World Congress 2025 Aug 20, 2025 Session details

Simple Steps to Kill DevSec without Giving Up on Security

Isaac Evans

Stop playing security whack-a-mole. Shifting left shouldn't mean drowning engineers in noisy alerts. Discover how to deploy invisible guardrails that protect code without destroying developer velocity.

Pause
Mute Enter Fullscreen
#1 about 2 min

Moving from binary exploitation to static code analysis

Transitioning from patching reactive vulnerabilities to making software exploitation fundamentally more expensive requires using code to analyze code.

#2 about 3 min

The impact of false positives on developer trust

Developers quickly ignore security tools when false positive rates exceed a low threshold of around ten percent.

#3 about 3 min

Rethinking shift left to avoid developer frustration

Shifting raw security alerts to developers often backfires unless an organization focuses on making software intrinsically harder to exploit.

#4 about 3 min

Moving from security gates to secure developer guardrails

Effective application security requires shifting from post-build vulnerability backlogs to frictionless preventative guardrails embedded in developer workflows.

#5 about 4 min

Building native security workflows and automated fix suggestions

Providing developers with frictionless base images and automated fix advice prevents issues while maintaining high deployment velocity.

#6 about 4 min

Prioritizing new code over legacy vulnerability backlogs

Because vulnerabilities decay over time, organizations achieve better security outcomes by isolating new code rather than rewriting entire legacy applications.

#7 about 2 min

Elevating basic developer security knowledge for rapid wins

Equipping developers with fundamental security concepts yields immediate bug bounty savings by preventing flaws during initial coding.

#8 about 2 min

Integrating security context directly into code generating models

Applying static analysis guardrails to massive code volumes produced by AI assistants prevents insecure endpoints and logic defects.

#9 about 3 min

Improving application security programs with tailored custom rules

Replacing generic vulnerability scanners with highly specific custom rules drastically improves developer compliance and overall program effectiveness.

Matching moments

2:30 min

Bridging the gap between developers and security tools

Bozidar Spirovski Bozidar Spirovski +1 · Coffee With Developers

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

7:16 min

Addressing developer adoption and future software security risks

Anna Fritsch-Weninger · LIVE

2:49 min

Integrating fundamental security evaluations into agile development sprints

Bozidar Spirovski Bozidar Spirovski +1 · Coffee With Developers

4:58 min

Scaling security teams through developer advocates

Tanya Janca · WWC 2021

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Don’t kill my Vibes - Simple Steps to Stay Secure when Vibe Coding

Isaac Evans

Co-founder & CEO of Semgrep

Isaac Evans
Open session

World Congress 2026 North America

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

Practical Threat Modeling for Software Developers

Mudassir Syed

Lead Security Software Engineer

Mudassir Syed
Open session

World Congress 2026 North America

Secure-by-Inclusion: Preventing Accessibility Barriers from Becoming Security Vulnerabilities

Radostina (Ina) Tsvetkova

Norwegian Directorate of Labour and Welfare (NAV), Senior Advisor in Digital Accessibility and Inclusive Design

Radostina (Ina) Tsvetkova
Open session

World Congress 2026 North America

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer @ Capital One

Desmond Lamptey