Collins Square Events Centre
August 20, 2025
8:30am - 3:00pm

Melbourne AppSec & DevSecOps Summit 2025

Join us in August to strengthen your development process with cutting-edge security practices. Connect with experts, explore automation, secure containers, and gain practical insights through interactive sessions and real-world case studies.

Melbourne AppSec & DevSecOps Summit 2025
Melbourne AppSec & DevSecOps Summit 2025

Join us at the AppSec and DevSecOps Summit to fortify your software development lifecycle.

We're bringing together developers, security experts, and industry leaders to seamlessly integrate security into every step of your development process.

Discover best practices for shifting left, automating security, and managing open-source risks. Explore how to improve DevSecOps adoption, secure containers and microservices, and weigh in on the debate: automation vs. manual testing. Engage in interactive sessions, real-world case studies, panel discussions, and debates to stay ahead of the latest trends in application security.

Key Themes:

  • Integrating Security into the Software Development Lifecycle
  • Shift Left Strategies
  • Application Breach Response
  • Automating Security Processes
  • Managing Open Source Risks
  • Improving DevSecOps Adoption
  • Container and Microservices Security
  • Automation vs. Manual Testing: What Works Best


Who Should Attend?


Developers, DevOps engineers, security professionals, IT leaders, and anyone eager to enhance their understanding of application security and DevSecOps practices.

Don't miss this chance for a day of learning, innovation, and collaboration at the AppSec and DevSecOps Summit.

Program Highlights

12+

Speakers

10+

Sessions

150+

AppSec & DevSecOps Leaders

1

Track

Our Speakers

Neha Malik

Neha Malik

Head of Product Security
Warren Bailey

Warren Bailey

General Manager - DevSecOps Customer and Product
m Brennan

m Brennan

Group Owner - Developer eXperience
Peter Freiberg

Peter Freiberg

Managing Consultant
Pamela O'Shea

Pamela O'Shea

Director
Paul McCarty

Paul McCarty

Security Researcher and Trainer
Cole Cornford

Cole Cornford

Chief Executive Officer
Matt Jones

Matt Jones

Director and Co-Founder
Marcio Almeida

Marcio Almeida

Technical Director & Co-Founder
Luke Bampton

Luke Bampton

Application Security Lead
Asim Suvedi

Asim Suvedi

Senior Engineering Manager - ClickSend
Hayden MacKellar

Hayden MacKellar

Head of Cyber Security & Assurance
Jaap Singh

Jaap Singh

VP of Customer Strategy and Co-Founder
Nir Weinberg

Nir Weinberg

Lead Technical Success Manager
Andrew Dean

Andrew Dean

Enterprise Solutions Engineer
Jim Williams

Jim Williams

APJ SA Leader

Agenda

8:30 AM
Registration Open - Barista Coffee, Breakfast and Networking
No items found.
9:15 AM
Opening Address from the MC
No items found.
9:25 AM
Opening Keynote: Building a Strong ProdSec Program

Examine best practices for establishing a robust production security program that minimises risk and accelerates incident response. Attendees will learn how to align security operations with DevOps practices and implement proactive monitoring across live environments.

  • Defining roles and responsibilities to ensure clear ownership and accountability in ProdSec teams
  • Integrating security monitoring and response into CI/CD pipelines for continuous protection
  • Leveraging threat modeling and automated controls to detect and mitigate runtime vulnerabilities
Neha Malik
Head of Product Security, REA Group
9:45 AM
From Friction to Function: Unsolved AppSec Challenges and Real-World Wins from Financial Services

Despite the abundance of tools in application security, many core challenges remain unresolved—especially around developer engagement and program effectiveness.

  • Persistent AppSec challenges include misaligned priorities, tool sprawl, and limited developer involvement
  • A comparison of two financial institutions reveals how shifting from traditional to dev-first security approaches led to improved outcomes
  • Securing developer buy-in is often the missing link in solving some of AppSec’s toughest, most persistent problems
Nir Weinberg
Lead Technical Success Manager, Snyk
10:15 AM
Debate: Secure by Design or Chaos by Default? Winning the Supply Chain War

This debate challenges two schools of thought: "Control-first defenders" vs "Exploit-first breakers"—exploring how far each philosophy should go, what trade-offs they create, and where real-world teams should focus their limited resources.

  • What creates more security ROI: building airtight controls or breaking things to expose flaws?
  • Should red teaming be embedded into the SDLC—or remain separate for objectivity?
  • Are tools like SBOMs and SLSA frameworks meaningful or just compliance theatre?
  • Can DevSecOps teams be trusted to police their own supply chains—or do we need centralised oversight?
  • Is it ever acceptable to ship insecure components in the name of velocity?
Paul McCarty
Security Researcher and Trainer, SourceCodeRED
Peter Freiberg
Managing Consultant, Sabbaticas
10:45 AM
Fewer Vulnerabilities, Faster Delivery: How to Cut 80% of Container CVEs Upfront

In the world of software updates, we often find ourselves overwhelmed by constant patching of code we don’t even use. Imagine cutting down that needless effort by removing 80% of unused code. This session dives into how purpose-built, minimal container images and modern supply chain security practices can drastically reduce vulnerability management headaches. Drawing on years of experience with containers, Kubernetes, and CNAPP tools, you will learn how to shrink your container attack surface, reduce CVEs by 80%, and ease the burden on engineering teams.

  • Reduce Vulnerabilities by Design: Learn how purpose-built minimalist container images can cut your container OS packages by 80%, drastically reducing the attack surface and CVEs upfront
  • Simplify Vulnerability Management: See how fewer packages and fewer vulnerabilities lead to a manageable volume of security alerts, enabling your teams to focus on what matters instead of being overwhelmed
  • Build with Supply Chain Security: Understand the importance of hardened build environments and signing with short-lived keys to trust the container images you deploy—bringing real supply chain security to your cloud-native apps

Andrew Dean
Enterprise Solutions Engineer, Chainguard
11:00 AM
Morning Tea & Networking
No items found.
11:30 AM
Interactive Audience Activity: Responding to a Real-Time Application Breach

An interactive session where attendees collaborate to handle a simulated security breach in a live application, focusing on rapid response and mitigation.

No items found.
11:50 AM
AppSec is a DevX Problem

Explore how application security challenges often stem from developer experience issues in security services and how improving DevX can lead to stronger security outcomes. Attendees will learn practical strategies to integrate security more smoothly into development workflows without compromising productivity.

  • How friction in the developer experience leads to security workarounds and vulnerabilities
  • Techniques for bringing security insights into IDEs and CI/CD pipelines to streamline DevX
  • Measuring success: key metrics and feedback loops that align security goals with developer productivity
m Brennan
Group Owner - Developer eXperience, Telstra
12:10 PM
How to... Scale Your DevSecOps with Compliance: From Bottleneck to Business Enabler

Transform compliance from a development bottleneck into an acceleration engine. This session provides actionable strategies for implementing unified compliance within your DevSecOps pipeline.

You'll learn how to:

  • Shift compliance left - Integrate policy checks into development workflows from day one
  • Automate policy enforcement - Build compliance gates that catch issues before production
  • Create audit-ready evidence - Generate compliance documentation automatically through your pipeline
  • Establish cross-team alignment - Get security, development, and compliance teams working together effectively

Jim Williams
APJ SA Leader, GitLab
12:25 PM
Panel Discussion: The Changing Nature of Software Assurance

This panel convenes security leaders to discuss how software assurance has evolved from periodic testing to continuous, integrated validation throughout the development lifecycle. Participants will explore emerging tools, standards, and cultural shifts that redefine how organisations ensure software trustworthiness today.

  • How has the adoption of DevOps and CI/CD pipelines transformed traditional software assurance practices, and what new skills do teams need?
  • In what ways are automation and shift-left testing changing when and how assurance activities are performed?
  • How are emerging frameworks impacting software assurance strategies and investments?
  • What role do runtime monitoring and continuous verification play in complementing pre-release security checks, and how can teams balance speed with thoroughness?
Jaap Singh
VP of Customer Strategy and Co-Founder, Secure Code Warrrior
Matt Jones
Director and Co-Founder, elttam
Pamela O'Shea
Director, Shea Security
Marcio Almeida
Technical Director & Co-Founder, Tanto Security
12:55PM
Roundtable Discussions

Select a topic of discussion and engage in an interactive roundtable discussion with a group of your like-minded peers.

No items found.
1:50 PM
Lunch & Networking
No items found.
2:40 PM
CloudSec QuickFire: 10 Questions in 10 Minutes

Put your cloud security knowledge to the test in this fast-paced quiz covering real-world threats, key concepts, and emerging trends. Compete for bragging rights—and a travel voucher—as the top scorer takes the crown.

No items found.
2:50 PM
Beyond Coverage and Capability, a New Approach to Guiding and Measuring AppSec Effectiveness

Enterprise application security programs are traditionally measured on their capability to address specific aspects of the technology stack, and then the coverage for rolling that out across the enterprise. While this sounds effective, it's anything but as can be seen by the proliferation of ASPM and AI-AST based products and their subsequent wringing in the markets.

So what should modern product security functions aim for? In this talk I'll outline a different Five I's that defines the baseline for an effective ProdSec function and how you can take quick steps as either a scale-up business or enterprise to align and move forward.

Cole Cornford
Chief Executive Officer, Galah Cyber
3:10 PM
Think Tank: Navigating What’s Next in AppSec and DevSecOps

This interactive session brings security, engineering, and product professionals together to unpack the big issues shaping the future of AppSec and DevSecOps. We’ll explore emerging threats, evolving team models, and the growing role of AI—highlighting both the risks and the opportunities. Expect honest takes, practical insights, and a healthy dose of forward-thinking debate.

  • What’s the most pressing challenge we’ll face by 2026?
  • Is AI accelerating our work—or introducing new risks?
  • How can we keep AI training data secure and trustworthy?
  • Are our teams prepared to defend against deepfake-style threats?
Warren Bailey
General Manager - DevSecOps Customer and Product, nbn® Australia
Luke Bampton
Application Security Lead, Monash University
Asim Suvedi
Senior Engineering Manager - ClickSend, Cinch
Hayden MacKellar
Head of Cyber Security & Assurance, Nuix
3:30 PM
Event Closes
No items found.

Who Attends?

Chief Technology Officer

Chief Information Security Officer

Head of Application Security

Head of DevSecOps

Head of Cybersecurity

VP Engineering

Product Security Director

DevOps Director

Developer Experience Manager

Release and Environment Manager

Platform Engineering Director

Software Engineering Manager

Cybersecurity Engineering Director

API Security Manager

Testing Manager

Benefits For Attendees

4.7 / 5

average overall rating from attendees at our events.

94%

of attendees rate our content as “Extremely Relevant”.

100%

of attendees would recommend attending a Clutch Event to a colleague.

Our event sponsors
For sponsorship opportunities, please get in touch with Danny Perry, danny@weareclutch.com.au

Event Location

Collins Square Events Centre

Level 5, Tower 2/727 Collins St, Docklands VIC 3008
Melbourne AppSec & DevSecOps Summit 2025

FAQs

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

No items found.

Get In Touch

Contact our event team for any enquiry

Danny Perry

Director of Sales
For sponsorship opportunities.
danny@clutchgroup.co

Lili Munar

Director of Client Relations
For guest and attendee enquiries.
lilibeth@clutchgroup.co

Ben Turner

Director of Conference Production
For speaking opportunities & content enquiries.
ben@clutchevents.co

Taylor Stanyon

Director of Operations
For event-related enquiries.
taylor@clutchgroup.co