Collins Square Events Centre
August 20, 2025
8:30am - 3:00pm

Melbourne AppSec & DevSecOps Summit 2025

Join us in August to strengthen your development process with cutting-edge security practices. Connect with experts, explore automation, secure containers, and gain practical insights through interactive sessions and real-world case studies.

Melbourne AppSec & DevSecOps Summit 2025
Melbourne AppSec & DevSecOps Summit 2025

Join us at the AppSec and DevSecOps Summit to fortify your software development lifecycle.

We're bringing together developers, security experts, and industry leaders to seamlessly integrate security into every step of your development process.

Discover best practices for shifting left, automating security, and managing open-source risks. Explore how to improve DevSecOps adoption, secure containers and microservices, and weigh in on the debate: automation vs. manual testing. Engage in interactive sessions, real-world case studies, panel discussions, and debates to stay ahead of the latest trends in application security.

Key Themes:

  • Integrating Security into the Software Development Lifecycle
  • Shift Left Strategies
  • Application Breach Response
  • Automating Security Processes
  • Managing Open Source Risks
  • Improving DevSecOps Adoption
  • Container and Microservices Security
  • Automation vs. Manual Testing: What Works Best


Who Should Attend?


Developers, DevOps engineers, security professionals, IT leaders, and anyone eager to enhance their understanding of application security and DevSecOps practices.

Don't miss this chance for a day of learning, innovation, and collaboration at the AppSec and DevSecOps Summit.

Program Highlights

12+

Speakers

10+

Sessions

150+

AppSec & DevSecOps Leaders

1

Track

Our Speakers

Neha Malik

Neha Malik

Head of Product Security
M Brennan

M Brennan

Group Owner - Developer Experience
Ben Gittins

Ben Gittins

Application Security
Peter Freiberg

Peter Freiberg

Managing Consultant
Paul McCarty

Paul McCarty

Security Researcher and Trainer
Cole Cornford

Cole Cornford

Chief Executive Officer
Riduanul Shahria

Riduanul Shahria

AppSec and E&A Practice Lead
Matt Jones

Matt Jones

Director and Co-Founder
Craig Dent

Craig Dent

Staff Solutions Engineer

Agenda

8:30 AM
Registration Open - Barista Coffee, Breakfast and Networking
No items found.
9:15 AM
Opening Address from the MC
No items found.
9:25 AM
Opening Keynote: Building a Strong ProdSec Program

Examine best practices for establishing a robust production security program that minimises risk and accelerates incident response. Attendees will learn how to align security operations with DevOps practices and implement proactive monitoring across live environments.

  • Defining roles and responsibilities to ensure clear ownership and accountability in ProdSec teams
  • Integrating security monitoring and response into CI/CD pipelines for continuous protection
  • Leveraging threat modeling and automated controls to detect and mitigate runtime vulnerabilities
Neha Malik
Head of Product Security, REA Group
9:45 AM
Unsolved Problems in Application Security

Despite ongoing advancements in tools and processes, application security still encounters persistent gaps that leave organisations exposed. This keynote will highlight broad challenges and discuss avenues for future improvement.

  • Ongoing visibility issues in complex architectures, where many vulnerabilities remain undetected by existing scanning and testing approaches
  • Persistent risks from third-party and open-source components, including gaps in tracking and verifying all dependencies
  • Difficulties in measuring and communicating true security impact, as simple vulnerability counts often fail to inform strategic decisions
Craig Dent
Staff Solutions Engineer, Snyk
10:15 AM
Panel Discussion: Securing the Software Supply Chain: Offensive and Defensive Strategies

This panel brings together security leaders to explore how adversaries compromise software supply chains and how organisations can defend against such threats. Attendees will learn from both attacker-focused tactics and practical defensive measures to strengthen their development pipelines.

  • What are the most common entry points attackers exploit in modern software supply chains, and how can teams proactively identify these weaknesses?
  • How can red teaming and adversary simulation be used to validate the effectiveness of existing supply chain security controls?
  • Which defensive techniques provide the greatest impact with minimal disruption to development velocity?
  • How should organisations balance rapid software delivery with rigorous supply chain security, and what governance models ensure accountability across Dev, Sec, and Ops teams?
Paul McCarty
Security Researcher and Trainer, SourceCodeRED
Peter Freiberg
Managing Consultant, Sabbaticas
10:45 AM
Tales and Fails: New Lessons in AppSec Learned in 2025

Join Cole Cornford as he explores the successes and missteps that defined application security in 2025, highlighting real-world case studies and emerging industry best practices. Attendees will gain actionable insights on how to anticipate evolving threats, avoid common pitfalls, and build more resilient AppSec programs moving forward.

  • How AI-driven attacks outpaced traditional defenses and adaptive mitigation strategies that proved effective
  • A deep dive into a major breach “fail,” examining the root causes and the rapid course corrections that minimised impact
  • Success stories: teams that mastered shift-left security at scale and the cultural changes that enabled their wins
  • Building continuous assurance: practical approaches to integrating runtime monitoring and automated remediation into CI/CD pipelines

Cole Cornford
Chief Executive Officer, Galah Cyber
11:00 AM
Morning Tea & Networking
No items found.
11:30 AM
Interactive Audience Activity: Responding to a Real-Time Application Breach

An interactive session where attendees collaborate to handle a simulated security breach in a live application, focusing on rapid response and mitigation.

No items found.
11:50 AM
AppSec Is a DevX Problem

Explore how application security challenges often stem from developer experience issues and how improving DevX can lead to stronger security outcomes. Attendees will learn practical strategies to integrate security seamlessly into development workflows without compromising productivity.

  • How friction in the developer experience leads to security workarounds and vulnerabilities
  • Techniques for embedding security tools and checks into IDEs and CI/CD pipelines to streamline DevX
  • Measuring success: key metrics and feedback loops that align security goals with developer productivity

M Brennan
Group Owner - Developer Experience, Telstra
12:10 PM
How I Solved... Cryptography Mismanagement By Engineers

Even the most capable developers can fall prey to hidden pitfalls when integrating cryptography into applications. This demo session shines a spotlight on common missteps—from poorly implemented encryption libraries to dangerous key management shortcuts—and illustrates how to prevent these errors in your own code.

  • Identifying classic cryptographic mistakes that put data at risk
  • Pinpointing faulty assumptions in encryption key management and usage
  • Demonstrating real-world consequences of cryptographic misconfigurations
  • Sharing proven best practices to embed robust encryption throughout the development cycle

No items found.
12:25 PM
Panel Discussion: The Changing Nature of Software Assurance

This panel convenes security leaders to discuss how software assurance has evolved from periodic testing to continuous, integrated validation throughout the development lifecycle. Participants will explore emerging tools, standards, and cultural shifts that redefine how organisations ensure software trustworthiness today.

  • How has the adoption of DevOps and CI/CD pipelines transformed traditional software assurance practices, and what new skills do teams need?
  • In what ways are automation and shift-left testing changing when and how assurance activities are performed?
  • How are emerging frameworks impacting software assurance strategies and investments?
  • What role do runtime monitoring and continuous verification play in complementing pre-release security checks, and how can teams balance speed with thoroughness?
Tara Whitehead
Cybersecurity Engineering Lead, MYOB
Matt Jones
Director and Co-Founder, elttam
12:55 PM
Roundtable Discussions

Select a topic of discussion and engage in an interactive roundtable discussion with a group of your like-minded peers.

No items found.
1:45 PM
Lunch & Networking
No items found.
2:35 PM
AI Is Reshaping AppSec

Learn how AI and machine learning are transforming application security by automating threat detection, vulnerability assessment, and remediation. Attendees will gain insights into real-world use cases and practical considerations for integrating AI-driven tools into existing AppSec workflows.

  • How AI-powered scanning and fuzzing are uncovering complex vulnerabilities faster than traditional methods
  • The role of machine learning in prioritising findings and reducing false positives for security teams
  • Ethical and practical challenges when relying on AI models—data quality, model drift, and explainability considerations
Riduanul Shahria
AppSec and E&A Practice Lead, Bunnings
2:55 PM
The Great Debate: Automation vs. Manual Testing: What's the Right Balance in AppSec?

A lively debate on the effectiveness of automated security tools versus manual testing methods in ensuring application security.

No items found.

Who Attends?

Chief Technology Officer

Chief Information Security Officer

Head of Application Security

Head of DevSecOps

Head of Cybersecurity

VP Engineering

Product Security Director

DevOps Director

Developer Experience Manager

Release and Environment Manager

Platform Engineering Director

Software Engineering Manager

Cybersecurity Engineering Director

API Security Manager

Testing Manager

Benefits For Attendees

4.7 / 5

average overall rating from attendees at our events.

94%

of attendees rate our content as “Extremely Relevant”.

100%

of attendees would recommend attending a Clutch Event to a colleague.

Our event sponsors
For sponsorship opportunities, please get in touch with Danny Perry, danny@weareclutch.com.au

Event Location

Collins Square Events Centre

Level 5, Tower 2/727 Collins St, Docklands VIC 3008
Melbourne AppSec & DevSecOps Summit 2025

FAQs

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

No items found.

Get In Touch

Contact our event team for any enquiry

Danny Perry

Director of Sales
For sponsorship opportunities.
danny@clutchgroup.co

Lili Munar

Director of Client Relations
For guest and attendee enquiries.
lilibeth@clutchgroup.co

Ben Turner

Director of Conference Production
For speaking opportunities & content enquiries.
ben@clutchevents.co

Taylor Stanyon

Director of Operations
For event-related enquiries.
taylor@clutchgroup.co