Skip to content

Details

The OWASP Boulder Chapter is excited to a double header presentation on Sep 22!

Make Insecure Code Hard to Write: The IDE Guardrails Playbook
with Joe Wilson

Most application security feedback arrives too late, after code is written, committed, and already headed toward production. This creates rework, delays, and recurring vulnerability patterns. In this talk, Joe will share a practical playbook for making insecure code hard to write and commit by delivering security guidance directly inside the IDE, where developers make decisions in real time. We’ll cover what “IDE guardrails” look like in practice, including secure-by-default suggestions, low-noise rules, secrets exposure prevention, and fast feedback loops that reinforce safer coding habits. He’ll also show a simple reference workflow using tools like SonarQube and BlueFlag Security as real-world examples, without turning the session into a product demo. Attendees will leave with a prioritized rollout plan they can implement within their own workflow and teams.

Raid Parties for Red Teams
with Jeremy Banker

Offensive security tooling was built for one person at one keyboard. Real engagements involve whole teams, and increasingly, autonomous agents working alongside them. Drawing on real platforms built at Horizon3, this talk looks at what happens when you apply platform engineering to traditionally solo offensive tasks like hash cracking or AWS enumeration, and asks a simple question about any tool you run: could a teammate use it next to you, and could an agent use it without you? If not, it might be quietly siloing knowledge and resources your whole team could be sharing.

Special thanks to the Rule4 Team for hosting!

AGENDA
6:00 - 6:30 Food, Drinks, Networking
6:30 - 7:00ish Make Insecure Code Hard to Write
7:00ish - 7:30 Raid Parties for Red Teams
7:30 - 8:00 More Networking

You can also get announcements from:
LinkedIn: https://www.linkedin.com/company/owasp-boulder

Related topics

Events in Boulder, CO
Computer Security
Software Security
Information Security
Professional Networking
Software Development

You may also like