Loading…
OWASP Global AppSec US 2021 has ended
All [clear filter]
Thursday, November 11
 

9:00am PST

25 Years in AppSec: Looking Back, Looking Forward
Speakers
avatar for Adam Shostack

Adam Shostack

President, Shostack + Associates
Adam is a leading expert on threat modeling, and a consultant, entrepreneur, technologist, author and game designer. He's a member of the BlackHat Review Board, and helped create the CVE and many other things. He currently helps many organizations improve their security via Shostack... Read More →


Thursday November 11, 2021 9:00am - 10:00am PST
On-Line
  Keynote

10:30am PST

How to Use Your Vulnerabilities to Train Your Developers on Security
The idea of secure coding training that covers just what you need, right when you need it, seems too good to be true. But it’s not. Leading development teams are using their own vulnerabilities to train their coders, focusing on their most pressing mistakes while providing a more relevant experience that keeps coders engaged. This presentation will show you how to set up a program, and how to make sure your developers develop a fix that really solves the problem.

Speakers
avatar for Jared Ablon

Jared Ablon

President, HackEDU
Jared Ablon is the President and co-founder of HackEDU. His experience includes serving as a CISO, leading cybersecurity teams at the Department of Defense, and founding two companies. Jared has a CISSP, MBA and an MS in Applied and Computational Mathematics focusing on computer/cyber... Read More →


Thursday November 11, 2021 10:30am - 11:00am PST
On-Line

11:00am PST

GitHub
GitHub is the developer company. We make it easier for developers to be developers: to work together, to solve challenging problems, to create the world’s most important technologies. We foster a collaborative community that can come together—as individuals and in teams—to create the future of software and make a difference in the world.

https://github.com/



Thursday November 11, 2021 11:00am - 11:30am PST
On-Line

11:30am PST

Changed Responsibilities in Modern Development Practices
With the business increased the pressure and demand for flexibility of the development team, the agile movement was pushed to the limits. CI/CD was born to reduce manual steps to reduce human errors and increase speed to go-live! Last not least, with DevOps the teams took application responsibilities, from cradle to grave. Many security teams still struggling on catching up with the current speed of software development and releases. Software security knowledge and experience is missing in most full-stack developers' resumes. Application security is kept out of the development teams responsibility and regarded as a responsibility of the  security department. Pity, because agile, CI/CD and DevOps are security enabling practices! This session is explaining Shift-left, early security enablement in the development Lifecycle. As the application development becomes more developer centric, the developer’s toolset must match the new challenges to have responsibilities matching capabilities. Learn from rugged software to supply chain cleanliness. Learn to avoid the common pitfalls and benefits of modern application development strategies. Hear why security champions programmes tend to fail, compliance driven security training is a waste of time and money. Take back the best practices, proven solutions and how to Shift Left beyond the development

Speakers
avatar for Martin Knobloch

Martin Knobloch

Global AppSec Strategist, Micro Focus
Martin Knobloch, Global AppSec Strategist with CyberRes, a Micro Focus line of business, is a long-time security leader with more than 15 years of experience in the field. With a background in software development and architecture, his focus is on software security. Martin is actively... Read More →


Thursday November 11, 2021 11:30am - 12:00pm PST
On-Line

3:00pm PST

Are you safe from OWASP #11
Everyone loves Top 10 lists but that's where API security STARTS - not ENDS. Come hear a lighthearted poke at Top 10 lists and what it takes to have a high-functioning API security program at scale. Don't get pwn3d by OWASP #11, create a successful API program and get a t-shirt to prove it you know better.

Speakers
avatar for Matt Tesauro

Matt Tesauro

DevSecOps and Security Automation advocate, Noname Security
Matt Tesauro is currently the Global Director of Security Evangelism at Noname Security. When not writing automation code in Go, Matt Tesauro is pushing for DevSecOps everywhere by contributing to open source projects, presenting, training and continuing to co-opt new technologies... Read More →


Thursday November 11, 2021 3:00pm - 3:30pm PST
On-Line

3:30pm PST

Why security fails, and how we can solve for it
As a company working in the security assessment space, Praetorian engineers have seen it all - ranging from an open S3 bucket sitting out in the cloud to Nation-state level code wrangling where we've taken control of a company using bespoke vulnerabilities. Using real-world examples from the field, we will explore lessons learned from our services practice and our process for, at times, translating those into open source products. Does security need to be as gosh-darn hard as it is in real life or is it a matter of working smarter, not harder? We will conclude with a discussion of actionable steps you can take to make your life easier.

Speakers
avatar for Richard Ford

Richard Ford

Chief Technology Officer, Praetorian
As a company working in the security assessment space, Praetorian engineers have seen it all - ranging from an open S3 bucket sitting out in the cloud to Nation-state level code wrangling where we've taken control of a company using bespoke vulnerabilities. Using real-world examples... Read More →


Thursday November 11, 2021 3:30pm - 4:00pm PST
On-Line

5:15pm PST

OWASP Leaders Meeting
OWASP Leaders Meeting
OWASP Leaders from projects, chapters, events, and committees are invited to listen to the latest updates about OWASP functional areas and to come together to share their experiences and discuss how to further the OWASP mission.

Speakers
avatar for Lisa Jones

Lisa Jones

Chapter and Membership Manager, OWASP Foundation
Lisa is the Chapter and Membership Manager at the OWASP Foundation. The Chapter and Membership Manager is a members’ advocate that professionally manages and services the chapter and membership functions of the OWASP Foundation. Additionally, this role supports our global partnerships... Read More →
avatar for Harold Blankenship

Harold Blankenship

Director of Technology & Projects, OWASP Foundation
Harold is the Director of Technology and Projects at the OWASP Foundation. The Director of Technology & Projects nurtures, manages, facilitates, and supports the volunteer open-source programs of the Foundation. Additionally, the Director of Technology & Projects champions, manages... Read More →


Thursday November 11, 2021 5:15pm - 6:15pm PST
On-Line
 
Friday, November 12
 

2:00pm PST

We Deserve Rights
Hackers have been mislabeled and treated as criminals due to socially constructed beliefs that have been pushed out by the public. In return, we face prosecution when doing our job and trying to keep the world safe from attackers. Current legislation has destroyed many lives of hackers who did not exploit and stayed within scope. In return, 1 out of 4 hackers don't submit vulnerabilities due to the ongoing fear of prosecution. This talk dives into the socially constructed beliefs that the world has towards hackers and how increasing public awareness is needed to change their mindset to update out-of-date legislation.

Speakers
avatar for Chloé Messdaghi

Chloé Messdaghi

CEO and Founder, Global Secure Partners
For over ten years, Chloé Messdaghi has advised and developed impactful solutions that have driven growth and innovation while transforming security teams to become resilient. Her work has helped businesses unlock opportunities to enhance trust, mitigate risk, and become purpose-driven... Read More →


Friday November 12, 2021 2:00pm - 3:00pm PST
On-Line
  Keynote
 
Filter sessions
Apply filters to sessions.