Conference Description
Key Takeaways
- Virtual conference addressing secure application development, DevSecOps practices, and AI integration challenges
- Designed for software developers, security engineers, DevSecOps practitioners, and technical leaders across technology, fintech, and enterprise IT sectors
- Coverage spans software supply chain security, SBOM implementation, LLM security risks, and non-human identity governance
- Technical sessions explore cloud-native security, code-to-cloud visibility, and AI-powered security analytics
- Sponsorship from Okta, Wiz, and participation from vendors including Snyk, Chainguard, GitGuardian, and Amazon Web Services
Introduction
CodeSecCon 2026 is a virtual conference bringing together software developers, application security professionals, and DevSecOps practitioners to examine how modern applications can be built, secured, and maintained as artificial intelligence becomes increasingly embedded in development workflows. The event addresses a critical inflection point for the industry: organisations must now secure not only their code and infrastructure but also the AI systems they integrate and the expanding attack surface created by cloud-native architectures and complex software supply chains.
About This Event
CodeSecCon 2026 operates as a fully virtual conference featuring expert-led sessions, technical talks, and hands-on workshops. The programme caters to both practitioners seeking implementation guidance and leaders responsible for security strategy. Content spans the full spectrum of application security concerns, from secure coding fundamentals to emerging challenges around large language model security and non-human identity management.
The event draws sponsorship and vendor participation from established players in the security ecosystem. Okta serves as platinum sponsor, with Wiz as gold sponsor. Additional participating organisations include Snyk, Chainguard, Kusari, Amazon Web Services, GitGuardian, BrowserStack, and Microsoft, alongside open-source communities and foundations such as OWASP, CNCF, and OpenSSF.
Securing Applications in the Age of AI Integration
A central theme running through CodeSecCon 2026 is the challenge of integrating AI capabilities into applications without introducing new vulnerabilities or exposing sensitive data. As organisations adopt large language models from providers such as Anthropic and Meta, they face novel security considerations that traditional application security frameworks were not designed to address. LLM hallucinations, prompt injection attacks, and the potential for models to leak training data represent emerging threat vectors that security teams must now account for.
The conference examines AI-powered security analytics as both a defensive tool and a subject requiring its own security controls. This dual perspective reflects the reality that AI is simultaneously transforming how security teams detect and respond to threats while creating new categories of risk that demand specialised expertise.
Software Supply Chain and SBOM Implementation
Software supply chain security has moved from a specialist concern to a board-level priority following high-profile incidents that demonstrated how vulnerabilities in dependencies can cascade through thousands of downstream applications. CodeSecCon 2026 addresses this through sessions on Software Bill of Materials implementation, examining how organisations can gain visibility into the components comprising their applications and respond more rapidly when vulnerabilities are disclosed.
The conference explores code-to-cloud visibility as an operational capability, connecting the dots between source code repositories, build pipelines, container registries, and runtime environments. This end-to-end perspective is essential for organisations operating in cloud-native environments where applications are assembled from numerous open-source components and deployed across distributed infrastructure.
DevSecOps Culture and Collaboration
Beyond technical controls, CodeSecCon 2026 emphasises the cultural and organisational dimensions of application security. Bridging the historical divide between development and security teams remains a persistent challenge, particularly as release cycles accelerate and security must be embedded earlier in the development lifecycle rather than applied as a final gate before deployment.
Sessions address practical approaches to reducing mean time to remediation, a metric that reflects both technical capability and organisational effectiveness. The conference also examines non-human identity governance, an increasingly important concern as service accounts, API keys, and machine identities proliferate across modern application architectures.
Who Should Attend
CodeSecCon 2026 is designed for technical professionals working at the intersection of software development and security. Software developers seeking to write more secure code, application security engineers responsible for vulnerability management, and DevSecOps practitioners building security into CI/CD pipelines will find relevant content throughout the programme. Engineering leaders and solutions architects evaluating security tooling and defining organisational security posture are also well served by the strategic sessions on offer.
The event draws attendees primarily from technology companies, fintech organisations, cloud service providers, and enterprise IT departments where application security is a critical operational concern.

