AI-Era AppSec: Transparency, Trust, and Risk Beyond the Firewall – Felipe Zipitria, Steve Springett, Aruneesh Salhotra, Ken Huang – ASW #363

This episode is sponsored by
Full Segment Notes
Guests
Project Leader at OWASP

Felipe Zipitria is a seasoned computer security expert with an MSc from Universidad de la República in Uruguay and over 20 years of technical experience. His career has evolved from SRE, DevOps, and SysAdmin roles into specialized security domains, with the past five years dedicated to Application Security and Cloud SecOps. Throughout his career, he has provided security consulting services for more than a decade, establishing himself as a trusted advisor in the field.
Beyond his professional practice, Felipe is deeply committed to education and open-source community leadership. He teaches Computer Security Fundamentals to undergraduate students and Web Application Security to graduate students at Uruguay’s public university. Since 2013, he has served as Uruguay Co-Chapter Leader for OWASP, and has been a core contributor to OWASP CRS as a developer and co-leader since 2021. He is also part of the OWASP Coraza leadership team, driving innovation in Web Application Firewall development. His dedication to nurturing the next generation of security professionals is evident through his four consecutive years as a Google Summer of Code mentor, where he guides students into open-source and OWASP initiatives.

Vice Chair, Global Board of Directors at OWASP Foundation

Steve guides teams in both the strategy and execution of secure software development. He integrates security throughout the entire development lifecycle, leading efforts in threat modeling, secure architecture and design, static, dynamic, and component analysis, offensive research, and defensive programming.

Steve’s passionate about helping organizations identify and reduce risk from the software supply chain. He is an open source advocate and leads the OWASP Dependency-Track project, OWASP Software Component Verification Standard (SCVS), and Chairs the OWASP CycloneDX Core Working Group and Ecma International TC54.

Steve serves as Vice Chair on the Board of Directors of the OWASP Foundation where he helps drive the continued growth of the foundation and the pursuit of its mission to make secure software a reality through open collaboration, education, and innovation.

CEO, CISO, SNM Consulting Inc. + OWASP Project Lead/Co-Lead at SNM Consulting Inc

I’m a seasoned technologist and servant leader with extensive expertise across cybersecurity, DevSecOps, AI, Business Continuity, Audit, and Sales. My impactful presence as an industry thought leader is underscored by my contributions as a speaker and panelist at leading industry events including RSA, CactusCon, Harvard, QA Forum, ADDO, Palo Alto Ignite, ISACA, OWASP, Open Source Congress, IAPP, InfoSec World, and Machines Can See (Dubai). My engagement with key security bodies like OWASP, IEEE, CFF, PBC, and IAPP significantly shapes security policies and promotes better cybersecurity practices.

I serve in leadership roles across multiple OWASP initiatives including AI Exchange, AIBOM (AI Bill of Materials), Serverless Top Ten Project, CRA, GenAI Lead Author as well as IEEE Next Gen Cyber Security. As a distinguished board advisor across many security and AI companies, Angel Investor and limited partner in several venture capital firms specializing in cybersecurity, I provide strategic direction to startups and established organizations navigating the complex intersection of security and AI. I’m also an active member of InfraGard in the NY Metro Chapter.

I leverage my credentials—including CISSP, C-CISO, GCISO, AWS, and Kubernetes—to bridge technical excellence with business strategy. I have a proven record of building communities around topics relevant to Cyber Security and AI, believing deeply in making security accessible and actionable for all.

CEO at DistributedApps.ai

Ken Huang is a prolific author and renowned expert in AI and Web3, with numerous published books spanning business and technical guides as well as cutting-edge research. He is a Research Fellow and Co-Chair of the AI Safety Working Groups at the Cloud Security Alliance, Co-Chair of the OWASP AIVSS project, and Co-Chair of the AI STR Working Group at the World Digital Technology Academy. He is also an Adjunct Professor at the University of San Francisco, where he teaches a graduate course on Generative AI for Data Security.

Huang serves as CEO and Chief AI Officer (CAIO) of DistributedApps.ai, a firm specializing in generative AI-related training and consulting. His technical leadership is further reflected in his role as a core contributor to OWASP’s Top 10 Risks for LLM Applications and his participation in the NIST Generative AI Public Working Group.

Key Books:

– Securing AI Agents: Foundations, Frameworks, and Real-World Deployment , Springer, October, 2025

– Agentic AI: Theories and Practices – Springer, July 2025

– LLM Design Patterns – Packt, May 2025

– Beyond AI: ChatGPT, Web3, and the Business Landscape of Tomorrow -Springer, 2023

– Generative AI Security: Theories and Practices -Springer, 2024)

– Practical Guide for AI Engineers (Volumes 1 and 2 by DistributedApps.ai, 2024)

– The Handbook for Chief AI Officers: Leading the AI Revolution in Business -DistributedApps.ai, 2024

– Web3: Blockchain, the New Economy, and the Self-Sovereign Internet – Cambridge University Press, 2024)

– Web3 Applications Security and New Security Landscape: Theories and Practices -Springer, 2024

– Blockchain and Web3: Building the Cryptocurrency, Privacy, and Security Foundations of the Metaverse (Wiley, 2023)

A globally sought-after speaker, Ken has presented at events hosted by RSA, OWASP, ISC2, Davos WEF, ACM, IEEE, Consensus, the CSA AI Summit, the Depository Trust & Clearing Corporation, and the World Bank.

Stay in the Know, No Smoke and Mirrors – Join Our Newsletter

You can skip this ad in 5 seconds