Loading…
Wednesday November 4, 2026 9:00am - 5:00pm PST

1-Day Training: November 4, 2026
Level: Beginner
Trainer: Jim Manico

To register, please purchase your training ticket here. Training and conference are two separate ticket purchases.

AI coding assistants are rapidly becoming the core of modern software delivery. They can accelerate development, generate tests, explain unfamiliar code, and assist with security review. They can also introduce insecure patterns, mishandle secrets, overreach with dangerous permissions, and produce code that appears correct while quietly violating security requirements.
This one-day, hands-on workshop shows developers and security professionals how to take control of AI-assisted development by building a trustworthy, spec-driven secure coding workflow.
Jim Manico walks participants through setting up a secure Claude Code and Codex environments from scratch, including permission controls, project-level security rules, hook configuration, and sandboxing. Participants will learn how to load secure coding prompts, define security requirements before code is generated, and use Claude Code and Codex side by side for secure code generation, security review, test creation, and vulnerability detection.
The session is fast-moving, demo-driven, and grounded in real codebases. Attendees will leave with practical workflows they can apply immediately to make AI coding assistants a security asset rather than an uncontrolled source of risk.
What You’ll LearnBy the end of this workshop, participants will be able to:
  • Configure a safer Claude Code environment using permission controls, CLAUDE.md security rules, hooks, and sandboxing.
  • Use secure coding prompts and project-level rules to guide AI tools toward secure-by-default output aligned with OWASP guidance.
  • Apply spec-driven AI development techniques so security requirements are defined before code is generated.
  • Use Claude Code and Codex together for code generation, independent review, vulnerability detection, and test creation.
  • Identify common insecure patterns produced by AI coding assistants, including weak authorization, injection flaws, insecure secret handling, unsafe dependencies, and insufficient validation.
  • Build repeatable AI-assisted workflows that developers, security engineers, and technical leads can bring back to their own teams.
Who Should AttendThis course is designed for:
  • Developers using or evaluating AI coding assistants who want to ship secure code from the start.
  • Security engineers who need to understand how AI tools generate insecure code patterns and how to detect, review, and fix them.
  • Application security professionals building secure development workflows for AI-assisted engineering teams.
  • Tech leads and architects evaluating how AI coding tools should be adopted safely across their organizations.
RequirementsParticipants should bring a laptop suitable for software development and be comfortable working with command-line tools, source code, and Git. An OpenAI or Anthropic account is needed to participate which we can set up in class. Prior experience with AI coding assistants is helpful but not required. The course is designed for developers and security professionals who want practical, repeatable workflows for using AI safely in real engineering environments.

Speakers
Wednesday November 4, 2026 9:00am - 5:00pm PST
TBA

Attendees (0)


Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link