These industry leaders bring a wealth of knowledge and experience in Application Security, and we are excited to have them share their insights and spicy opinions with us.
Tanya Janca
Head of Education & Community @ Semgrep
Speaker bio
Kim Wuyts
Manager Cyber & Privacy @ PWC
Speaker bio
Cassey Crossley
VP Supply Chain Security @ Schneider Electric
Speaker bio
Akira Brand
AppSec Engineer and DevRel consultant
Speaker bio
Chris Romeo
CEO and Co-Founder @ Devici
Speaker bio
Dustin Lehr
Co-founder @ Katilyst Security
Speaker bio
Jacob Salassi
Co-Founder @ Stealth-mode Startup, Former Director of Product Security at Snowflake
Speaker bio
Mel Reyes
Global CIO & CISO turned Executive Coach & Advisor, Creator @ The Fellowship of Digital Guardians
Speaker bio
Ariel Shin
Security Engineering Manager @ Datadog

Speaker bio
Alina Yakubenko
Senior Application Security Engineer @ Toast, Inc.
Speaker bio
Aravind Sreenivasa
Manager, Application Security @ SeatGeek
Speaker bio
James Berthoty
Founder @ Latio Tech

Speaker bio
Sandesh Mysore Anand
Co-founder @ Seezo.io
Former Head of Security @ Razorpay
Speaker bio
Antoine Carossio
Co-Founder and CTO @ Escape
Speaker bio
Amit Bismut
Head of Product @ Backslash Security
Speaker bio
Ron Nissim
CEO and Co-founder @ Entitle
Speaker bio
Swan Beaujard
Security Software Engineer @ Escape
Speaker bio
Tristan Kalos
CEO @ Escape
Speaker bio
Jeevan Singh
Director of Security Engineering @ Rippling
Speaker bio
Kyle Kelly
Tech Lead Supply Chain Security Research @ Semgrep
Speaker bio
Munawar Hafiz
CEO @ OpenRefactory

Speaker bio
Anmol Agarwal
Senior Security Researcher @ Nokia
Speaker bio
Track 1 - General AppSec Topics
Explore what’s broken in AppSec and how to fix it.
This track is full of bold insights and spicy takes that challenge the status quo.
Tanya Janca
Shifting Left Doesn’t Mean Anything Anymore
9:05 AM - 9:35 AM
Kim Wuyts
Compliance is overrated

9:40 AM - 10:10 AM
Cassey Crossley
Accountability in Application Development
10:15 AM - 10:45 AM
Akira Brand
Mycelium as the Path: How the Fungi Kingdom Guides us Toward Resilience in Our Cyber Programs
10:50 AM - 11:20 AM
Chris Romeo
Why the 'Secure by Design' pledge won't save us from AppSec failures
11:25 AM - 11:55 AM
Dustin Lehr
Building a Proactive Developer Security Culture - Can We Actually Make it Work?
12:00 PM - 12:25 PM
Jacob Salassi
Shift left sucks for SWEs: AppSec is a structured data problem
1:05 PM - 1:35 PM
Mel Reyes, Ariel Shin, and Alina Yakubenko
The Challenge of Scaling AppSec: Why It's Harder Than You Think
1:40 PM - 2:10 PM
Aravind Sreenivasa
My mistakes in building an AppSec team
2:15 PM - 2:45 PM
Track 2 - Focus on AppSec Tools
This track is perfect for those who want to hear speakers' specific takes on different AppSec tooling.
You can expect roasts of tools’ features, examples of nonsensical marketing, and of course, several mentions of how XYZ is dead.
James Berthoty

A future of Security free from CNAPP
9:05 AM - 9:35 AM
Sandesh Mysore Anand, Antoine Carossio, and Amit Bismut
Can we actually measure the effectiveness of AI in cybersecurity?
9:40 AM - 10:10 AM
Ron Nissim

Is PAM Dead?! Long live Just-in-time Access!
10:15 AM - 10:45 AM
Swan Beaujard
DAST is dead, or is it?

10:50 AM - 11:20 AM
Tristan Kalos
We have been doing API security wrong

11:25 AM - 11:55 AM
Jeevan Singh
Most Security Tools are expensive paperweights: How to get your money’s worth
12:30 PM - 1:00 PM
Kyle Kelly
The Dumpster Fire of Software Supply Chain Security
1:05 PM - 1:35 PM
Munawar Hafiz
Our SAST Tools Have Failed Us
1:40 PM - 2:10 PM
Anmol Agarwal
AI in AppSec: Why We Need To Prioritize Security
2:15 PM - 2:45 PM