-
AppSec & DevSecOps Melbourne
-
08:20
Register; grab a coffee. Mix, mingle and say hello to peers old and new.
-
09:00
Welcome from Corinium and the Chairperson
Tara Whitehead - Senior Manager Security Engineering Education - CommBank
-
09:10
Speed Networking – Making new connections!
In this 5-minute networking session, the goal is to connect with three new people. Enjoy the opportunity to expand your network!
-
09:15
Headliner Debate
Shift Left vs AI: Who Owns the Future of AppSec?Security teams are split: should we embed security early in the SDLC or rely on AI to detect and fix vulnerabilities faster? This interactive debate explores the trade-offs, risks, and real-world impact. No easy answers, just insights to challenge how you secure modern delivery pipelines.
- Can AI replace secure coding practices, or is developer education irreplaceable?
- Are AI tools creating hidden risks, or do traditional processes slow innovation?
- How do you balance human judgement, automation, and team accountability in modern DevSecOps?
Facilitator:
Angelina Liu Account Executive Aikido
Speakers:
Kalpana Venkatesan Senior DevSecOps Engineer Kmart Australia
Dilip Konar Former Application Service & Engineering Manager ex-Australia Post
Matt Kellock Group DevSecOps Lead Deel
Ibrahim Mohammed DevSecOps Design & Assurance Manager Insignia Financia -
09:50
The AI Challenge You Don't Yet Know About - Software Supply Chain
Clarence Cheah - Regional Director ANZ - Chainguard
In an era where AI is accelerating software development, organisations must also contend with evolving software supply chain risks. Drawing on Chainguard's research and observed industry patterns, this session explores how these compromises occur - without the hype. Attendees will gain practical strategies to improve software integrity, secure their development pipelines, and build confidence in the software they deliver.
-
10:15
Panel discussion
Is AppSec Still Ignored in GRC?Application security is often mentioned in compliance frameworks, but does it actually get integrated into risk management processes? This panel examines the disconnect between GRC requirements and engineering reality, and how teams can close the gap.
- Why are AppSec risks still overlooked in many GRC frameworks?
- How can compliance obligations become actionable for developers without creating friction?
- What metrics or reporting approaches best link AppSec outcomes to business impact?
- Should GRC professionals and engineers collaborate differently to improve adoption and visibility?
Moderator:
Tara Whitehead Senior Manager Security Engineering Education CommBank
Panellists:
Jugal Nayal Application Security Specialist Data Capture Experts
Andy Hsu Senior Application Security Engineer Flexera
Priyank Sharma Application Security Engineer Lead, ANZ Black Duck
-
10:50
Pentesting in the Age of AI: Evolution or Extinction
Angelina Liu - Account Executive - Aikido
Penetration testing is at a crossroads. In an era of AI agents and automation, some argue it’s becoming obsolete, others insist it’s more essential than ever. Can agentic AI agents truly rival the creativity and intuition of human hackers, or will AI simply accelerate routine tasks?
-
11:15
Get Refreshed! Mingle
-
11:55
AI in DevSecOps: Powering the Lifeblood Donate Blood App
Andrew Cunningham - Application Development Manager - Australian Red Cross Lifeblood
This session explores how AI/ML is being applied within DevSecOps pipelines supporting the Lifeblood Donate Blood app and the internal Lifeblood platforms behind it. We’ll focus on practical ways AI is being used to increase test coverage, enhance security, streamline delivery, and introduce smarter governance, along with insights from applying these approaches in a production environment.
- Leveraging AI to enhance security and pipeline efficiency
- Balancing automation with regulated governance in DevSecOps
- Insights from scaling AI across customer and internal platforms
-
12:20
AppSec is Dead? Why Frontier Models Demand Evolution, Not Replacement.
Nir Weinberg - Senior Solutions Engineer - Snyk
Large language models (LLMs) are changing vulnerability detection, but operationalizing this capability is challenging due to non-determinism, cost, and scaling issues. This session argues that AppSec is not dead; it must evolve to integrate frontier models like Mythos while reinforcing crucial foundational security basics. Learn how human-centric AppSec complements AI, rather than being replaced by it.
-
12:45
What DevSecOps Teams Must Do Now for the Post-Quantum Transition
Roma Singh - Portfolio Security Advisor - Department of Transport and Planning
This session explores quantum readiness and crypto agility in modern systems. Discovering how cryptography is embedded across applications, APIs, identity, and infrastructure, and what organisations must consider as standards evolve. The focus is on improving visibility and preparing DevSecOps and AppSec teams for future cryptographic transitions, ensuring systems can adapt and remain resilient as change accelerates.
-
13:10
Lunch
-
14:10
Panel Discussion
Breaking Boundaries: Securing APIs, Microservices, and SaaS Across TeamsThis panel explores how organisations manage security beyond the code they own. Panellists share how they maintain visibility, enforce standards and reduce risk across APIs, microservices and SaaS integrations.
- What blind spot in an API, SaaS, or dependency later turned into a security issue?
- Where have ownership gaps caused problems, and how did you fix them in practice?
- What security approach sounded good on paper but failed once teams had to move fast?
Moderator:
Andrew Bandeira Security Architecture, Strategy & Advisory Lead Australian Payments PlusPanellists:
Luke Bampton Application Security Lead Monash University
Medha Mishra Lead Application Security Engineer Wrkr
Ibrahim Mohammed DevSecOps Design & Assurance Manager Insignia Financial
-
14:45
Locking the Vault: Real-Time Mobile Threat Defense for Modern Apps
Jason Salway - Sales Engineering Manager, Asia Pacific - Zimperium
Your mobile app is the modern bank vault, but it runs unprotected beyond your firewall. If that vault is compromised, user trust is impacted. This session explores how to secure apps where they are most vulnerable: at runtime. Discover how embedding real-time Mobile Application Protection into your DevSecOps pipeline provides total threat visibility. Walk away with actionable strategies to block tampering, stop reverse-engineering, and ensure your apps actively defend themselves in the wild.
-
15:10
Closing Keynote Presentation
Carrot vs Stick: What Actually Drives Secure Engineering Behaviour?Abdullah Muhammad - Application Defence Manager - Bupa
Security teams debate whether engineers respond better to incentives or enforcement. This session explores approaches for motivating secure coding practices in fast-moving DevSecOps teams.
- Do incentives work better than mandatory rules and policies to drive secure behaviour, or vice versa?
- Are there examples where culture alone improved security outcomes more than policies?
- How do metrics and recognition influence engineering decisions day-to-day?
-
15:35
Chairperson's Closing Remarks
Tara Whitehead - Senior Manager Security Engineering Education - CommBank
-
15:45
Close of AppSec & DevSecOps Melbourne 2026 & Afternoon Tea
Not Found