-
AppSec & DevSecOps Melbourne
-
08:20
Register; grab a coffee. Mix, mingle and say hello to peers old and new.
-
09:00
Welcome from Corinium and the Chairperson
Tara Whitehead - Security Engineering Leader -
-
09:10
Speed Networking – Making new connections!
In this 5-minute networking session, the goal is to connect with three new people. Enjoy the opportunity to expand your network!
-
09:15
Headliner Debate
Shift Left vs AI: Who Owns the Future of AppSec?Security teams are split: should we embed security early in the SDLC or rely on AI to detect and fix vulnerabilities faster? This interactive debate explores the trade-offs, risks, and real-world impact. No easy answers, just insights to challenge how you secure modern delivery pipelines.
- Can AI replace secure coding practices, or is developer education irreplaceable?
- Are AI tools creating hidden risks, or do traditional processes slow innovation?
- How do you balance human judgement, automation, and team accountability in modern DevSecOps?
Facilitator:
Angelina Liu Account Executive Aikido
Speakers:
Kalpana Venkatesan Senior DevSecOps Engineer Kmart Australia
Thilina Senevirathna Technical Lead Cloud & Application Security Reece Group
Sara Gray Senior Product Security Manager Atlassian
-
09:50
Ransomware Readiness: What Every Organisation Needs to Know
Ransomware remains one of the most disruptive threats with attackers adapting faster than many defences. This session expliores practical strategies for prevention, early detection and effective response. Learn how to reduce impact, strengthen readiness and close the gaps that make organisations vulnerable to modern ransomware campaigns.
-
10:15
Panel discussion
Is AppSec Still Ignored in GRC?Application security is often mentioned in compliance frameworks, but does it actually get integrated into risk management processes? This panel examines the disconnect between GRC requirements and engineering reality, and how teams can close the gap.
- Why are AppSec risks still overlooked in many GRC frameworks?
- How can compliance obligations become actionable for developers without creating friction?
- What metrics or reporting approaches best link AppSec outcomes to business impact?
- Should GRC professionals and engineers collaborate differently to improve adoption and visibility?
Panellists:
Jugal Nayal Application Security Specialist Data Capture Experts
-
10:50
Automating Compliance at Cloud Speed: Lessons for CI/CD and DevSecOps
As software delivery accelerates, compliance can’t be an afterthought. This session explores how leading teams embed automated controls into CI/CD pipelines, translating governance into code. Learn practical approaches to scaling compliance across DevSecOps workflows—without slowing innovation or compromising security.
-
11:15
Get Refreshed! Mingle
-
11:55
When Security Slows Delivery: What Actually Breaks at Release Time
This session explores how security controls behave in live delivery environments. From blocked pipelines to last minute risk escalations, the release function often sees where DevSecOps design does not match operational reality. The speaker shares how controls were redesigned to reduce friction while improving risk clarity and release predictability.
-
12:20
Red Teaming with AI: Simulating Adversaries in Real Time
AI is transforming the way organisations approach offensive security. Rather than relying solely on periodic, human-led exercises, AI can simulate adversaries at scale and in real time, continuously probing for weaknesses that traditional methods may miss. This session will explore how AI is being applied to red teaming, the opportunities it creates for faster feedback within DevSecOps pipelines, and the safeguards required to ensure these simulations remain accurate, ethical, and effective.
-
12:45
Beyond STRIDE: Why MAESTRO is the New Baton for DevSecOps Threat Modelling
The static nature of traditional threat modeling approaches fail to capture the fluid attack surfaces of cloud-native ecosystems and AI-integrated workflows. This session introduces MAESTRO, a dynamic threat modeling framework designed for multi-agent systems, continuously evolving environments. Using real-world examples, it shows how to embed security into AI lifecycle and CI/CD pipelines addressing IAM complexity, misconfigurations, supply chain risks, and emergent threats - enabling DevSecOps teams to build resilient, adaptive, and secure AI systems by design.
Speakers:
Owais Khan Senior Cyber Security Architect EnergyAustralia
Rakesh Sharma Chief Advisor CYAIFI (Cyber & Artificial Intelligence for Future Impact)
-
13:10
Lunch
-
14:10
Panel Discussion
Breaking Boundaries: Securing APIs, Microservices, and SaaS Across TeamsThis panel explores how organisations manage security beyond the code they own. Panellists share how they maintain visibility, enforce standards and reduce risk across APIs, microservices and SaaS integrations.
- What blind spot in an API, SaaS, or dependency later turned into a security issue?
- Where have ownership gaps caused problems, and how did you fix them in practice?
- What security approach sounded good on paper but failed once teams had to move fast?
Panellists:
Luke Bampton Application Security Lead Monash University
Medha Mishra Lead Application Security Engineer Wrkr
Ibrahim Mohammed DevSecOps Design & Assurance Manager Insignia Financial
-
14:45
Securing Cloud, Compliance, and the Software Supply Chain
As cloud adoption accelerates, managing and securing digital assets is more critical than ever. This session explores strategies for ensuring robust security, maintaining compliance, and strengthening governance. We’ll also examine how software supply chain management plays a key role in mitigating vulnerabilities, providing a comprehensive approach to securing your organisation’s digital landscape.
-
15:10
AI in DevSecOps: Powering the Lifeblood Donate Blood App
Andrew Cunningham - Application Development Manager Australian Red Cross Lifeblood -
This session explores how AI/ML is being applied within DevSecOps pipelines supporting the Lifeblood Donate Blood app and the internal Lifeblood platforms behind it. We’ll focus on practical ways AI is being used to increase test coverage, enhance security, streamline delivery, and introduce smarter governance, along with insights from applying these approaches in a production environment.
- Leveraging AI to enhance security and pipeline efficiency
- Balancing automation with regulated governance in DevSecOps
- Insights from scaling AI across customer and internal platforms
-
15:50
Closing Keynote Presentation
Carrot vs Stick: What Actually Drives Secure Engineering Behaviour?Abdullah Muhammad - Application Defence Manager - Bupa
Security teams debate whether engineers respond better to incentives or enforcement. This session explores approaches for motivating secure coding practices in fast-moving DevSecOps teams.
- Do incentives work better than mandatory rules and policies to drive secure behaviour, or vice versa?
- Are there examples where culture alone improved security outcomes more than policies?
- How do metrics and recognition influence engineering decisions day-to-day?
-
16:00
Chairperson's Closing Remarks
-
16:10
Close of AppSec & DevSecOps Melbourne 2026 & Afternoon Tea
Not Found