Uploaded August 2025 | Updated September 2026, 1 week ago
Security isn’t just the job of specialists – it’s every developer’s responsibility. While security expertise is critical, it doesn’t have to be exclusive.
In this talk, Nisal Wickramage, Thoughtworks Developer, explores how developers can use generative AI as a sidekick to better understand, model, and address security risks from the very start of a project. You’ll see how prompt engineering, GenAI tools, and emerging specialized AI assistants can bring security knowledge directly into developer workflows.
You’ll learn how to:
Step confidently into the role of Security Champion and defend what you build
Use shift-left practices to embed security earlier in development
Apply GenAI for threat modeling and prompt-driven analysis
Leverage prompt templates to scale security knowledge across teams
Provide the right context to improve GenAI’s reliability
Refine prompts for clearer, actionable security insights
By the end, you’ll understand how to pair developer intuition with GenAI tools to write more secure software—without needing to be a security guru.
Chapters
00:00 – Introduction: background and concerns on how to start
01:31 – Exploring GenAI as a sidekick for developers
03:12 – The Security Champion's role and challenges
04:52 – Amplifying shift-left practices with AI
06:58 – Effective context-setting for GenAI outputs
10:23 – Utilizing prompt templates for security reasoning
12:02 – Importance of scaling security knowledge across teams
13:44 – Demonstration of Gen AI in threat modeling: prompting, better context, and templates
25:04 – Conclusion and key takeaways
Follow Thoughtworks on YouTube for more insights and talks on AI, security, and the future of software engineering.
thoughtworks.com
Security isn’t just the job of specialists – it’s every developer’s responsibility. While security expertise is critical, it doesn’t have to be exclusive.
In this talk, Nisal Wickramage, Thoughtworks Developer, explores how developers can use generative AI as a sidekick to better understand, model, and address security risks from the very start of a project. You’ll see how prompt engineering, GenAI tools, and emerging specialized AI assistants can bring security knowledge directly into developer workflows.
You’ll learn how to:
Step confidently into the role of Security Champion and defend what you build
Use shift-left practices to embed security earlier in development
Apply GenAI for threat modeling and prompt-driven analysis
Leverage prompt templates to scale security knowledge across teams
Provide the right context to improve GenAI’s reliability
Refine prompts for clearer, actionable security insights
By the end, you’ll understand how to pair developer intuition with GenAI tools to write more secure software—without needing to be a security guru.
Chapters
00:00 – Introduction: background and concerns on how to start
01:31 – Exploring GenAI as a sidekick for developers
03:12 – The Security Champion's role and challenges
04:52 – Amplifying shift-left practices with AI
06:58 – Effective context-setting for GenAI outputs
10:23 – Utilizing prompt templates for security reasoning
12:02 – Importance of scaling security knowledge across teams
13:44 – Demonstration of Gen AI in threat modeling: prompting, better context, and templates
25:04 – Conclusion and key takeaways
Follow Thoughtworks on YouTube for more insights and talks on AI, security, and the future of software engineering.
thoughtworks.com










