DevSecOps Virtual Conference logo
Event Ran Live

Wednesday, September 25, 2024

8:30 AM to 12 PM EST

Click the Icon Below for Presenter Lineup &
Video Replay Links Per Session...

Session Agenda

*Presenter Lineup Subject to Change

8:30 - 8:35 AM ET

Opening Statements

Speaker:
Dan Wakeman

Dan
Wakeman

8:35 - 9:15 AM ET

Executive Round Table​

Speakers:
Chris Gushue

Chris
Gushue

Randy Guy

Randy
Guy

Brian Heemsoth

Brian
Heemsoth

Satvik Sharma

Satvik
Sharma

9:15 - 9:45 AM ET

API Security

This presentation will start with top risks APIs are vulnerable to and recent security incidents caused by API vulnerabilities. A walkthrough of FIS new API security program initiative and capabilities this program will be built upon to protect the FIS APIs followed by demo of API exploitation.

Speaker:
Ajay Gupta

Ajay
Gupta

9:45 - 10:15 AM ET

API Exploit Demo

This presentation will cover API exploitation, specifically 2 examples of API exploitation which cover abusing an API that is vulnerable to broken auth leading to exposure of PII. It will also demonstrate username harvesting. Beyond exploitation of API, expect an overview of tools leveraged to exploit and discover APIs, in addition to tactics used by threat actors to discover APIs. Lastly, this presentation will cover stats around how exploitation of APIs has affected FIS directly.

Speaker:
Emily Larson

Emily
Larson

10:15 - 10:45 AM ET

Automating Quality Gates

Automating quality gates through the adoption of Policy-as-Code will provide a capability for FIS to enforce Policy, Controls and Guardrails in the SDLC that is integrated into our target CI/CD Delivery Platform so we can achieve our North Star of Continuous Production Deployment. We will discuss how this capability supports our strategic goal to deliver quality products faster.

Speaker:
Cristian Mihalcea

Cristian
Mihalcea

10:45 - 11:15 AM ET

CI/CD Pipeline Case Study

Providing an end-to-end pipeline demo starts from code commit to UAT deployment, integrating various security and test tools, as well as automating JIRA and SNOW ticket creation. Harness SEI captures DORA metrics for continuous improvement, and feature flags enable or disable features without redeploying.

Speaker:
Karthik Sadasivam

Karthik
Sadasivam

11:15 - 11:45 AM ET

Harness AIDA Product Offering

A walk-through of Harness AI Developer Assistant (AIDA) and opportunities to reduce effort in areas such as Pipeline Error Analysis, Continuous Verification, Policy as Code Authoring, and Generating Reports.

Speakers:
Ulan Bekishov

Ulan
Bekishov
(Harness)

11:45 AM - 12 PM ET

Call to Action/Closing Statements​

Speakers:
Matthew Hein

Matthew
Hein

Robert Woods

Dan
Wakeman

Shannon Wallace

Shannon
Wallace