SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals

This SANS@Night talk explores how Application Security is transforming in the age of agentic AI, organized around three practical themes: applying AI to strengthen traditional AppSec tools like SAST, SCA, DAST, and WAF through agentic workflows and reusable skills; securing AI systems themselves, including chatbots, RAG pipelines, single and multi-agent architectures, and MCP servers, with defense in depth controls such as guardrails, prompt spotlighting, and human in the loop approvals; and governing the secure use of vendor AI through structured assessments and trusted agentic coding backed by OWASP standards.
In-Person & Virtual
AI is a major topic of discussion today—and rightfully so. But for those of us in cyber security, it's crucial not only to understand how to use AI for security, but also to recognize the threats targeting AI models, their ecosystems, and how to defend and secure them effectively.
In-Person & Virtual