Loading…
Registration is NOW Open
Marriott Wardman Park
2660 Woodley Rd NW
Washington DC, District of Columbia 20008 USA
Phone: 1-202-328-2000 

Book Now 
*discount rates expire August 19, 2019
Salon 2 [clear filter]
Thursday, September 12
 

8:45am EDT

Opening Remarks
Thursday September 12, 2019 8:45am - 9:00am EDT
Salon 2

9:00am EDT

Applying Security Engineering Principles to Complex Composite Systems
Modern web applications and systems have grown increasing complex in the 18 years since OWASP was founded. Today's systems are composed from many diverse components, employ a wide variety of frameworks and toolkits, and utilize a vast spectrum of hosting models and external services.  Secure design and operation for such composite systems requires thoughtful application security engineering principles, attention to interactions among composite system elements, and awareness of dependencies across the system lifecycle. This talk will cover a selection of high-level principles, and illustrate them with reference to a Smart City transit system example.

Speakers
avatar for Neal Ziring

Neal Ziring

Technical Director for the National Security Agency’s Capabilities Directorate, NSA
Mr. Neal Ziring is the Technical Director for the National Security Agency’s Capabilities Directorate, serving as a technical advisor to the Capabilities Director, Deputy Director, and other senior leadership. Mr. Ziring is responsible for setting the technical direction across... Read More →


Thursday September 12, 2019 9:00am - 10:00am EDT
Salon 2

2:00pm EDT

Making a Change, One at a time - Diversity: More than just Gender
There has been a lot of conversations around diversity and inclusion in the recent past.  This is a step in a positive direction. The benefits of diversity in cybersecurity are clear. As an industry, we can do better, we need to do better. We need not only to keep the conversation going but to really place some action behind it. While homogenous teams feel easier to operate in, it can lead to stagnation, or specialisations in some aspects at the expense of others.

In this talk, I will present some of my thoughts on the importance and benefits of diversity and inclusion in our industry. I will share some of my experiences working over the last few years towards diversity initiatives, some real change observed, challenges associated with it and small steps anyone can do to improve diversity.

Speakers
avatar for Vandana Verma

Vandana Verma

Security Solutions Architect, IBM
Vandana is a seasoned security professional with experience ranging from application security to infrastructure and now dealing with DevSecOps. She has been Keynote speaker / Speaker / Trainer at various public events ranging from Global OWASP AppSec events to BlackHat events to regional... Read More →


Thursday September 12, 2019 2:00pm - 3:00pm EDT
Salon 2
 
Friday, September 13
 

9:00am EDT

Talent matters. You matter.
The internet wasn’t built with security in mind, the world has a massive talent shortage, and we can’t rely on automation to solve everything.

If you’re on an application security team, I’m willing to bet you have more to do than time and resources to do it. Maybe one of your colleagues left for a new job last month, and there are two additional unfilled positions on your team. You could actually be in a position where you’re trying to do the jobs of 4 people.

Talent matters. You matter.

This talk is about preventing and addressing burnout for overworked application security professionals. It’s also about how to attract, retain, and grow a great team.

Speakers
avatar for Caroline Wong

Caroline Wong

Caroline’s close and practical information security knowledge stems from broad experience as a Cigitalconsultant, a Symantec product manager, and day-to-day leadership roles at eBay and Zynga.Caroline is an advisor for RSA Conference and ISC2 North America. She has been featured... Read More →


Friday September 13, 2019 9:00am - 10:00am EDT
Salon 2

2:00pm EDT

A DevSecOps Tale of Business, Engineering, and People
DevOps and the subsequent move to bring security in under the umbrella of DevSecOps has created a new ethos for security. This is good. But, when things go wrong–and we know they will–are we going to be successful with the DevSecOps model, or will we be left searching yet again?

In an attempt to answer this question, we will look back in time over 120 years to unveil a tale that touches on business, engineering, and resilience. We will see how engineering decisions affect the lives of those around us and even though the world has radically changed over the last century, we are still facing many of the same root challenges.

Along the way, we will highlight the high-performing DevSecOps teams of today and introduce a framework for approaching DevSecOps in your organization. Topics range from empathy to lean to system safety with the hope to frame a new playbook for devs, ops, and security to work together.



Speakers
avatar for James Wickett

James Wickett

Sr. Security Engineer and Developer Advocate, Verica
James is a dynamic speaker on software engineering topics ranging from security to development practices. He spends a lot of time at the intersection of the DevOps and Security communities, and seeing the gap in software testing, James founded the open source project, Gauntlt, to... Read More →


Friday September 13, 2019 2:00pm - 3:00pm EDT
Salon 2
 
Filter sessions
Apply filters to sessions.