Beyond the Checklist: Building an AppSec Culture That Engineers Don’t Dread @OWASPGLOBAL
Beyond the Checklist: Building an AppSec Culture That Engineers Don’t Dread  @OWASPGLOBAL
Uploaded December 2025 | Updated September 2026, 2 weeks ago
Creating an effective application security culture is less about enforcing rules and more about enabling engineering teams to ship secure code without friction. This session explores how we introduced a lightweight AppSec culture into a growing DevOps environment—without slowing developers down. You'll learn how we aligned AppSec practices with developer workflows, moved away from security gatekeeping, and communicated risk in a way that made business sense to leadership. We’ll share lessons learned from both successes and missteps, including how we balanced automation with empathy, supported adoption without authority, and got buy-in from skeptics. If you’re building an AppSec program or looking to reboot your existing one, this talk will give you practical, immediately applicable takeaways.

Khaja Moinuddin Shaik
Autodesk
Principal DevSecOps Engineer

Principal DevSecOps Engineer focused on integrating security into CI/CD, automating AppSec tooling, and fostering developer-friendly security culture. Passionate about scalable solutions and bridging gaps between engineering and security.

Managed by the OWASP® Foundation
owasp.org
Beyond the Checklist: Building an AppSec Culture That Engineers Don’t DreadOWASP Software Assurance Maturity Model (SAMM) - Aram Hovsepyan, Sebastien DeleersnyderHow to Defend Your PKI Estate: Lessons Learned from Eight Years of CAA and Certificate TransparencyExhibitor : Over a Decade of Software Security  What Have We Learned -  Adam BrownOWASP Cornucopia Abuse Case ModelingExploitable In The Wild CVE Appears! But Should We Fix em All?OWASP Global Board of Directors - September 2025OWASP Global Board of Directors - October 2025Plugins Gone Rogue: Attacking Developer Environments202008 August 2020 Global Board MeetingFrom Logs to Defense: Building AI Enhanced XDR Pipelines for Application Level Threats track 1OWASP Global Board of Directors Meeting - July 2025
OWASP Foundation |

Beyond the Checklist: Building an AppSec Culture That Engineers Don’t Dread

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER