SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals


Speakers:
Sunil Agrawal, CISO—Glean
Daniel Bardenstein, CEO & Co-Founder—Manifest
Harry Thomas, CTO & Co-Founder—Frenos
Ismael Valenzuela, VP Labs, Threat Research & Intelligence—Arctic Wolf | Author & Senior Instructor—SANS
More Speakers to be Announced
This workshop introduces participants hands-on to the security of AI systems, using the OWASP AI Exchange (owaspai.org) as a framework. Attendees will gain insight through hacking labs how modern AI architecture operates, how it can be attacked, and how to secure them in real-world deployments. The workshop covers threats to LLMs and to conventional machine learning models, covering critical risks such as prompt injection, sensitive data leakage, model and data poisoning, supply chain threats, vector database vulnerabilities, excessive agent behavior, system prompt exposure, misinformation, and resource abuse.
Speakers:
Ferhat Dikbiyik, Ph.D., CTIA, Chief Research & Intelligence Officer—Black Kite
Charles "Chuck" Everette, CISO—City of Fort Lauderdale | vCISO Advisor—Mimic Cyber Solutions
Teri Green, VP of Technology—Elevate Energy
Dr. Ugur Koc, Sr. AI R&D Engineer—Manifest
Sydney Marrone, Head of Threat Hunting—Nebulock
Yaamini Barathi Mohan, VP—Women in Cybersecurity
Marissa Morales-Rodriguez Ph.D., Founder & Technology Security Strategiest—STEMPRISE
Bryant Pickford, Security Specialist Solutions Architect—AWS More Speakers to be Announced
We all want to connect AI to everything and provide it with our data — as long as we can trust it. But how do we secure it? First, we need to understand what can go wrong: we need to identify and understand the threats.
In this immersive, hands-on workshop, participants will use FinBot—an interactive, multi-agent Capture-the-Flag (CTF) platform—to attack and then defend a realistic agentic financial workflow:
Invoice Intake → Validation → Approval → Funds Transfer → Reconciliation
Working in a pre-configured cloud environment (no setup required), attendees will reproduce three high-impact failure modes observed in real-world multi-agent systems:
ASI01 – Agent Goal Hijack
ASI02 – MCP-Driven Indirect Zero-Click (Tool Misuse & Exploitation)
ASI05 – Unexpected Remote Code Execution (RCE)
Modern cyber defenders are inundated with vast volumes of raw threat reports, advisories, technical analyses, incident summaries, and narrative threat write-ups, which are rich in context but unstructured and difficult to operationalize. In this hands-on workshop, participants will learn how to build an AI-augmented threat intelligence platform using a popular data Lakehouse, the free edition of Databricks, that transforms unstructured reports into structured, actionable intelligence and then applies Generative AI features and analytics to extract high-value insights at scale.
Please join us for an In-Person Networking Breakfast. Share stories, make connections, and learn how to make the most of your week in Arlington, VA. Complimentary coffee and breakfast items to be provided. Hope to see you there!