Loading…
Venue: Software Engineering Institute clear filter
Tuesday, July 21
 

8:30am EDT

Networking Breakfast
Tuesday July 21, 2026 8:30am - 9:00am EDT
Join us for breakfast and start networking with your fellow attendees!
Tuesday July 21, 2026 8:30am - 9:00am EDT
Software Engineering Institute 4301 Wilson Boulevard, Arlington, VA 22203

9:00am EDT

Welcome
Tuesday July 21, 2026 9:00am - 9:15am EDT
Welcome to DevSecOps Days Washington, D.C. 2026!
Speaker
avatar for Hasan Yasar

Hasan Yasar

Technical Director of Rapid Fielding of High Assurance Software Team, Carnegie Mellon University Software Engineering Institute
Hasan Yasar is the Technical Director of the Rapid Fielding of High Assurance Software (previously known as Continuous Deployment of Capability) directorate in the Software Solutions Division (SSD) of the Software Engineering Institute, CMU. Hasan leads an engineering group to enable... Read More →
Tuesday July 21, 2026 9:00am - 9:15am EDT
Software Engineering Institute 4301 Wilson Boulevard, Arlington, VA 22203

9:15am EDT

Keynote: Evolving BOMs to Meet Modern System Metadata Needs
Tuesday July 21, 2026 9:15am - 10:00am EDT
Modern systems are no longer just software and hardware, instead, a wide variety of artifacts—including AI models, data sets, and services—participate in the supply chain, opening many new vectors for exploits. Obtaining and maintaining accurate metadata is going to be key to efficiently managing the intelligence and processes required to keep modern systems safe and secure. This talk will review some of the best practices identified so far, and discuss how ISO/IEC DIS 5962 and future versions of SPDX will help facilitate the collection and analysis of key metadata for systems with safety elements to be managed.
Keynote
avatar for Kate Stewart

Kate Stewart

VP Dependable Embedded Systems, The Linux Foundation
Kate Stewart works with the safety, security and license compliance communities to advance the adoption of best practices into embedded open source projects. Kate was one of the founders of System Package Data eXchange (SPDX) and is currently a technical team co-lead. She has led... Read More →
Tuesday July 21, 2026 9:15am - 10:00am EDT
Software Engineering Institute 4301 Wilson Boulevard, Arlington, VA 22203

10:00am EDT

Build your Castle, Dig your Moat: AI Sovereignty, Provenance and Compliance
Tuesday July 21, 2026 10:00am - 10:30am EDT
Your intelligent application is your castle, and your security practices are the moat that protects it. Inside your castle, you must aim for full visibility into what you’re running and why, with freedom to iterate. Your moat creates your security perimeter, ensuring no proprietary data leaves your castle and enforcing best practices including data provenance, cryptographically signed models, evaluation tools, build pipelines and reproducible environments.

Build on your infrastructure, answer to your requirements, scale on your terms.
Speaker
avatar for Dawn Wages

Dawn Wages

Director Community and Developer Relations, Anaconda, Inc.
Dawn Wages is the Director of Community and Developer Relations at Anaconda, responsible for the most popular Python distribution in the world. She is a software engineer, ethical open source advocate, and community leader who previously served as Chair of the Python Software Foundation. Her... Read More →
Tuesday July 21, 2026 10:00am - 10:30am EDT
Software Engineering Institute 4301 Wilson Boulevard, Arlington, VA 22203

10:30am EDT

Mid-morning Break
Tuesday July 21, 2026 10:30am - 10:45am EDT
Get a refresher on your coffee and rejoin the session!
Tuesday July 21, 2026 10:30am - 10:45am EDT
Software Engineering Institute 4301 Wilson Boulevard, Arlington, VA 22203

10:45am EDT

Zero Trust, DevSecOps, AI, and Ecosystem Architectures
Tuesday July 21, 2026 10:45am - 11:30am EDT
The presentation will cover the evolving posture of DevSecOps in the context of Zero Trust as a core capability of the upcoming update to the Zero Trust Reference Model. It will also cover the evolving role of DevSecOps in the context of ecosystem architectures and touch on the SCRM implications. It will also cover the role of Zero Trust and DevSecOps in the context AI, especially focusing on LLMs, Agentic, Machine Learning and embodied intelligence.
Speaker
avatar for Nikhil Kumar

Nikhil Kumar

President and Founder, ApTSi (Applied Technology Solutions, Inc.)
Nikhil is President and Founder of ApTSi (Applied Technology Solutions, Inc.) a visionary organization creating the future of technology solutions. Nikhil has been actively involved in setting the strategy, vision, and direction of enterprise cybersecurity architectures for over 3... Read More →
Tuesday July 21, 2026 10:45am - 11:30am EDT
Software Engineering Institute 4301 Wilson Boulevard, Arlington, VA 22203

11:30am EDT

Tooling for Air-Gapped K8s: An Overview of Solutions
Tuesday July 21, 2026 11:30am - 12:00pm EDT
Container orchestration in air-gapped environments has been a technical barrier slowing its adoption in highly regulated industries. In this talk we'll discuss a basic solution to achieve moving resources (like Helm Charts, OCI Images, etc.) to show the "old school" method, then transition to discussion of two open-source projects that vastly improve the experience of managing platforms in the disconnected network. We'll discuss the differences
between the two and use cases for each.
Speaker
avatar for Patrick Earl

Patrick Earl

DevOps Engineer, Carnegie Mellon University Software Engineering Institute
Patrick joined the SEI as an Associate DevOps Engineer with the Rapid Fielding of High Assurance Software (previously known as Continuous Deployment of Capability) directorate in May of 2022. Previously he worked as a CS/IT instructor at Kutztown University of PA for three years teaching undergraduate information technology/programming courses. Topics included C++, Python, Linux Systems Administration, and Computer Networking.Patrick mainly focuses on working with Kubernetes in limited connectivity environments on-prem (RKE2, K3S, OpenShift... Read More →
avatar for Jeffrey Hamed

Jeffrey Hamed

Senior DevOps Software Engineer, Carnegie Mellon University Software Engineering Institute
Jeffrey Hamed is a member of the technical staff at the Software Engineering Institute. In his time here he has worked as a Forensic Video Analyst and Software Engineer. In his current role as a DevSecOps Engineer he provides SEI customers with technical expertise by delivering custom... Read More →
Tuesday July 21, 2026 11:30am - 12:00pm EDT
Software Engineering Institute 4301 Wilson Boulevard, Arlington, VA 22203

12:00pm EDT

Lunch Break
Tuesday July 21, 2026 12:00pm - 12:45pm EDT
Lunch for all attendees
Tuesday July 21, 2026 12:00pm - 12:45pm EDT
Software Engineering Institute 4301 Wilson Boulevard, Arlington, VA 22203

12:45pm EDT

Keynote: The Right Side of DevSecOps: The Safety Dilemma Beyond Shift-Left
Tuesday July 21, 2026 12:45pm - 1:30pm EDT
DevSecOps transformed how we build software. Security entered the development pipeline, controls moved closer to engineers, and organizations became better at discovering defects before deployment. But while security moved left, production kept moving—becoming faster, more automated, more interconnected, and increasingly difficult for any individual or team to fully understand.

Many of the most consequential hazards emerge after deployment, where real traffic, hidden dependencies, operational tooling, human judgment, automation, and customer demand collide. Architecture diagrams describe work as imagined, while engineers and operators continually adapt to work as done. The rise of AI agents further expands this runtime gap as agents begin participating in diagnosis, decision-making, and operational action. When humans and agents hold different assumptions about system state, scope, evidence, or recovery, ordinary work can create customer harm at machine speed.

This session introduces Operational Safety Engineering, a discipline focused on preventing customer harm whether the cause is malicious, accidental, or the result of system complexity. Drawing on safety science, resilience engineering, human factors, chaos engineering, AI safety, and experience operating hyperscale cloud services, Aaron Rinehart will show how teams can investigate complex systems in production, surface hidden hazards through novel instrumentation, develop deeper learning from high-severity incidents, and establish safe operating expectations for human–AI workflows.

Attendees will learn how to extend DevSecOps into the live system, identify complexity-shaped hazards that traditional security and reliability practices may miss, and design cloud services—and the AI agents operating within them—to fail safely while limiting customer harm. Security moved left. Now our learning must move into production.
Keynote
avatar for Aaron Rinehart

Aaron Rinehart

Global Leader of Cloud & AI Safety Engineering, Oracle
Aaron Rinehart leads Oracle’s Cloud & AI Safety organization delivering a durable operational engineering safety framework for the company.

Aaron’s focus is outcome over intent: reducing undesirable results and uncertainty in Oracle’s products and services by turning learning into repeatable mechanisms, tooling, and operational practices. At Oracle, he has helped establish Operational Engineering Safety as a first-class... Read More →
Tuesday July 21, 2026 12:45pm - 1:30pm EDT
Software Engineering Institute 4301 Wilson Boulevard, Arlington, VA 22203

1:30pm EDT

Prevent-Govern-Prove: On Time, On Budget Mission Software Development
Tuesday July 21, 2026 1:30pm - 2:00pm EDT
  1. Software supply chain risk is no longer a periodic audit exercise—it is a primary driver of rework, schedule slips, and degraded mission readiness. As government organizations and their industry partners strive to deliver software faster while navigating increasingly complex threats and software ecosystems, teams need practical controls that improve delivery predictability without slowing development.

In this session, Thomas Tapley, Product Manager at Sonatype, explains how leading organizations are moving from disconnected point solutions to an integrated software supply chain management approach that spans the full software development lifecycle.

Attendees will learn a practical operating model to:
Prevent malicious or high-risk components from entering development environments through controlled intake and pre-use protections.
Govern component selection with automated, policy-driven enforcement across developer workflows, CI/CD pipelines, and release processes.
Prove software readiness through continuously updated SBOMs and real-time visibility into software supply chain risk.

Using real-world examples and lessons learned, this session demonstrates how organizations can reduce costly rework, respond more quickly to newly disclosed vulnerabilities, and deliver mission software on time and on budget—without sacrificing security, developer productivity, or operational resilience.
Speaker
avatar for Tom Tapley

Tom Tapley

Product Manager, Federal Programs, Sonatype
Tom Tapley specializes in securing software supply chains for Federal environments, bringing deep expertise in aligning agency security, compliance, and operational requirements with modern technology solutions. With a proven track record in supporting mission-critical systems, he... Read More →
Tuesday July 21, 2026 1:30pm - 2:00pm EDT
Software Engineering Institute 4301 Wilson Boulevard, Arlington, VA 22203

2:00pm EDT

Mid-afternoon Break
Tuesday July 21, 2026 2:00pm - 2:15pm EDT
Take a short break and get ready for the last few sessions
Tuesday July 21, 2026 2:00pm - 2:15pm EDT
Software Engineering Institute 4301 Wilson Boulevard, Arlington, VA 22203

2:15pm EDT

Presentation
Tuesday July 21, 2026 2:15pm - 2:45pm EDT
Coming soon!
Tuesday July 21, 2026 2:15pm - 2:45pm EDT
Software Engineering Institute 4301 Wilson Boulevard, Arlington, VA 22203

2:45pm EDT

Wrap Up and Adjourn
Tuesday July 21, 2026 2:45pm - 3:00pm EDT
Wrap-up of the day's sessions
Speaker
avatar for Hasan Yasar

Hasan Yasar

Technical Director of Rapid Fielding of High Assurance Software Team, Carnegie Mellon University Software Engineering Institute
Hasan Yasar is the Technical Director of the Rapid Fielding of High Assurance Software (previously known as Continuous Deployment of Capability) directorate in the Software Solutions Division (SSD) of the Software Engineering Institute, CMU. Hasan leads an engineering group to enable... Read More →
Tuesday July 21, 2026 2:45pm - 3:00pm EDT
Software Engineering Institute 4301 Wilson Boulevard, Arlington, VA 22203
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.