Manager/Lead Security Engineer Donnelley Financial Solutions, United States
AI significantly shapes the "shift left" approach in application security (AppSec) by enabling automated, real-time code analysis, identifying potential vulnerabilities early in the development lifecycle, providing context-aware recommendations to developers, and prioritizing critical security issues, effectively allowing developers to fix security problems as they code rather than waiting until later stages of development.AI willanalyze code context to better understand the intent behind code snippets, leading to more accurate vulnerability detection and reducing false positives in SAST and Open-source analysis.Most SCA scanning tools focus on manifest files which doesn't sync with source code and version-based vulnerability; hence we are 100% not sure if the engineering team uses the flagged version. AI significantly enhance the perspective of SAST/SCA/DAST/Vulnerability scanning and Pentest in software security.
Learning Objectives:
How AI-powered AppSec tools can seamlessly integrate with existing development environments like IDEs, allowing developers to receive security feedback directly within their workflow and this will help significantly reduce false positives and improve overall security posture.
Understanding AI benifits in shift-left process and describe the challenges involved
Demonstrate the benifits of baking AI into APpsec tools