Uploaded December 2025 | Updated September 2026, 2 weeks ago
Agenda for the OWASP DefectDojo project showcase:
I. Introduction to OWASP DefectDojo
A. What is DefectDojo?
1. Open-source vulnerability management tool
2. Designed to streamline security testing and vulnerability tracking
B. Why is it important?
1. Improves application security posture
2. Accelerates remediation efforts
3. Provides clearer understanding of overall security landscape
II. Key Features of DefectDojo
A. Aggregation of Security Findings
1. Supports various scanning tools (SAST, DAST, SCA, etc.)
2. Centralized repository for vulnerabilities
B. Collaboration Facilitation
1. Bridges development and security teams
2. Workflow management for remediation
C. Comprehensive Reporting
1. Risk assessment
2. Compliance reporting
3. Customizable dashboards
III. Benefits and Use Cases
A. Enhanced Vulnerability Management
1. Prioritization of critical vulnerabilities
2. Tracking of remediation progress
B. Improved Security Posture
1. Proactive identification of security flaws
2. Reduced attack surface
C. Real-world applications
1. Integrating into CI/CD pipelines
2. Managing bug bounty programs
IV. Live Demonstration (Optional, but Recommended)
A. Basic workflow: importing findings, creating engagements, tracking vulnerabilities
B. Example of a comprehensive report
V. Conclusion
A. Recap of DefectDojo's value proposition
B. Q&A session
C. Resources for further learning
Matt Tesauro
Defect Dojo
Distinguished Engineer, Founder and AppSec guru
Texas
defectdojo.com/blog
Matt Tesauro is a DevSecOps and AppSec guru with specialization in creating security programs, leveraging automation to maximize team velocity and training emerging and senior professionals. When not writing automation code in Go, Matt is pushing for DevSecOps everywhere via his involvement in open-source projects, presentations, trainings and new technology innovation. _x000D_
_x000D_
As a versatile engineer, Matt’s background spans software development (primarily web development), Linux system administration, penetration testing and application / cloud security. He thrives on tackling technical problems, but his economics background gives him a unique understanding of business constraints and incentives around security initiatives._x000D_
_x000D_
Currently, as a Distinguished Engineer at Noname Security, Matt is evangelizing Noname’s ground-breaking API security platform and API security in general. Previously, he rolled out AppSec automation at USAA and founded 10Security. Early in his career, Matt served as Director of Community and Operations at the OWASP Foundation, Senior AppSec Engineer at Duo Security, Senior Software Security Engineer at Pearson and Senior Product Security Engineer at Rackspace._x000D_
Tracy Walker
DefectDojo
Principal Solution Architect
linkedin.com/in/tracyfwalker
Tracy Walker is a 30-year veteran in Information Technology, go-lives, point-of-no-returns and hot-fixes. As a principal solutions architect for DefectDojo, Walker is passionate to help any I.T. environment improve security using open source and enterprise security tools.
Managed by the OWASP® Foundation
owasp.org
Agenda for the OWASP DefectDojo project showcase:
I. Introduction to OWASP DefectDojo
A. What is DefectDojo?
1. Open-source vulnerability management tool
2. Designed to streamline security testing and vulnerability tracking
B. Why is it important?
1. Improves application security posture
2. Accelerates remediation efforts
3. Provides clearer understanding of overall security landscape
II. Key Features of DefectDojo
A. Aggregation of Security Findings
1. Supports various scanning tools (SAST, DAST, SCA, etc.)
2. Centralized repository for vulnerabilities
B. Collaboration Facilitation
1. Bridges development and security teams
2. Workflow management for remediation
C. Comprehensive Reporting
1. Risk assessment
2. Compliance reporting
3. Customizable dashboards
III. Benefits and Use Cases
A. Enhanced Vulnerability Management
1. Prioritization of critical vulnerabilities
2. Tracking of remediation progress
B. Improved Security Posture
1. Proactive identification of security flaws
2. Reduced attack surface
C. Real-world applications
1. Integrating into CI/CD pipelines
2. Managing bug bounty programs
IV. Live Demonstration (Optional, but Recommended)
A. Basic workflow: importing findings, creating engagements, tracking vulnerabilities
B. Example of a comprehensive report
V. Conclusion
A. Recap of DefectDojo's value proposition
B. Q&A session
C. Resources for further learning
Matt Tesauro
Defect Dojo
Distinguished Engineer, Founder and AppSec guru
Texas
defectdojo.com/blog
Matt Tesauro is a DevSecOps and AppSec guru with specialization in creating security programs, leveraging automation to maximize team velocity and training emerging and senior professionals. When not writing automation code in Go, Matt is pushing for DevSecOps everywhere via his involvement in open-source projects, presentations, trainings and new technology innovation. _x000D_
_x000D_
As a versatile engineer, Matt’s background spans software development (primarily web development), Linux system administration, penetration testing and application / cloud security. He thrives on tackling technical problems, but his economics background gives him a unique understanding of business constraints and incentives around security initiatives._x000D_
_x000D_
Currently, as a Distinguished Engineer at Noname Security, Matt is evangelizing Noname’s ground-breaking API security platform and API security in general. Previously, he rolled out AppSec automation at USAA and founded 10Security. Early in his career, Matt served as Director of Community and Operations at the OWASP Foundation, Senior AppSec Engineer at Duo Security, Senior Software Security Engineer at Pearson and Senior Product Security Engineer at Rackspace._x000D_
Tracy Walker
DefectDojo
Principal Solution Architect
linkedin.com/in/tracyfwalker
Tracy Walker is a 30-year veteran in Information Technology, go-lives, point-of-no-returns and hot-fixes. As a principal solutions architect for DefectDojo, Walker is passionate to help any I.T. environment improve security using open source and enterprise security tools.
Managed by the OWASP® Foundation
owasp.org










