About the summit
Now in its second year, AppSec World brings together application security, product security and engineering leaders on both US coasts, with events in New York and San Francisco. Software is being built and released faster than security teams can review it. Cloud-native development, open-source dependencies, APIs, AI-generated code and now coding agents have expanded the attack surface, while AppSec teams are still expected to reduce risk without slowing engineering. At most US cybersecurity conferences, application security is a stream inside a much broader event, never the room itself. AppSec World is that room. Across both coasts, CISOs, VPs and Heads of AppSec, Product Security and Security Engineering come together with architects, engineering leaders and the practitioners responsible for securing software to compare programmes directly with their peers. Make sure you are part of the discussion at AppSec World in New York and San Francisco.
Who attends
- CISO
- Head of AppSec
- Director of Product Security
- VP Engineering
- Head of Platform / Cloud
- Principal Security Engineer
What the programme covers
- Application Security at ScaleBuilding security into the software lifecycle without turning AppSec into a release gate.
- Product Security and Secure by DesignOwning security from architecture and design through development and production.
- AI-Generated Code and Coding AgentsSecuring the code, tools and permissions introduced by AI-assisted and agentic development.
- Software Supply Chain SecurityProtecting open-source dependencies, build pipelines, artifacts and the systems software teams rely on.
- Application Security Testing and ASPMConnecting testing and posture data so teams can focus on the vulnerabilities that matter.
- API and Cloud-Native SecurityFinding and securing APIs, containers, Kubernetes and cloud-native applications as they change.
- Vulnerability Prioritisation and RemediationMoving from vulnerability volume to what is exploitable, exposed and actually fixable.
- Developer Security and Secure CodingGiving engineers the guardrails, training and secure defaults to fix risk before production.