Agentic Development and the Evolution of DevSecOps - Ken Toler - Cyber Smokehouse - Episode #28
#28

Agentic Development and the Evolution of DevSecOps - Ken Toler - Cyber Smokehouse - Episode #28

Take your application security strategy to the next level with powerful insights on securing fast-paced agentic development, navigating abstracted SaaS platforms, and bridging the gap between engineers and security teams. It’s time to move past rigid no-saying, embrace "vibe coding" as a shared collaborative workspace, and build resilient security systems that stand the test of time. Who better to guide you through it than DevSecOps podcast host, blockchain application security expert, and Founder & Managing Principal Consultant at Asgard Security, Ken Toler?

You will learn how AI-driven tools are accelerating threat modeling and supply chain management, why abstracted "squishy middle" infrastructure presents new attack vectors, and how to foster a curious, error-friendly engineering culture. Get motivated to enable your developers, simplify system abstractions, and build collaborative bridges across your entire organization!

Takeaways:

  • The Pace of Agentic Development: AI tools and agentic development aren't changing core security fundamentals; rather, they are accelerating execution and making practices like threat modeling and supply chain fixes faster to implement.
  • Preserving Systems Thinking: While AI lowers barriers to coding, engineers and security teams must still maintain deep reading and architectural comprehension to diagnose complex system vulnerabilities.
  • The Danger of the "Squishy Middle": Modern abstracted platforms (like Replit or Lovable) consolidate credentials and environment variables into shared SaaS infrastructure, creating lucrative targets for attackers.
  • Embracing Citizen Developers & "Vibe Coding": When non-technical departments prototype apps using AI, security and engineering teams should engage collaboratively rather than dismissively to build organizational alignment.
  • Enabling Over Blocking: Security leaders thrive by finding creative, positive ways to enable business goals securely instead of being the transactional "no guy".

Quote of the Show:

"I've gotten so much further figuring out how to enable people securely rather than trying to tell people why they are insecure. Nobody wants to talk to the angry security guy." - Ken Toler


Links:

Ways to Tune In: