• HOME
    • SPEAKERS
      • REQUEST TO SPEAK
    • AGENDA
      • VIEW AGENDA
      • PDF AGENDA
    • PARTNERS
      • SPONSORSHIP
      • VIEW PARTNERS
    • REGISTER
    • CONTENT
    • VENUE
    • CONTACT
    • CO-EVENT
      • CISO MELBOURNE
      • OT SECURITY
      • CLOUD SECURITY
    • Menu Item 1
      • Sub-menu Item 1
        • Another Item
      • Sub-menu Item 2
    • Menu Item 2
      • Yet Another Item
    • Menu Item 3
    • Menu Item 4
RE•WORK | AppSec & DevSecOps Melbourne
Register  
    • HOME
    • SPEAKERS
      • REQUEST TO SPEAK
    • AGENDA
      • VIEW AGENDA
      • PDF AGENDA
    • PARTNERS
      • SPONSORSHIP
      • VIEW PARTNERS
    • REGISTER
    • CONTENT
    • VENUE
    • CONTACT
    • CO-EVENT
      • CISO MELBOURNE
      • OT SECURITY
      • CLOUD SECURITY

15 July 2026

AppSec & DevSecOps Melbourne schedule



Download PDF
  • AppSec & DevSecOps Melbourne 15 July
Get your ticket

    Not Found

  • AppSec & DevSecOps Melbourne

  • 08:20

    Register; grab a coffee. Mix, mingle and say hello to peers old and new.

    Arrow
  • 09:00
    Tara Whitehead

    Welcome from Corinium and the Chairperson

    Tara Whitehead - Senior Manager Security Engineering Education - CommBank

    Arrow
  • 09:10
    Connect _Network-1

    Speed Networking – Making new connections!

    Arrow

    In this 5-minute networking session, the goal is to connect with three new people. Enjoy the opportunity to expand your network! 

  • 09:15
    Interactive Discussion

    Headliner Debate
    Shift Left vs AI: Who Owns the Future of AppSec?

    Arrow

    Security teams are split: should we embed security early in the SDLC or rely on AI to detect and fix vulnerabilities faster? This interactive debate explores the trade-offs, risks, and real-world impact. No easy answers, just insights to challenge how you secure modern delivery pipelines.

    • Can AI replace secure coding practices, or is developer education irreplaceable?
    • Are AI tools creating hidden risks, or do traditional processes slow innovation?
    • How do you balance human judgement, automation, and team accountability in modern DevSecOps?

    Facilitator:

    Angelina Liu Account Executive Aikido

    Speakers:

    Kalpana Venkatesan Senior DevSecOps Engineer Kmart Australia

    Thilina Senevirathna Technical Lead Cloud & Application Security Reece Group

    Sara Gray Senior Product Security Manager Atlassian

    Dilip Konar Former Application Service & Engineering Manager ex-Australia Post 

  • 09:50
    Sponsor Presentation

    Ransomware Readiness: What Every Organisation Needs to Know

    Senior representative - - Chainguard

    Arrow

    Ransomware remains one of the most disruptive threats with attackers adapting faster than many defences. This session expliores practical strategies for prevention, early detection and effective response. Learn how to reduce impact, strengthen readiness and close the gaps that make organisations vulnerable to modern ransomware campaigns. 

     

  • 10:15
    Panel Discussion

    Panel discussion
    Is AppSec Still Ignored in GRC?

    Arrow

    Application security is often mentioned in compliance frameworks, but does it actually get integrated into risk management processes? This panel examines the disconnect between GRC requirements and engineering reality, and how teams can close the gap.

    • Why are AppSec risks still overlooked in many GRC frameworks?
    • How can compliance obligations become actionable for developers without creating friction?
    • What metrics or reporting approaches best link AppSec outcomes to business impact?
    • Should GRC professionals and engineers collaborate differently to improve adoption and visibility?

    Moderator:

    Tara Whitehead Senior Manager Security Engineering Education CommBank

    Panellists:

    Jugal Nayal Application Security Specialist Data Capture Experts

    Andy Hsu Senior Application Security Engineer Flexera

    Simon Scaife Sales Director Zimperium 

  • 10:50
    Sponsor Presentation

    Automating Compliance at Cloud Speed: Lessons for CI/CD and DevSecOps

    Arrow

    As software delivery accelerates, compliance can’t be an afterthought. This session explores how leading teams embed automated controls into CI/CD pipelines, translating governance into code. Learn practical approaches to scaling compliance across DevSecOps workflows—without slowing innovation or compromising security.

  • 11:15
    Break-1

    Get Refreshed! Mingle

    Arrow
  • 11:55
    Andrew Cunningham-1

    AI in DevSecOps: Powering the Lifeblood Donate Blood App

    Andrew Cunningham - Application Development Manager Australian Red Cross Lifeblood -

    Arrow

    This session explores how AI/ML is being applied within DevSecOps pipelines supporting the Lifeblood Donate Blood app and the internal Lifeblood platforms behind it. We’ll focus on practical ways AI is being used to increase test coverage, enhance security, streamline delivery, and introduce smarter governance, along with insights from applying these approaches in a production environment.

    • Leveraging AI to enhance security and pipeline efficiency
    • Balancing automation with regulated governance in DevSecOps
    • Insights from scaling AI across customer and internal platforms
  • 12:20
    Nir Weinberg-2

    AppSec is Dead? Why Frontier Models Demand Evolution, Not Replacement.

    Nir Weinberg - Senior Solutions Engineer - Snyk

    Arrow

    This session explores how security controls behave in live delivery environments. From blocked pipelines to last minute risk escalations, the release function often sees where DevSecOps design does not match operational reality. The speaker shares how controls were redesigned to reduce friction while improving risk clarity and release predictability.

  • 12:45
    Interactive Discussion

    Beyond STRIDE: Why MAESTRO is the New Baton for DevSecOps Threat Modelling

    Arrow

    The static nature of traditional threat modeling approaches fail to capture the fluid attack surfaces of cloud-native ecosystems and AI-integrated workflows. This session introduces MAESTRO, a dynamic threat modeling framework designed for multi-agent systems, continuously evolving environments. Using real-world examples, it shows how to embed security into AI lifecycle and CI/CD pipelines addressing IAM complexity, misconfigurations, supply chain risks, and emergent threats - enabling DevSecOps teams to build resilient, adaptive, and secure AI systems by design.

    Speakers:

    Owais Khan Senior Cyber Security Architect EnergyAustralia

    Rakesh Sharma Chief Advisor CYAIFI (Cyber & Artificial Intelligence for Future Impact) 

  • 13:10
    Lunch_ Dinner-1

    Lunch

    Arrow
  • 14:10
    Panel Discussion

    Panel Discussion
    Breaking Boundaries: Securing APIs, Microservices, and SaaS Across Teams

    Arrow

    This panel explores how organisations manage security beyond the code they own. Panellists share how they maintain visibility, enforce standards and reduce risk across APIs, microservices and SaaS integrations.

    • What blind spot in an API, SaaS, or dependency later turned into a security issue?
    • Where have ownership gaps caused problems, and how did you fix them in practice?
    • What security approach sounded good on paper but failed once teams had to move fast?

    Panellists:

    Luke Bampton Application Security Lead Monash University

    Medha Mishra Lead Application Security Engineer Wrkr

    Ibrahim Mohammed DevSecOps Design & Assurance Manager Insignia Financial 

  • 14:45
    Sponsor Presentation

    Securing Cloud, Compliance, and the Software Supply Chain

    Arrow

     As cloud adoption accelerates, managing and securing digital assets is more critical than ever. This session explores strategies for ensuring robust security, maintaining compliance, and strengthening governance. We’ll also examine how software supply chain management plays a key role in mitigating vulnerabilities, providing a comprehensive approach to securing your organisation’s digital landscape.  

  • 15:10
    Abdullah Muhammad - NEW

    Closing Keynote Presentation
    Carrot vs Stick: What Actually Drives Secure Engineering Behaviour?

    Abdullah Muhammad - Application Defence Manager - Bupa

    Arrow

    Security teams debate whether engineers respond better to incentives or enforcement. This session explores approaches for motivating secure coding practices in fast-moving DevSecOps teams.

    • Do incentives work better than mandatory rules and policies to drive secure behaviour, or vice versa?
    • Are there examples where culture alone improved security outcomes more than policies?
    • How do metrics and recognition influence engineering decisions day-to-day?
  • 15:35
    Tara Whitehead

    Chairperson's Closing Remarks

    Tara Whitehead - Senior Manager Security Engineering Education - CommBank

    Arrow
  • 15:45
    Break

    Close of AppSec & DevSecOps Melbourne 2026 & Afternoon Tea

    Arrow
Slack icon Join the Corinium Community
Corinium-logo_+tagline_horizontal_web-header
  • Corporate Home
  • About Us
  • Events Calendar
  • Sponsorship Inquiries
  • Business of Data
  • Business of InfoSec
  • AssetOps
  • Privacy Policy
Join our newsletter for all our latest news & events
Sign me up
© 2026, Corinium Global Intelligence

NO.08520994 | enquiries@coriniumintel.com | Privacy policy