World Congress 2026 Europe Jul 10, 2026 Session details

Automated Security for the Entire SDLC

Carey Liu

Are traditional security models slowing your AI-assisted deployments? Discover how TikTok uses LLMs to inject security into technical specs before a single line of code is written.

Pause
Mute Enter Fullscreen
#1 about 4 min

Managing security risks in AI-accelerated development processes

Generating code rapidly with AI introduces vulnerabilities that are costly to fix if discovered late.

#2 about 4 min

The hidden costs of late security intervention

Unplanned rework, staging vulnerabilities, and production incidents disrupt workflows when security is an afterthought.

#3 about 3 min

Embedding security controls during the design phase

Proactive security validation integrates control requirements into technical design documents prior to code generation.

#4 about 4 min

Validating technical designs with an AI security agent

A multi-stage validation workflow scopes relevant domains and abstracts risks before writing code.

#5 about 3 min

Actionable security guidance in product validation reports

Exposing potential attack chains and compliance consequences helps engineers address critical business logic flaws.

#6 about 3 min

Shifting security from unhelpful blockers to collaborative partners

Integrating native validation tools into existing collaboration platforms creates a positive feedback loop with developers.

#7 about 2 min

Scaling AI-native security capabilities across the system

Matching engineering velocity requires continuous learning and embedding validation seamlessly into code generation workflows.

#8 about 2 min

Validating AI-generated vulnerabilities with developer feedback

Utilizing user feedback loops helps identify the most accurate security risks and improves agent training data.

#9 about 2 min

Adopting design-stage security for external development teams

Open-sourcing security prompts and agent skills enables independent developers to run early validation checks.

#10 about 2 min

Testing probabilistic large language models against new threats

Maintaining a golden test set ensures consistent security coverage when upgrading internal foundational models.

#11 about 3 min

Balancing human engineering insight with automated security tools

Fostering a security-by-design culture combined with strict internal policies simplifies identifying issues efficiently.

#12 about 2 min

Reviewing deterministic security controls and compliance frameworks

Continuous iteration of control points against industry best practices reduces false positives in automated validation.

Matching moments

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

4:15 min

Security integration and AI skepticism in developer tooling

Chris Heilmann +2 · LIVE

3:05 min

Injecting automated security into mobile CI/CD pipelines

Moataz Nabil Moataz Nabil · LIVE

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

2:58 min

Managing vulnerabilities in auto-generated software development processes

Chris Wysopal Chris Wysopal +2 · WWC 2024

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

Upcoming sessions on this topic

Open session

World Congress 2026 North America

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer @ Capital One

Desmond Lamptey
Open session

World Congress 2026 North America

SecurePrompt: Building a Pre-Flight Security Layer for Agentic AI

Ravi Sastry Kadali

AI/ML Engineer at General Motors

Ravi Sastry Kadali
Open session

World Congress 2026 North America

Don’t kill my Vibes - Simple Steps to Stay Secure when Vibe Coding

Isaac Evans

Co-founder & CEO of Semgrep

Isaac Evans
Open session

World Congress 2026 North America

Who Tests the AI? Building Trustworthy AI Systems at Enterprise Scale

Him Raj Singh

PayPal, Manager, Software Engineer

Him Raj Singh
Open session

World Congress 2026 North America

Reinventing Testing Practices in the AI Era

Eric Deandrea

Java Champion & Senior Principal Software Engineer, IBM

Eric Deandrea
Open session

World Congress 2026 North America

Red Teaming Your LLM App -- A Hands-On Threat Model You Can Reuse

Saloni Garg

Senior ML Engineer at Adobe

Saloni Garg