Friday November 6, 2026 3:30pm - 4:15pm PST
Room: Bayview B (Bay Level)
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -