World Congress 2025 • Aug 20, 2025 • Session details

Simple Steps to Kill DevSec without Giving Up on Security

Isaac Evans

Stop playing security whack-a-mole. Shifting left shouldn't mean drowning engineers in noisy alerts. Discover how to deploy invisible guardrails that protect code without destroying developer velocity.

Pause
Mute Enter Fullscreen
#1 about 2 min

Moving from binary exploitation to static code analysis

Transitioning from patching reactive vulnerabilities to making software exploitation fundamentally more expensive requires using code to analyze code.

#2 about 3 min

The impact of false positives on developer trust

Developers quickly ignore security tools when false positive rates exceed a low threshold of around ten percent.

#3 about 3 min

Rethinking shift left to avoid developer frustration

Shifting raw security alerts to developers often backfires unless an organization focuses on making software intrinsically harder to exploit.

#4 about 3 min

Moving from security gates to secure developer guardrails

Effective application security requires shifting from post-build vulnerability backlogs to frictionless preventative guardrails embedded in developer workflows.

#5 about 4 min

Building native security workflows and automated fix suggestions

Providing developers with frictionless base images and automated fix advice prevents issues while maintaining high deployment velocity.

#6 about 4 min

Prioritizing new code over legacy vulnerability backlogs

Because vulnerabilities decay over time, organizations achieve better security outcomes by isolating new code rather than rewriting entire legacy applications.

#7 about 2 min

Elevating basic developer security knowledge for rapid wins

Equipping developers with fundamental security concepts yields immediate bug bounty savings by preventing flaws during initial coding.

#8 about 2 min

Integrating security context directly into code generating models

Applying static analysis guardrails to massive code volumes produced by AI assistants prevents insecure endpoints and logic defects.

#9 about 3 min

Improving application security programs with tailored custom rules

Replacing generic vulnerability scanners with highly specific custom rules drastically improves developer compliance and overall program effectiveness.

Matching moments

2:30 min

Bridging the gap between developers and security tools

Bozidar Spirovski Bozidar Spirovski +1 · Coffee With Developers

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

7:16 min

Addressing developer adoption and future software security risks

Anna Fritsch-Weninger · LIVE

2:49 min

Integrating fundamental security evaluations into agile development sprints

Bozidar Spirovski Bozidar Spirovski +1 · Coffee With Developers

4:58 min

Scaling security teams through developer advocates

Tanya Janca · World Congress 2021

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 25, 2026 · 09:00–09:30

Stage 4

Don’t kill my Vibes - Simple Steps to Stay Secure when Vibe Coding

Isaac Evans

Founder & CEO of Semgrep

Isaac Evans
Open session

World Congress 2026 North America

September 25, 2026 · 15:00–17:00

Stage 12

Secure development from pull request to production with GitHub

Sam Jarvinen

Senior Solutions Engineer, GitHub

Sam Jarvinen
Open session

World Congress 2026 North America

September 24, 2026 · 14:50–15:20

Stage 1

The Era of Machine-Driven Defense is Here: Headless Security

Loris Degioanni

Founder & CTO of Sysdig

Loris Degioanni
Open session

World Congress 2026 North America

September 25, 2026 · 13:30–14:00

Stage 9

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

September 24, 2026 · 11:40–12:10

Stage 3

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

September 24, 2026 · 16:00–18:00

Stage 13

Practical Threat Modeling for Software Developers

Mudassir Syed

Lead Security Software Engineer

Mudassir Syed