Skip to content

Details

Building a Viable AppSec Program
Join us as we speak with a panel of CISOs about how they go about ensuring that application security is being done properly at their organizations. This entails finding the right Information Security staff who have the right set of skills and experience to interface with the development team as well as knowledge of security testing methodologies and tools.

Our panelists will also discuss the steps they have taken to ensure a build out of a robust Secure SDLC.

Moderator: Richard Greenberg, former CISO & OWASP LA Chapter Leader
Panelists:
Brett Cumming, Sr. Director, Information Security at Skechers
Awwab Arif, SVP, CISO at East West Bank
Mikhael Felker, Head of Product Security, Verily Life Sciences (subsidiary of Alphabet)

Brett Cumming is the senior leader responsible for Information Security at Skechers, a $6B+ athleisure brand with wholesale, retail, and ecommerce operations in more than 180 countries. As the Information Security Officer Brett runs a program that has global responsibility for cybersecurity operations, security architecture and engineering, digital security, privacy and compliance, and global security strategy. Mr. Cumming’s experience working in both business and engineering focused tech roles provides a broad perspective that allows him to design and implement an information security strategy that successfully bridges risk management practices and business priorities, while remaining effective and adaptable to the various unique regional and business unit requirements around the world. Having earned his B.S. in Business Administration (Management & Operations Management) from CSULB, Mr. Cumming also holds a number of professional certifications including CISSP, CISM, and 5x GIAC, in addition to being an active participant with the RH-ISAC, a governing body member of the Evanta SoCal CISO community, and a SANS Advisory Board member.

Awwab Arif has more than 20 years of experience in Information Technology, Information Security, IT risk, compliance and a proven track record in establishing and managing of an Information Security program aligned to overall organizational strategic goals and risk appetite. Expertise in the establishing of Information Security policies, procedures, management reporting, and an array of Internal Controls with a demonstrable efficacy towards managing risks and meeting audit, vendor risk and regulatory obligations.

Mikhael Felker has over 15 years of security, privacy, risk and compliance experience working at both startups and several Fortune 500 companies. Felker received his M.S. in information security policy and management from Carnegie Mellon University and B.S. in computer science from UCLA. His written work of 50+ publications has been featured in Forbes, ACM, IEEE Security & Privacy, ISACA Journal, ISSA Journal, several case studies and a number of online magazines.

ATTENTION SPONSORS: YOUR NAME COULD BE HERE
Contact sponsorship.la@owasp.org

Related topics

Events in Santa Monica, CA
Computer Security
OWASP
Web Security
Ethical Hacking
Software Development

Sponsors

OWASP - LA

OWASP - LA

sponsorship.la@owasp.org

Kodem

Kodem

Helping AppSec Teams Make Security a Priority

Semgrep

Semgrep

Protect your code with secure guardrails

Fastly

Fastly

Create fast, secure, and scalable sites and apps

You may also like