-
20 August 2025
-
08:30
Registration, Coffee & Networking in the Exhibition Area
-
09:00
Welcoming Remarks from Corinium & Chair's Remarks
Dan Haagman - CEO Chaleit & Honorary Professor - Murdoch University
-
09:10
Speed Networking
-
09:15
Building an AI Agent for PII Management on API Definition/Contract and Datawarehouse
Rajath Ramesh - Group Director, Product and Platform Engineering - Carousell Group
-
09:40
Shift-Left Security: Proactively Building Resilient Applications in AppSec and DevSecOps
- How integrating security practices early in the SDLC reduces costs and strengthens application resilience
- Empowering developers with tools and training to identify and address vulnerabilities during the coding phase
- Leveraging automated security tools and processes within continuous integration/continuous deployment pipelines
- Strategies to align rapid software delivery with robust security in agile and DevSecOps environments
-
10:05
Keynote Panel: Safeguarding the Software Ecosystem – From Development to Deployment
- What innovative practices ensure end-to-end security across the software development and supply chain lifecycle, integrating DevSecOps, AppSec, and container security?
- How can continuous risk assessment and improvement through DevSecOps practices protect every phase of the SDLC?
- What role does automation play in enhancing operational efficiency and simplifying compliance within governance frameworks?
- How can layered security strategies proactively address vulnerabilities in software supply chains and containerised environments?
Moderator:
Dan Haagman CEO Chaleit & Honorary Professor Murdoch University
Speakers:
Reuben Athaide Head, Cyber Security Advisory and DevSecOps Standard Chartered
Yih Wen Tsai Senior Cybersecurity Architect PODIUM.io
-
10:40
Topic to Be Confirmed
Senior representative - - Sonatype
-
11:05
Morning Coffee & Networking in the Exhibition Area
-
11:35
Topic to Be Confirmed
Senior representative - - Gitlab
-
12:00
DevSecOps Practices: Applying Security Principles to Software Development
Suresh Govindaraju - Director of Engineering - PayPal
-
12:30
Topic to Be Confirmed
Senior representative - - JFrog
-
12:55
Buffet Lunch & Networking in the Exhibition Area
-
13:55
Topic to Be Confirmed
Senior representative - - Black Duck
-
14:20
Panel: Building Bridges - Integrating Development, IT and Security in a Seamless DevSecOps Strategy
- Breaking Down Silos: Fostering collaboration between development, IT operations, and security teams for unified goals
- Embedding security checks and tools into the CI/CD pipeline without slowing down development
- Shared Responsibility: Aligning roles, responsibilities, and KPIs to ensure security is everyone's job
- Encouraging a proactive mindset toward security through training and organisational buy-in
Panellists:
Sathiyaseelan Murugaiayh Head of DevSecOps Circles.Life
-
14:55
Security Anti-patterns in CI/CD
Linda Chang - Assistant Director, Clusters & Technology Management Office (CTMO) - GovTech
While driving adoption of CI/CD across more than 50 Singapore Government agencies in a landscape with distributed and mostly outsourced systems, GDT-CSH has encountered various security anti-patterns in the CI/CD pipelines that could compromise application security. Drawing from real-world experiences with agencies and vendors, this talk will dissect common security anti-patterns we've discovered and share practical strategies for addressing them.
Speakers:
Linda Chang Assistant Director, Clusters & Technology Management Office (CTMO) GovTech
Daniel Liu Senior DevOps Engineer GovTech
-
15:30
Afternoon Tea & Networking in the Exhibition Area
-
16:00
Implementing Effective Security Incident Response in DevSecOps: Practical Strategies for Developers, Security, and Operations Teams
- Step-by-step guidance on embedding incident response processes within CI/CD pipelines for faster detection and containment
- Practical implementation of tools and technologies for automated security event monitoring, alerting, and remediation across development and operational environments
- Coordinating Cross-Team Responses to Security Incidents: Proven techniques for ensuring developers, security professionals, and operations teams work in unison during an incident to quickly address and resolve vulnerabilities
- Post-Incident Response and Feedback Loops: Strategies for documenting incidents, conducting root cause analysis, and using insights to strengthen DevSecOps workflows and improve future security posture
-
16:25
Closing Panel: What Are the Best Practices in Cultivating Security as a Core Pillar in Software Development
- Building security measures into every phase of the SDLC, enhancing efficiency, reducing risks, and bolstering trust
- Adopting early-stage vulnerability detection to mitigate risks before they escalate, ensuring safer and smoother production
- How can you define comprehensive policies and guidelines to unify team actions and maximise the effectiveness of security tools and technologies?
- Encouraging ongoing skill development and adaptive strategies to meet evolving security challenges head-on
Moderator:
Zhou Zhihao Vice President ISC2 SG Chapter
-
17:00
Closing Remarks
Not Found