SecAppDev 2025 Faculty
Avi Douglen
CEO and Application Security Specialist, OWASP Board of Directors, Bounce Security & OWASP
Avi Douglen has been building secure applications for decades, and is *obsessed* with maximizing value output from security efforts. Avi is the founder and CEO of Bounce Security, a boutique consulting agency dedicated to helping developers integrate security efficiently into their workflows. He is a frequent speaker, keynote, and trainer, and has trained thousands of developers to build more secure products. AviD is an active contributor to open source communities, including leading the OWASP Israel chapter, creating the popular AppSecIL security conference, co-founding the OWASP Threat Modeling project, and currently serving on the OWASP Global Board of Directors. He is also a community moderator on Security StackExchange, and co-authored the Threat Modeling Manifesto.
Don't miss out on SecAppDev!
Grab your seat nowGet out of your Bubble: Collaborative Threat Modeling
Deep-dive lecture by Avi Douglen in room Lemaire
Tuesday June 3th, 16:00 - 17:30
Threat modeling by yourself is great - noone is there to tell you you're wrong. But if you want to discover nontrivial issues, the ones you'd not have on your checklist, you'll need to engage with others. But too often we chase them away.
Key takeaway: Threat modeling is not JUST a technical activity, and should intentionally leverage social techniques to maximize stakeholders participation.
Value Driven Security - A Roadmap to Business Alignment
Introductory lecture by Avi Douglen in room West Wing
Wednesday June 4th, 14:00 - 15:30
Much of security today is generic best practices and checkbox olympics. Shame to waste resources on stuff noone really cares about! Better to map out the business' value streams, and invest efforts in protecting what is actually important.
Key takeaway: Strategic planning requires understanding your environment, your goals, and your challenges. Value-driven mapping techniques help you get there.
No Size Fits All: Customized Application Security Tests
One-day workshop by Avi Douglen in room West Wing
Thursday June 5th, 09:00 - 17:30
The interesting, important, and hard to find bugs are not generic. They often stem from unique business logic, so they require familiarity with the product.
Instead of getting frustrated with generic scans that barely find obvious problems and flood you with false positives, you can run custom checks that find what you care about. In this course, you'll learn how to take your internal knowledge and write custom, tailored scans that will work for you, across the whole codebase.
You’ll leave the course with clear understanding how to customize automated security tests for your code efficiently.
Learning goal: Learn how to find subtle, non-generic bugs in your code, make the most of open-source scanners, and set up smart security guardrails—all with practical techniques that fit into real-world development workflows.