Speaking
Chris Romeo, AI security and application security speaker
25 talks, 58 stages, since 2014
RSA Conference every year from 2015 to 2025
Chris is booking speaking engagements for 2027.
Speaking topics
Securing AI agents
How to secure AI agents, control their access to tools and data, and assess the risks of the actions they take.
How AI changes the AppSec program
How application security programs can adapt their practices and priorities as teams build with AI.
AI-written code
How to review and secure AI-written code, with checks that help developers find security problems before they ship.
Building security champion programs
How to build security champion programs that give developers practical skills and support for securing their software.
Bio for organizers
Chris Romeo is a third-time cybersecurity founder, now building a new company in application security and AI. He founded Security Journey and led it to an exit in 2022, then co-founded Devici, which exited in 2025. Chris has thirty years in security, including time as Chief Security Advocate at Cisco, and has spoken at RSA Conference every year from 2015 to 2025. He co-hosts The Application Security Podcast and AI Security Table.
Past chairing & programming
ThreatModCon 2023
Founding team & emcee
RSA Conference
Program Committee
OWASP Triangle
Chapter Lead
Cisco SecCon
Organiser & Host
Past talks
2025
The Next Twenty Years: What AppSec Needs to Do to Cement the Future
2025
The Startup Operating System
2024
Secure and Privacy by Design Converge with Threat Modeling
2024
Why the “Secure by Design” pledge won’t save us from AppSec failures
2024
The Paradox of Secure and Private by Design and Default
2024
The Modern Application Security Rocket Ship
2023
Zero Trust Threat Modeling
2023
The Application Security State of the Union
2023
Open Source Software: The Good, The Bad, The Ugly
2022–2023
Ten DevSecOps Culture Failures
2022
Elite Security Champions Build Strong Security Culture
2021–2022
Using the Threat Modeling Manifesto to Build an Enterprise Threat Modeling Program
2021
Developers Dislike Security: Ten Frustrations and Resolutions
2021
DevSecOps Culture: Laughing Through the Failures
2020
10 Things I Wish Every Developer Knew about Security
2019–2020
Cheaper by the Dozen: Application Security on a Limited Budget
2018
Security Culture Hacking: Disrupting the Security Status Quo
2018
Building an AppSec Program with a Budget of $0: Beyond the OWASP Top 10
2017–2018
How to Transform Developers into Security People
2017–2018
AppSec Behaviors for DevOps Breed Security Culture Change
2016
AppSec Awareness: A Blue Print for Security Culture Change
2015–2016
Cisco’s Security Dojo: Raising the Application Security Awareness of 20,000+
2015
Application Security Awareness: Building an Effective and Entertaining Security Training Program
2014
DevOps & AppSec: Why They Matter in an IoT World
2014
Dysfunctional Testing
Past training & workshops
Threat Modeling Championship: Breaker vs. Builder
3-hour workshop · red team against blue team, against the clock
Advanced Security Threat Modeling: Red vs. Blue
Learning Lab · co-facilitated with Michael Burch
Security Threat Modeling
Two-hour Learning Lab, run twice · co-facilitated with Michael Burch
Hands-on Threat Modeling
2-hour workshop
Building a World Class Security Champions Program
Birds of a Feather · facilitated discussion under Chatham House Rule
Building an AppSec Program on the Cheap with OWASP
Peer2Peer discussion, capacity-limited · three annual runs
Building an AppSec Program with OWASP
Full-day training
Changing Security Culture
Interactive table exercise · companion to the Security Culture Hacking talk
Threat Modeling: uncover vulnerabilities without looking at code
Workshop
AppSec Fundamentals
Full-day training
Guest appearances
- Security Champion Veterans Explain All
- Supercharge Threat Modeling with Software Supply Chain Security
- Designing Secure and Private Software by Default
- Why “shift-left” isn’t good enough
- RSAC 2024 Recap: Top Trends & Takeaways
- AppSec Unbounded: Embrace “Secure and Privacy by Design”
- Building a Successful Security Champions Program
- AppSec and DevSecOps track discussion
- The Role of AI in Application Security
- Threat Modeling Lab — a hands-on workshop
- Shift Left? — The Hedge 212
- The Great Debate: Does DAST work for DevSecOps?
- Threat Modeling and Software Supply Chain Security
- Threat Modeling Roundtable
- Building a Grassroots Security Champions Program
- The state of application security
- Learning Application Security
- SBOMs, provenance, security champions and third-party risk
- The Security Champions Framework
- Threat Modeling Manifesto in a Mobile First World
- Application Security at Scale
- Threat Modeling with Chris Romeo — The Hedge 164
- Chris Romeo Talks Security Journey Exit
- How a Cybersecurity Professional Broke Out as an Entrepreneur
- Successes and Failures at Security Training
- DevSecOps Culture: Laughing Through the Failures
- Threat Modeling for Product Managers
- Threat Modeling the Software
- Chris Romeo and the State of Security — The Hedge 48
- How to Transform Developers Into Security People
- The Threat Modeling Manifesto: From Theory to Practice
- Threat Modeling Manifesto launch panel
- AppSec Awareness and Security Culture
- Things Every Developer Should Know About Security
- Creating Security Champions with Continuous Education in DevSecOps
- Building a Security Mindset
- IoT Security: the Security Development Lifecycle Way
- On Changing Culture
- The Cisco Security Ninja program