Developer-Centric Threat Modeling: Embedding Security in Agile Workflows @OWASPGLOBAL
Developer-Centric Threat Modeling: Embedding Security in Agile Workflows  @OWASPGLOBAL
Uploaded December 2025 | Updated September 2026, 2 weeks ago
Presentation slides: static.sched.com/hosted_files/owaspglobalappsecusa2025/ae/%5BOWASP%20DC%5D%20Developer-Centric%20Threat%20Modeling_%20Embedding%20Security%20in%20Agile%20Workflows.pdf

Threat modeling remains essential yet challenging within agile teams due to rapid iteration cycles and frequent releases. Building on the previously introduced Rapid Developer-Driven Threat Modeling (RaD-TM) methodology, this session explores practical strategies for embedding RaD-TM seamlessly into agile workflows. RaD-TM explicitly puts developers in the driving seat, empowering them to proactively manage security risks. Participants will gain insights through real-world examples demonstrating how agile development teams successfully integrate and scale RaD-TM, leveraging predefined Risk Templates to facilitate continuous threat identification and mitigation without significant disruption.

Andrea Scaduto
Secure coding, threat modeling, and ethical hacking
London, UK

With a strong foundation in cybersecurity, Andrea holds an MSc in Computer Engineering, multiple IT Security certifications, and more than a decade of industry experience. His expertise spans breaking, building, and securing web, mobile, and cloud applications, with extensive knowledge of secure coding techniques aimed at reducing the cost of fixing vulnerabilities at scale.

Alan Pestrin
Thomson Reuters
Lead Product Security Engineer

Product security expert with background in medical devices, intellectual property protection and applied cryptography. Currently responsible for establishing and improving product security processes and practices in Thomson Reuters.

Managed by the OWASP® Foundation
owasp.org
Developer-Centric Threat Modeling: Embedding Security in Agile WorkflowsEscaping Vulnerability Hell: Bridging the Gap Between Developers and Security Teams - Ahmad SadeddinRethinking how we evaluate security agents for real-world use - Track 1Securing Access: Leveraging IGA, JIT & Policy Controls to Tackle OWASP ThreatsMaturing Your Application Security Program with ASVS-Driven Development - Aram HovsepyanEvolving Your Security Champions Program: Introducing the OWASP Security Champions Maturity ModelAI Code Generation - Benefits, Risks and Mitigation Controls - Aruneesh SalhotraThe OWASP Events Committee Presents Vienna 26Keynote: Thriving in the Age of AI - Aanchal GuptaHidden Chains: Revealing High-Impact Bugs from Bounty submissions - Vinay & MuraliOWASP Global Board of Directors Meeting - February 2025Under the Radar: How we found 0-days in the Build Pipeline of OSS Packages - François Proulx
OWASP Foundation |

Developer-Centric Threat Modeling: Embedding Security in Agile Workflows

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER