Uploaded December 2025 | Updated September 2026, 2 weeks ago
Creating an effective application security culture is less about enforcing rules and more about enabling engineering teams to ship secure code without friction. This session explores how we introduced a lightweight AppSec culture into a growing DevOps environment—without slowing developers down. You'll learn how we aligned AppSec practices with developer workflows, moved away from security gatekeeping, and communicated risk in a way that made business sense to leadership. We’ll share lessons learned from both successes and missteps, including how we balanced automation with empathy, supported adoption without authority, and got buy-in from skeptics. If you’re building an AppSec program or looking to reboot your existing one, this talk will give you practical, immediately applicable takeaways.
Khaja Moinuddin Shaik
Autodesk
Principal DevSecOps Engineer
Principal DevSecOps Engineer focused on integrating security into CI/CD, automating AppSec tooling, and fostering developer-friendly security culture. Passionate about scalable solutions and bridging gaps between engineering and security.
Managed by the OWASP® Foundation
owasp.org
Creating an effective application security culture is less about enforcing rules and more about enabling engineering teams to ship secure code without friction. This session explores how we introduced a lightweight AppSec culture into a growing DevOps environment—without slowing developers down. You'll learn how we aligned AppSec practices with developer workflows, moved away from security gatekeeping, and communicated risk in a way that made business sense to leadership. We’ll share lessons learned from both successes and missteps, including how we balanced automation with empathy, supported adoption without authority, and got buy-in from skeptics. If you’re building an AppSec program or looking to reboot your existing one, this talk will give you practical, immediately applicable takeaways.
Khaja Moinuddin Shaik
Autodesk
Principal DevSecOps Engineer
Principal DevSecOps Engineer focused on integrating security into CI/CD, automating AppSec tooling, and fostering developer-friendly security culture. Passionate about scalable solutions and bridging gaps between engineering and security.
Managed by the OWASP® Foundation
owasp.org










