The AppSec lessons from Iron Man
2024-12-14 , Workshop Room 4

In this 2-hour interactive workshop, we will dive into the world of Application Security with the perspective of one of the most iconic tech-savvy superheroes: Iron Man. Like Tony Stark, who continuously refines his armor to fend off evolving threats, we will explore how developers, security champions, and engineers can fortify their applications against vulnerabilities.

The session will cover the full spectrum of Application Security, from threat modeling and secure coding to incident response, framed within the tech innovation and constant iteration that Iron Man embodies. Attendees will learn practical approaches to building robust security mechanisms into their software development lifecycle (SDLC), while maintaining agility in the face of new threats—just as Iron Man does with his suits.

Through engaging analogies, real-world examples, and actionable takeaways, participants will leave with a superhero’s toolkit to defend their applications from vulnerabilities, automate their defenses, and respond swiftly to incidents.

Key Topics:

Threat Modeling: Understanding the foundational elements of secure software.
DevSecOps: How to protect core application components from critical threats.
Vulnerability Management: Proactive vulnerability management process.
Application Monitoring: Incident response tactics that mirror Iron Man's agility in combat.

Get ready to suit up and protect your applications with the same ingenuity and foresight as Iron Man!


Step into the shoes—or rather, the suit—of Iron Man as we explore the dynamic world of Application Security. In this 2-hour workshop, you'll learn how to protect your applications with the same innovative strategies Tony Stark uses to shield his tech from relentless attacks.

This workshop is designed for developers, security engineers, and security champions who want to understand and implement security practices that are both robust and agile. We’ll cover every aspect of Application Security, from the fundamentals of secure coding to the latest automated defenses, all framed through the lens of Iron Man’s constant innovation and real-time problem-solving.

You’ll uncover how to:

Develop “armor” for your applications by integrating security from the start.
Protect the “arc reactor” of your system—its most critical components—from the most dangerous threats.
Improve your “battlefield awareness” with threat modeling and continuous vulnerability scanning.
Automate and scale your defenses using cutting-edge security tools.
Respond swiftly and effectively to incidents, with agility and precision, just like Iron Man in the heat of battle.
This engaging, workshop will not only provide practical insights and strategies but also inspire you to approach Application Security with creativity and foresight. By the end, you’ll be equipped with the tools and mindset to defend your applications like a true tech superhero.

Prepare to suit up—your journey to becoming an Application Security hero starts here!

Cassio Batista Pereira, a.k.a. @cassiodeveloper, is a Software Developer and Architect by formation. He acts as an AppSec Expert and thus helps companies and professionals to build safer solutions. He has two decades of experience in the IT market and Information Security in the most varied business segments, where he gained knowledge to work with different technologies, programming languages and processes. He is an evangelist for the Secure Development culture.