Uploaded December 2025 | Updated September 2026, 2 weeks ago
Presentation slides: static.sched.com/hosted_files/owaspglobalappsecusa2025/ae/%5BOWASP%20DC%5D%20Developer-Centric%20Threat%20Modeling_%20Embedding%20Security%20in%20Agile%20Workflows.pdf
Threat modeling remains essential yet challenging within agile teams due to rapid iteration cycles and frequent releases. Building on the previously introduced Rapid Developer-Driven Threat Modeling (RaD-TM) methodology, this session explores practical strategies for embedding RaD-TM seamlessly into agile workflows. RaD-TM explicitly puts developers in the driving seat, empowering them to proactively manage security risks. Participants will gain insights through real-world examples demonstrating how agile development teams successfully integrate and scale RaD-TM, leveraging predefined Risk Templates to facilitate continuous threat identification and mitigation without significant disruption.
Andrea Scaduto
Secure coding, threat modeling, and ethical hacking
London, UK
With a strong foundation in cybersecurity, Andrea holds an MSc in Computer Engineering, multiple IT Security certifications, and more than a decade of industry experience. His expertise spans breaking, building, and securing web, mobile, and cloud applications, with extensive knowledge of secure coding techniques aimed at reducing the cost of fixing vulnerabilities at scale.
Alan Pestrin
Thomson Reuters
Lead Product Security Engineer
Product security expert with background in medical devices, intellectual property protection and applied cryptography. Currently responsible for establishing and improving product security processes and practices in Thomson Reuters.
Managed by the OWASP® Foundation
owasp.org
Presentation slides: static.sched.com/hosted_files/owaspglobalappsecusa2025/ae/%5BOWASP%20DC%5D%20Developer-Centric%20Threat%20Modeling_%20Embedding%20Security%20in%20Agile%20Workflows.pdf
Threat modeling remains essential yet challenging within agile teams due to rapid iteration cycles and frequent releases. Building on the previously introduced Rapid Developer-Driven Threat Modeling (RaD-TM) methodology, this session explores practical strategies for embedding RaD-TM seamlessly into agile workflows. RaD-TM explicitly puts developers in the driving seat, empowering them to proactively manage security risks. Participants will gain insights through real-world examples demonstrating how agile development teams successfully integrate and scale RaD-TM, leveraging predefined Risk Templates to facilitate continuous threat identification and mitigation without significant disruption.
Andrea Scaduto
Secure coding, threat modeling, and ethical hacking
London, UK
With a strong foundation in cybersecurity, Andrea holds an MSc in Computer Engineering, multiple IT Security certifications, and more than a decade of industry experience. His expertise spans breaking, building, and securing web, mobile, and cloud applications, with extensive knowledge of secure coding techniques aimed at reducing the cost of fixing vulnerabilities at scale.
Alan Pestrin
Thomson Reuters
Lead Product Security Engineer
Product security expert with background in medical devices, intellectual property protection and applied cryptography. Currently responsible for establishing and improving product security processes and practices in Thomson Reuters.
Managed by the OWASP® Foundation
owasp.org










