Mackenzie
Want to build secure applications without co-sponsoring a Formula 1 team? The modern threat landscape is a mess of AI-generated vulnerabilities, supply chain poisoning, and cloud misconfigurations. You don't need a seven-figure vendor budget to fight it.
In this 2-hour hands-on workshop, we will build a complete, automated AppSec pipeline using entirely open-source tools. We will wire up Opengrep for SAST, Trivy for containers, Checkov for infrastructure, and ZAP for DAST - piping the chaos into DefectDojo for centralized vulnerability management. We will also explore how to use local AI models to triage the inevitable mountain of false positives. You will walk away with a functional pipeline and a realistic understanding of where open-source excels, and where it falls apart.
Mackenzie
Developer and security advocate
Mackenzie is a developer advocate with a passion for DevOps and code security. As the co-founder and former CTO of a health tech startup, he learnt first-hand how critical it is to build secure applications with robust developer operations. Today as the Developer Advocate at GitGuardian, Mackenzie is able to share his passion for code security with developers and works closely with research teams to show how malicious actors discover and exploit vulnerabilities in code.