Speakers
These industry leaders bring a wealth of knowledge and experience in Application Security, and we are excited to have them share their insights and spicy opinions with us.
Tanya Janca
Author Alice & Bob Learn Secure Coding & Application Security, Secure Coding Trainer @ She Hacks Purple
Speaker bio
Marisa Fagan
Head of Product, Katilyst, OWASP 2026 Global Board Member
Speaker bio
Izar Tarandach
Sr. Principal Security Architect,
Co-author "Threat Modeling: A Practical Guide for Development Teams"
Speaker bio
Kennedy Toomey
Application Security Researcher & Advocate at Datadog
Speaker bio
Jackie Mak
Director, Cyber Threat Management, KPMG US
Speaker bio
Dustin Lehr
Application Security Advocate @ Security Journey
Speaker bio
Alina Yakubenko
Staff Product Security Engineer, Tech Lead Manager @ Toast, Inc.
Speaker bio
Mohamed AboElKheir
Sr. Staff Application Security Engineer, Ironclad
Speaker bio
Ariel Shin
Senior Security Engineer, Stripe

Speaker bio
Sana Talwar‍
Product Security Engineer @ ServiceNow
Speaker bio
Antoine Carossio
Co-Founder and CTO @ Escape
Speaker bio
Enrique Larios Vargas
Security and Learning Specialist, Adyen
Speaker bio
Jyoti Raval
Director, Cyber Security Engineering with Baker Hughes
Speaker bio
Nohé Hinniger-Foray
R&D Engineer @ Escape
Speaker bio
Alekh Gadekar
Senior Application Security Manager, Backbase
Speaker bio
Maxwell Zhou
Founding partner at PolarStar Cybersecurity Group
Speaker bio
Day 1
Explore what’s broken in AppSec and how to fix it.
This day is full of bold insights and spicy takes that challenge the status quo.
Tanya Janca
K‍eynote: Crushed by the Backlog: The DevSecOps Problem No One Wants to Admit
8:30 AM - 9:00 AM
Abstract
Panel:
Enrique Larios Vargas, Alina Yakubenko,
Alekh Gadekar
Beyond the "Champions": Is security culture the new must-have for organizations?
9:05 AM - 09:45 AM
Abstract
Antoine Carossio
Will 2026 be the end of manual pentesting? Time to find out
10:00 AM - 10:30 AM
Abstract
Sana Talwar
Why Third-Party Reviews are broken (and how to fix them)
10:35 AM - 11:05 AM
Abstract
Jackie Mak
The Secure SDLC Maturity Model: A Consultant's Guide to Faking It 'Til You Make It
11:05 AM - 11:35 AM
Abstract
Dustin Lehr
AI Is Table Stakes. People Are Still the Variables.
11:40 PM - 12:10 PM
Abstract
Day 2
This day is perfect for those who want to hear speakers' specific takes on all things AI and all the messy, unspoken realities of vulnerability management and the "shift-left" movement
Izar Tarandach
What is old is new again: are AI threats that novel?‍
8:00 AM - 8:30 AM
Abstract
Panel:
Ariel Shin,
Jyoti Raval,
Maxwell Zhou
Human-assisted vs AI-powered AppSec - where do we draw the line?
8:30 AM - 09:10 AM
Abstract
Nohé Hinniger-Foray
What does it really mean to build with "vibes"?
09:15 AM - 09:45 AM
Abstract
Kennedy Toomey
Shift Left Meets Shift Right: The Security Paradox


10:00 AM - 10:30 AM
Abstract
Mohamed AboElKheir
Are AI Agents the Ultimate Confused Deputy? How AI Agents' Capabilities Are Being Abused
10:35 AM - 11:05 AM
Abstract
Marisa Fagan
The Elephant in Vulnerability Management
11:05 PM - 11:40 PM
Abstract