> Markdown version of [/videos/100323-automated-security-for-the-entire-sdlc?t=822](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc?t=822). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Automated Security for the Entire SDLC Are traditional security models slowing your AI-assisted deployments? Discover how TikTok uses LLMs to inject security into technical specs before a single line of code is written. - **Speakers:** [Carey Liu](https://www.wearedevelopers.com/@carey-liu) - **Event:** World Congress 2026 Europe - **Published:** July 10, 2026 - **Duration:** 27:30 - **URL:** https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc ## Summary As AI-assisted coding accelerates software development, traditional security models struggle to keep pace, frequently catching vulnerabilities too late in the SDLC. Discovering issues during production or through external bug bounties leads to expensive rework, deployment delays, and eroded user trust. To address this scaling challenge, TikTok's Global Security Organization reimagined its approach by shifting security conceptually and technologically "left"—introducing automated risk assessments before a single line of code is written. The cornerstone of this proactive strategy is SEVA (Spec Driven Engineering Validation Agent), an LLM-powered tool that continuously validates Product Requirements Documents (PRDs) and Technical Design Documents (TRDs). Operating as a silent partner rather than a workflow blocker, SEVA integrates directly into existing project management platforms to cross-reference software blueprints against over 500 security control points across 90 domains. It then appends necessary security controls directly into the technical specifications, ensuring downstream AI coding assistants naturally incorporate secure-by-default logic. Transitioning security from a systemic bottleneck to an active engineering partner fundamentally improves development culture. By categorizing potential risks into technical vulnerabilities, compliance gaps, and business logic flaws, SEVA equips engineers with contextual attack chains, tangible business impacts, and actionable remediation steps sourced from internal penetration testers. A critical insight for organizations deploying AI-native security tools is the necessity of maintaining continuous R&D feedback loops alongside a foundational "golden test set" to evaluate prompt accuracy as underlying LLM base models evolve. Ultimately, engineering efficiency is dictated not just by raw talent, but by exactly when and where security surfaces in the workflow. **Keywords:** automated SDLC security, ai-assisted security validation, shift-left security, security by design, PRD and TRD risk assessment, LLM prompt evaluation, automated vulnerability management, compliance risk mitigation, developer workflow integration, ai coding assistants, security control databases, proactive threat modeling, penetration testing remediation, engineering velocity ## Chapters 1. **Managing security risks in AI-accelerated development processes** (00:20) — Generating code rapidly with AI introduces vulnerabilities that are costly to fix if discovered late. 1. **The hidden costs of late security intervention** (03:57) — Unplanned rework, staging vulnerabilities, and production incidents disrupt workflows when security is an afterthought. 1. **Embedding security controls during the design phase** (07:50) — Proactive security validation integrates control requirements into technical design documents prior to code generation. 1. **Validating technical designs with an AI security agent** (10:41) — A multi-stage validation workflow scopes relevant domains and abstracts risks before writing code. 1. **Actionable security guidance in product validation reports** (13:42) — Exposing potential attack chains and compliance consequences helps engineers address critical business logic flaws. 1. **Shifting security from unhelpful blockers to collaborative partners** (15:52) — Integrating native validation tools into existing collaboration platforms creates a positive feedback loop with developers. 1. **Scaling AI-native security capabilities across the system** (17:56) — Matching engineering velocity requires continuous learning and embedding validation seamlessly into code generation workflows. 1. **Validating AI-generated vulnerabilities with developer feedback** (19:51) — Utilizing user feedback loops helps identify the most accurate security risks and improves agent training data. 1. **Adopting design-stage security for external development teams** (21:04) — Open-sourcing security prompts and agent skills enables independent developers to run early validation checks. 1. **Testing probabilistic large language models against new threats** (22:17) — Maintaining a golden test set ensures consistent security coverage when upgrading internal foundational models. 1. **Balancing human engineering insight with automated security tools** (23:38) — Fostering a security-by-design culture combined with strict internal policies simplifies identifying issues efficiently. 1. **Reviewing deterministic security controls and compliance frameworks** (25:46) — Continuous iteration of control points against industry best practices reduces false positives in automated validation. ## Related Moments - [Introduction to security advocacy and automation testing](https://www.wearedevelopers.com/videos/1331-wearedevelopers-live-chrome-for-sale-comet-the-upcoming-perplexity-browser-stealing-and-leaking) (from "WeAreDevelopers LIVE - Chrome for Sale? Comet - the upcoming perplexity browser Stealing and leaking") - [Security integration and AI skepticism in developer tooling](https://www.wearedevelopers.com/videos/1830-wearedevelopers-live-speculaitions) (from "WeAreDevelopers LIVE - SpeculAItions") - [Injecting automated security into mobile CI/CD pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) (from "DevSecOps: Injecting Security into Mobile CI/CD Pipelines") - [Shifting left and creating internal security champion programs](https://www.wearedevelopers.com/videos/346-stranger-danger-your-java-attack-surface-just-got-bigger) (from "Stranger Danger: Your Java Attack Surface Just Got Bigger") - [Managing vulnerabilities in auto-generated software development processes](https://www.wearedevelopers.com/videos/926-wwc24-chris-wysopal-helmut-reisinger-and-johannes-steger-fighting-digital-threats-in-the-age-of-ai) (from "WWC24 - Chris Wysopal, Helmut Reisinger and Johannes Steger - Fighting Digital Threats in the Age of AI") - [Shifting security left using the DevSecOps approach](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) (from "DevSecOps: Security in DevOps") ## Related Articles - [Exploring AI: Opportunities and Risks for Developers](https://www.wearedevelopers.com/magazine/522-exploring-ai-opportunities-and-risks-for-developers) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) ## Related Jobs - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/1921051-staff-developer-advocate-github-security-lab) at **GitHub** - [Security Architect - AI](https://www.wearedevelopers.com/jobs/ext/1581899-security-architect-ai) at **ZEISS Group** - [Engineer, Offensive Security Organization](https://www.wearedevelopers.com/jobs/ext/1992296-engineer-offensive-security-organization) at **Twilio** - [Security Engineer](https://www.wearedevelopers.com/jobs/ext/1574416-security-engineer) at **Twilio** - [Staff Engineer, Security Engineering Partners](https://www.wearedevelopers.com/jobs/ext/1187268-staff-engineer-security-engineering-partners) at **Twilio** - [Staff Engineer - Offensive Security](https://www.wearedevelopers.com/jobs/ext/1226927-staff-engineer-offensive-security) at **Twilio**