Hero guide: Security Automation for Builders
A curated guide by Rossana Suarez, AWS Container Hero, tailored for developers, DevSecOps professionals, and cloud builders. Learn how to integrate security into the development lifecycle with AI-powerd tools and automation strategies.

Engineer
naranjax
This guide is specifically designed for developers and DevSecOps professionals who are looking to implement security early in their development processes. As cloud infrastructure evolves, integrating security seamlessly into the development pipeline is crucial. In this guide, I’ve selected sessions from AWS re:Inforce 2025 that will help you enhance security automation, leverage generative AI for rapid incident response, and optimize compliance practices. These sessions focus on practical, hands-on approaches to building secure, compliant cloud systems. Whether you're automating incident response or enhancing your CI/CD pipelines, these sessions are tailored to address the challenges builders face in securing applications at scale.
Generative AI for Cloud Security
Generative AI is revolutionizing cloud security by speeding up incident response and automating manual security operations. This section focuses on how AI can be used to protect your applications and ensure compliance with minimal human intervention.
This session demonstrates how to reduce recovery time after security incidents by using AWS native generative AI services. Perfect for developers and DevSecOps professionals looking to automate and streamline incident response processes.
Shows how to leverage Amazon Q Developer for intelligent compliance checks and automated remediation workflows, ideal for those focused on maintaining regulatory compliance in cloud development environments.
Learn to use generative AI agents to monitor and control egress traffic, a key aspect of securing cloud infrastructure. This session is ideal for builders integrating AI into their security processes.
Focuses on automating forensics and incident response workflows in EC2 and EKS environments using AWS Security Hub, a must for DevSecOps professionals aiming to optimize security operations.
Advanced Cloud Security Practices
Securing cloud infrastructure involves protecting networks, managing sensitive data, and mitigating risks in AI-driven systems. This section addresses advanced strategies for cloud architects and developers looking to enhance their security posture.
This hands-on session teaches you to build automated security policies as code, a key practice for developers integrating security into CI/CD pipelines. It’s crucial for maintaining secure infrastructure at scale.
Perfect for builders working with multi-account AWS environments, this session shows how to implement secure authentication patterns across your AWS accounts.
Learn how to strengthen security posture using AWS CloudHSM, a critical skill for developers working with sensitive data and cryptographic keys in cloud environments.
This session covers the best practices for securing AI-powered systems using AWS governance services, crucial for building secure and compliant AI applications.
Automating Compliance & Governance
Compliance is a critical aspect of cloud security. This section highlights how to integrate automated compliance checks and governance workflows into your CI/CD pipelines for secure cloud operations.
Perfect for builders who need to streamline compliance processes using AWS tools like AWS Artifact, AWS Config, and AWS Audit Manager. This session helps integrate compliance into automated CI/CD pipelines.
Focuses on creating continuous compliance monitoring solutions, combining generative AI with AWS Config to automate compliance checks, a must for cloud architects.
Learn to build a security log pipeline using the Open Cybersecurity Schema Framework (OCSF), essential for threat detection in cloud environments and for developers working with large-scale security data.
This session teaches how to use AWS GuardDuty for ransomware detection in Amazon S3, an important session for cloud builders who want to protect their cloud storage systems.
Closing comments