Conference Description
Key Takeaways
- Israel’s largest application security conference, organized by OWASP and attracting over 1,000 attendees
- Covers secure software development, DevOps and cloud security, web/mobile/API protection, threat modeling, and risk management
- Features technical deep dives, hands-on workshops, and real-world case studies
- Designed for security professionals, developers, DevOps engineers, architects, and product leaders
- Community-driven event with no ticket sales, supported entirely by sponsorship
About the Event
OWASP AppSec Israel 2026 is the country’s premier application security conference, organized by the Open Web Application Security Project. The event takes place at Tel Aviv Expo, Pavilion 10, and draws over 1,000 professionals from technology companies, startups, enterprises, government, and academia. As a community-driven conference, it operates without ticket sales and relies on sponsorship to remain accessible to all attendees.
The conference supports OWASP’s broader mission of providing free, vendor-neutral, and practical security guidance. Programming includes technical sessions, hands-on workshops, and networking opportunities. The venue is family-friendly and wheelchair accessible.
Core Technical Topics
The conference agenda addresses security challenges across the software development lifecycle. Key subject areas include:
- Secure software development: Integrating security practices into development workflows from design through deployment
- DevOps and cloud security: Managing risks in modern infrastructure and continuous delivery pipelines
- Web, mobile, and API security: Protecting application interfaces and endpoints from evolving threats
- Threat modeling: Systematic approaches to identifying and prioritizing security risks
- Risk management: Frameworks for assessing and mitigating organizational security exposure
Sessions combine technical deep dives with real-world case studies, allowing attendees to learn from practical implementations rather than theoretical concepts alone.
Who Should Attend
The conference serves a broad range of roles involved in building and securing software. Security specialists and cyber defense professionals will find content addressing current threats and defensive techniques. Developers and software engineers can learn how to embed security into their daily work. DevOps engineers and architects benefit from sessions on securing cloud environments and infrastructure.
Product leaders and executives gain insight into security strategy and organizational risk, while researchers can engage with the latest developments in application security. The event bridges technical practitioners and decision-makers, making it relevant for those responsible for both implementation and governance.

