275 sessions
- Lightning talk300 - AdvancedThreat Detection and Incident ResponseDevSecOpsSecurity AnalyticsThreat IntelligenceCloud Security SpecialistDevOps EngineerIT AdministratorTuesday, Jun 171:00 p.m. Tuesday, Jun 17SOC analysts are drowning in alerts - an average of 4,484 alerts per day, with 67% routinely ignored as noise. This session offers a battle-tested playbook for alert noise reduction. We discuss methods to systematically tune out false positives, consolidate redundant alarms, and apply risk-based filtering so that high-fidelity alerts rise to the top. Real examples illustrate how adding context (asset criticality, threat intel) and leveraging automation can transform an alert avalanche into a manageable stream of insights. This presentation is brought to you by Graylog, an AWS Partner.Session Type: Lightning talkLevel: 300 - AdvancedTrack: Threat Detection and Incident Response
- Lightning talk200 - IntermediateThreat Detection and Incident ResponseAutomationThreat IntelligenceAWS Security Hub8:00 a.m. Tuesday, Jun 17Tuesday, Jun 17In this session, Tines will demonstrate how security teams can transform their alert response capabilities through intelligent workflow orchestration and automation. We'll showcase how organizations can harness Tines to automatically triage, enrich, and remediate AWS Security Hub alerts - significantly reducing mean time to resolution while enabling security teams to focus on strategic priorities. With Tines, organizations can enhance visibility, improve response consistency, and accelerate remediation of critical AWS Security Hub findings. This presentation is brought to you by Tines, an AWS Partner.Session Type: Lightning talkLevel: 200 - IntermediateTrack: Threat Detection and Incident Response
- Builders' session300 - AdvancedApplication SecurityGenerative AIAgentic AICloud Security SpecialistDeveloper / EngineerSolution / Systems ArchitectAmazon BedrockCross-Industry Solutions1:00 p.m. Monday, Jun 16Monday, Jun 16Step into the shoes of an AI-powered red team adversary in the GenAI Red Team Challenge. In this intensive workshop, you'll deploy an AI security agent to orchestrate sophisticated threat chains against GenAI applications, systematically discovering and exploiting vulnerabilities from prompt injection to boundary testing while mastering automated security testing workflows. In addition, you’ll learn to apply countermeasures, from prompt templating to guardrails. This hands-on, gamified experience helps you think like a threat actor and equips you with practical skills in automated vulnerability testing and risk mitigation against common MITRE and OWASP vulnerabilities for LLM-based applications. You must bring your laptop to participate.Session Type: Builders' sessionLevel: 300 - AdvancedTrack: Application Security
- Builders' session300 - AdvancedApplication SecurityGenerative AIAgentic AICloud Security SpecialistDeveloper / EngineerSolution / Systems ArchitectAmazon BedrockCross-Industry SolutionsWednesday, Jun 182:00 p.m. Wednesday, Jun 18Step into the shoes of an AI-powered red team adversary in the GenAI Red Team Challenge. In this intensive workshop, you'll deploy an AI security agent to orchestrate sophisticated threat chains against GenAI applications, systematically discovering and exploiting vulnerabilities from prompt injection to boundary testing while mastering automated security testing workflows. In addition, you’ll learn to apply countermeasures, from prompt templating to guardrails. This hands-on, gamified experience helps you think like a threat actor and equips you with practical skills in automated vulnerability testing and risk mitigation against common MITRE and OWASP vulnerabilities for LLM-based applications. You must bring your laptop to participate.Session Type: Builders' sessionLevel: 300 - AdvancedTrack: Application Security
- Lightning talk300 - AdvancedApplication SecurityAutomationAgentic AICloud Security SpecialistAWS Security HubTuesday, Jun 1712:00 p.m. Tuesday, Jun 17AI agents are redefining how we approach enterprise cybersecurity and engineering work. Not very far into the future, AI Agents will work tirelessly to triage and remediate common security issues without human intervention. In this session, we’ll explore what AI Agents are and what challenges they need to overcome to become truly autonomous in a complex enterprise environment. To put theory to practice, we will provide a real security issue to a few AI Agents to see if they can actually remediate a cloud security issue - will they make it? Will you trust it? This presentation is brought to you by Backline, an AWS Partner.Session Type: Lightning talkLevel: 300 - AdvancedTrack: Application Security
- Builders' session300 - AdvancedData ProtectionWell-Architected FrameworkAutomationDevSecOpsCloud Security SpecialistDevOps EngineerSolution / Systems ArchitectAmazon EventBridgeAWS Key Management Service (AWS KMS)AWS Secrets ManagerCross-Industry SolutionsFinancial ServicesGovernment2:00 p.m. Monday, Jun 16Monday, Jun 16Ever wondered how tech giants protect their crown jewels in the cloud? Attend this cutting-edge session to unlock the vault of industry-leading practices using AWS Secrets Manager's latest features. Journey through real-world scenarios mastering automated rotation, encryption at rest, access control, replication, intelligent caching and security incidents. You'll craft a robust secrets fortress using AWS Secrets Manager, AWS KMS, AWS Lambda, Amazon EventBridge, and AWS Config that scales with your applications. Transform your security posture and reduce operational overhead while meeting enterprise compliance requirements in the cloud age. You must bring your laptop to participate.Session Type: Builders' sessionLevel: 300 - AdvancedTrack: Data Protection
- Builders' session300 - AdvancedData ProtectionWell-Architected FrameworkAutomationDevSecOpsCloud Security SpecialistDevOps EngineerSolution / Systems ArchitectAmazon EventBridgeAWS Key Management Service (AWS KMS)AWS Secrets ManagerCross-Industry SolutionsFinancial ServicesGovernmentWednesday, Jun 1811:00 a.m. Wednesday, Jun 18Ever wondered how tech giants protect their crown jewels in the cloud? Attend this cutting-edge session to unlock the vault of industry-leading practices using AWS Secrets Manager's latest features. Journey through real-world scenarios mastering automated rotation, encryption at rest, access control, replication, intelligent caching and security incidents. You'll craft a robust secrets fortress using AWS Secrets Manager, AWS KMS, AWS Lambda, Amazon EventBridge, and AWS Config that scales with your applications. Transform your security posture and reduce operational overhead while meeting enterprise compliance requirements in the cloud age. You must bring your laptop to participate.Session Type: Builders' sessionLevel: 300 - AdvancedTrack: Data Protection
- Meetup4:00 p.m. Monday, Jun 16Monday, Jun 16Join AWS Women of the Cloud, Women in Security, and Women at AWS for an informal meetup prior to the "Women of the Cloud networking reception" event. At 4:30pm, attendees will gather in a group and walk together to the Expo for the Women of the Cloud networking reception event (approx. 15 minute walk). All are welcome.Session Type: Meetup
- Lightning talk200 - IntermediateCloud Security SpecialistIT ExecutiveSolution / Systems ArchitectAmazon BedrockTuesday, Jun 173:00 p.m. Tuesday, Jun 17AI security is a top priority for AWS. By building AI solutions that are secure by design, AWS helps customers innovate quickly with confidence while mitigating emerging threats. But securing AI goes beyond individual organizations - it requires industry-wide standards and best practices. AWS actively contributes to global AI security efforts, including its participation industry standards bodies such as CoSAI (The Coalition for Secure AI), to make sure AI technologies are safe, resilient, and trustworthy. This session will explore how AWS is leading AI security innovation, protecting customers, and collaborating to help shape the future of AI security for the entire industry.Session Type: Lightning talkLevel: 200 - Intermediate
- Workshop300 - AdvancedNetwork and Infrastructure SecurityResilience9:00 a.m. Wednesday, Jun 18Wednesday, Jun 18Learn how to protect your applications from Distributed Denial of Service (DDoS) attacks. In this hands-on workshop, you will learn how to implement protection methodologies for web applications against DDoS events using AWS security services. Practice configuring DDoS resilience patterns and learn how to respond effectively to attacks. This session is ideal for builders who manage web applications, content delivery network (CDN) configurations, web application firewalls (WAF), and security controls. You must bring your laptop to participate.Session Type: WorkshopLevel: 300 - AdvancedTrack: Network and Infrastructure Security
- Community activities4:00 p.m. Monday, Jun 16Monday, Jun 16Join AWS Women of the Cloud, Women in Security, and Women at AWS as this reception brings together women and allies from various sectors and backgrounds attending AWS re:Inforce, offering a unique opportunity to network, share best practices, and cultivate a supportive community. The event offers a come-and-go format, providing flexibility for attendees. All are welcome.Session Type: Community activities
- Breakout session200 - IntermediateApplication SecurityGenerative AIDevSecOpsContainer/Serverless SecurityTuesday, Jun 171:00 p.m. Tuesday, Jun 17Cloud native applications have scaled to levels never seen before. New DevOps workflows, modern tech stacks, and the use of GenAI are dramatically changing how applications are built and deployed, all while risks abound. In this session, Orca Security has unpacked a wealth of cloud datapoints to get a special glimpse into data exposure, infrastructure misconfigurations risks, GenAI concerns, and more. Attendees will get a front-row-seat into the data while learn how they can improve their overall level of cloud security. This presentation is brought to you by Orca Security, an AWS Partner.Session Type: Breakout sessionLevel: 200 - IntermediateTrack: Application Security
- Innovation talk200 - IntermediateTuesday, Jun 1712:00 p.m. Tuesday, Jun 17The best security empowers organizations to move faster and innovate with confidence. In this session, we'll explore how AWS is built end-to-end to handle the undifferentiated heavy lifting of security on behalf of our customers and how we safeguard your organization’s most valuable assets. You'll learn how our substantial investments in security translate into tangible benefits for your organization. We'll share how our enduring commitment to solving complex security challenges allows you to focus on what matters most: innovation and supporting your mission. Whether you're beginning your cloud journey or seeking to enhance your existing security posture, this session will illuminate how AWS foundational security capabilities help organizations of all sizes build and operate with confidence in an increasingly complex digital landscape.Session Type: Innovation talkLevel: 200 - Intermediate
- Community activities8:00 a.m. Tuesday, Jun 17Tuesday, Jun 17Drop by to create DASH Kits for I Support the Girls, supporting individuals in the Philadelphia community.Session Type: Community activities
- Community activities4:00 p.m. Monday, Jun 16Monday, Jun 16Drop by to create DASH Kits for I Support the Girls, supporting individuals in the Philadelphia community.Session Type: Community activities
- Lightning talk100 - FoundationalThreat Detection and Incident ResponseCulture of SecuritySecurity AnalyticsThreat IntelligenceCloud Security SpecialistSolution / Systems ArchitectTech ExplorerCross-Industry SolutionsFinancial Services8:00 a.m. Tuesday, Jun 17Tuesday, Jun 17Your security tools are now part of the attack surface. As adversaries evolve, they’re no longer bypassing defenses - they’re exploiting them directly. This shift has redefined the boundaries of threat exposure. From control planes to misconfigurations, attackers are finding and slipping through cracks in the very infrastructure meant to stop them. This talk explores why traditional models fall short - and what CISOs must do to uncover hidden risk, fortify defenses, and maximize the ROI of their security investments. This presentation is brought to you by Zafran, an AWS Partner.Session Type: Lightning talkLevel: 100 - FoundationalTrack: Threat Detection and Incident Response
- Lightning talk200 - IntermediateWell-Architected FrameworkCulture of SecurityThreat IntelligenceCloud Security SpecialistIT ExecutiveIT Professional / Technical ManagerCross-Industry SolutionsTuesday, Jun 171:00 p.m. Tuesday, Jun 17Discover how inclusive practices can transform your security operations in this lightning talk. Explore real-world examples of how diversity enhances threat detection, incident response, and security innovation. Learn strategies for building inclusive security teams, leveraging employee resource groups, and creating an environment where all voices are heard. Leave with practical frameworks to cultivate a security culture that harnesses the power of diverse perspectives for better security outcomes.Session Type: Lightning talkLevel: 200 - Intermediate
- MeetupTuesday, Jun 173:00 p.m. Tuesday, Jun 17Explore ways to amplify your voice and influence in the security community. Learn about speaking opportunities at conferences, effective approaches to mentoring emerging security leaders, and contributing to open source security projects. Connect with experienced professionals to discuss best practices for knowledge sharing and building your presence as a security thought leader while making meaningful contributions to advance the field.Session Type: Meetup
- Breakout session300 - AdvancedGenerative AICloud Security SpecialistIT ExecutiveSolution / Systems ArchitectAmazon BedrockAmazon SageMakerWednesday, Jun 181:00 p.m. Wednesday, Jun 18Enterprise AI adoption demands robust security. In this session, join Anthropic's head of risk governance along with AWS security leaders to reveal how AWS and Anthropic collaborate to deliver enterprise-grade security for LLMs and the generative AI workloads they enable. Learn about the multi-layered security approach spanning infrastructure, data, and models. We'll explore real-world security architectures, governance frameworks, and risk mitigation strategies. You will leave with a deeper understanding of how to leverage AWS and Anthropic's security capabilities to accelerate your organization's AI initiatives while maintaining stringent security and compliance requirements.Session Type: Breakout sessionLevel: 300 - Advanced
- Lightning talk200 - IntermediateGenerative AITuesday, Jun 173:00 p.m. Tuesday, Jun 17In this session, we will discuss the generative AI security landscape, how customers can build secure AI workloads, what considerations customers need to keep in mind, and what changes with new capabilities, including AI Agents.Session Type: Lightning talkLevel: 200 - Intermediate
- Lightning talk400 - ExpertData ProtectionResilienceProvable SecurityThreat IntelligenceTuesday, Jun 175:00 p.m. Tuesday, Jun 17As attackers weaponize generative AI to scale phishing, deepfakes, and behavioral manipulation, defenders must fight back with smarter AI. This session breaks down real-world adversarial tactics and shows how Mimecast builds AI models to detect and prevent human-layer threats. Learn how we responsibly train models on behavioral data while ensuring transparency, fairness, and privacy. This presentation is brought to you by Mimecast, an AWS Partner.Session Type: Lightning talkLevel: 400 - ExpertTrack: Data Protection
- Lightning talk200 - IntermediateCulture of SecurityBusiness ExecutiveCloud Security SpecialistIT Professional / Technical ManagerAmazon GuardDutyAWS Security Incident ResponseCross-Industry Solutions2:00 p.m. Monday, Jun 16Monday, Jun 16Upskill your developers into security champions without the burden of creating training from scratch. The AWS Security Champion Learning Plan offers a curated learning path that saves organizations significant time and resources. Explore the curriculum's key components, including interactive labs and practical exercises. Learn how to implement this efficient training solution and measure its impact on your team's security capabilities.Session Type: Lightning talkLevel: 200 - Intermediate
- Lightning talk300 - AdvancedGenerative AICloud Security SpecialistDevOps EngineerSolution / Systems ArchitectAmazon BedrockAmazon CognitoAWS Identity and Access Management (IAM)3:00 p.m. Wednesday, Jun 18Wednesday, Jun 18In this session, we will explore the challenges and solutions for managing identities in generative AI workloads. Learn about securing API access for LLMs, implementing proper authentication across AI services, and maintaining data lineage. Learn practical approaches towards securing generative AI applications while maintaining compliance and governance requirements.Session Type: Lightning talkLevel: 300 - Advanced
- Innovation talk200 - IntermediateResilienceTuesday, Jun 171:00 p.m. Tuesday, Jun 17Every day, AWS customers deliver essential services and solutions to every corner of the globe that power economies, governments, critical infrastructure, and more. Even small failures can have outsized impact for these workloads. At AWS, we take the responsibility of providing the cloud for these critical services seriously. In this talk, we’ll explore some of the engineering innovations, operational practices, and organizational lessons learned from nearly two decades of deliberate investment and focus on resilience. These help AWS provide the foundation for the world’s innovation.Session Type: Innovation talkLevel: 200 - Intermediate
- Lightning talk200 - IntermediateResilienceCulture of SecurityCryptography and Post-QuantumCloud Security SpecialistIT Professional / Technical ManagerSolution / Systems ArchitectAerospace & SatelliteCross-Industry SolutionsSoftware & Internet5:00 p.m. Monday, Jun 16Monday, Jun 16Surprises, whether good or bad, often emerge at the intersection of different domains and during the early stages of new technologies, when risks are not yet fully understood. We'll examine historical examples and connect them to today's emerging technologies, such as quantum computing, space exploration, and AI-powered robotics. These advancements are driving us toward a more interconnected world, expanding the potential attack surface. While we're often told that modern problems need modern solutions, we'll discover that the most effective strategies for addressing unknown threats are often the simple, time-tested methods we've known all along. This presentation is brought to you by Accenture, an AWS Partner.Session Type: Lightning talkLevel: 200 - Intermediate
- Lightning talk200 - IntermediateThreat Detection and Incident Response5:00 p.m. Monday, Jun 16Monday, Jun 16Learn how to streamline security operations by routing the right data to Amazon Security Lake. This session explores how to collect, filter, and transform security-relevant data at the edge - before it's sent to the cloud.This presentation is brought to you by Splunk, an AWS Partner.Session Type: Lightning talkLevel: 200 - IntermediateTrack: Threat Detection and Incident Response
- Lightning talk200 - IntermediateThreat Detection and Incident ResponseTuesday, Jun 174:00 p.m. Tuesday, Jun 17With data sprawl and data living in multiple places like Splunk and Amazon Security Lake, it is important for the SOC to get the visibility they need on the data to drive security outcomes to be able to detect threats. This presentation is brought to you by Splunk, an AWS Partner.Session Type: Lightning talkLevel: 200 - IntermediateTrack: Threat Detection and Incident Response
- Code talk400 - ExpertIdentity and Access ManagementGenerative AIAgentic AI4:00 p.m. Monday, Jun 16Monday, Jun 16Generative AI agents run tasks on behalf of human users and often interact with each other across on-premises environments and different cloud providers. This brings new challenges in identity authentication, propagation, delegation, and resource authorization in the overall agentic AI solution. Learn how Amazon Cognito's OAuth2-based identity management, machine-to-machine authentication, combined with Amazon Verified Permissions fine-grained authorization can enable secure delegation patterns for AI agents, while preserving human identity and consent, agent machine identity, and other request context throughout the agent chain. We will walk through real-world examples with agents built on Amazon Bedrock or other frameworks.Session Type: Code talkLevel: 400 - ExpertTrack: Identity and Access Management
- Breakout session200 - IntermediateApplication SecurityDevSecOpsCloud Security SpecialistDevOps EngineerAmazon InspectorCross-Industry SolutionsWednesday, Jun 182:00 p.m. Wednesday, Jun 18As organizations adopt DevSecOps practices, securing both runtime environments and source code is essential. This session highlights the journey Amazon Inspector has taken from traditional compute vulnerability scanning to extending coverage into source code analysis. Discover how this shift-left approach reduces risk, accelerates remediation, and aligns with modern security frameworks.Session Type: Breakout sessionLevel: 200 - IntermediateTrack: Application Security
- Code talk300 - AdvancedApplication SecurityGenerative AIAmazon BedrockAmazon CognitoAWS Cloud Development Kit (AWS CDK)Cross-Industry SolutionsWednesday, Jun 1811:00 a.m. Wednesday, Jun 18When building prototypes and applications with technologies such as generative AI and serverless, it’s critical to move quickly and securely. In this code talk, learn how the AWS prototyping team successfully balances these goals. To meet user demand, AWS builds prototypes over a short amount of time while meeting a high bar for security expectations. Learn pointers, tips, and tricks to build quickly and securely, from threat modeling to using AWS CDK and the help of Generative AI to harden the security of your infrastructure and improve productivity.Session Type: Code talkLevel: 300 - AdvancedTrack: Application Security
- Lightning talk200 - IntermediateGovernance, Risk, and ComplianceGenerative AIDevSecOps10:00 a.m. Wednesday, Jun 18Wednesday, Jun 18The rapid evolution of AI regulations requires careful consideration when implementing business solutions. In this talk, explore how organizations can leverage AWS AI/ML services while adhering to emerging regulatory requirements. Learn practical approaches for developing responsible AI practices, implementing governance frameworks, and driving business value through compliant AI solutions. Discover strategies for balancing innovation with compliance as you scale AI capabilities across your organization.Session Type: Lightning talkLevel: 200 - IntermediateTrack: Governance, Risk, and Compliance
- Breakout session300 - AdvancedThreat Detection and Incident ResponseDevSecOpsCloud Security SpecialistAWS CloudTrailTuesday, Jun 171:00 p.m. Tuesday, Jun 17Join us to learn about modernizing threat detection through Detection as Code and get more value from your security data pipeline. We’ll discuss Detection as Code, data normalization, and the Open Cybersecurity Schema Framework (OCSF). Discover how to implement detection as code, learn the value of a unified data model, and adopt data normalization frameworks. We’ll walk through how Detection as Code brings software engineering practices - like version control, code review, and automated testing - into detection pipelines. This presentation is brought to you by Datadog, an AWS Partner.Session Type: Breakout sessionLevel: 300 - AdvancedTrack: Threat Detection and Incident Response
- Breakout session200 - IntermediateOpen SourceWednesday, Jun 181:00 p.m. Wednesday, Jun 18Getting and managing Transport Layer Security (TLS) certificates is easier than ever, but the web Public Key Infrastructure (PKI) keeps evolving. From short-lived certificates and IP address certs to the end of Online Certificate Status Protocol (OCSP), folks from Let's Encrypt and AWS will talk about what's going on with TLS certificates today, how we got here, and what to look for in the future.Session Type: Breakout sessionLevel: 200 - Intermediate
- Code talk400 - ExpertIdentity and Access ManagementGenerative AIAgentic AITuesday, Jun 174:00 p.m. Tuesday, Jun 17Generative AI agents run tasks on behalf of human users and often interact with each other across on-premises environments and different cloud providers. This brings new challenges in identity authentication, propagation, delegation, and resource authorization in the overall agentic AI solution. Learn how Amazon Cognito's OAuth2-based identity management, machine-to-machine authentication, combined with Amazon Verified Permissions fine-grained authorization can enable secure delegation patterns for AI agents, while preserving human identity and consent, agent machine identity, and other request context throughout the agent chain. We will walk through real-world examples with agents built on Amazon Bedrock or other frameworks.Session Type: Code talkLevel: 400 - ExpertTrack: Identity and Access Management
- Chalk talk200 - IntermediateApplication SecurityGenerative AICloud Security SpecialistDeveloper / EngineerSolution / Systems ArchitectAmazon BedrockAmazon Q BusinessCross-Industry SolutionsWednesday, Jun 184:00 p.m. Wednesday, Jun 18You've identified your generative AI use case, tested it and are creating a secure application architecture design. How do you know what generative AI specific threats you should be protecting against, and what tools or services are available that can help? You may have heard of the OWASP Top 10 for LLM Applications, but where or how do you start? Join us as we discuss the OWASP Top 10 threats, the differences between versions, and how AWS can help you mitigate these threats.Session Type: Chalk talkLevel: 200 - IntermediateTrack: Application Security
- Lightning talk200 - IntermediateAutomationCulture of SecuritySecurity AnalyticsCloud Security SpecialistIT ExecutiveSolution / Systems ArchitectAmazon GuardDutyAWS OrganizationsAWS Security HubCross-Industry SolutionsProfessional ServicesSoftware & InternetTuesday, Jun 175:00 p.m. Tuesday, Jun 17Discover how AWS is evolving its approach to validating security partners to meet increasingly sophisticated customer needs. Learn about enhanced validation requirements that help customers identify partners with demonstrated expertise in critical security domains. See how AWS native services and validated partner solutions work together to deliver comprehensive security outcomes in today's dynamic threat landscape.Session Type: Lightning talkLevel: 200 - Intermediate
- MeetupIdentity and Access ManagementAgentic AI2:00 p.m. Tuesday, Jun 17Tuesday, Jun 17Join peers to discuss evolving IAM challenges in a world of AI agents, automated workloads, and human users. Share approaches for implementing least-privilege access, managing machine identities, and securing service-to-service authentication. Exchange experiences with modern identity tools like AWS IAM Identity Center, Cognito, and Verified Permissions. Learn how organizations are adapting their IAM strategies for AI/ML workloads while maintaining security and compliance.Session Type: MeetupTrack: Identity and Access Management
- Lightning talk200 - IntermediateGovernance, Risk, and Compliance2:00 p.m. Tuesday, Jun 17Tuesday, Jun 17Toni de la Fuente, creator and CEO of Prowler will debut Prowler’s AI‑powered features - designed to predict misconfigurations, unify compliance workflows, and prescribe fixes in real time. If you’re ready to break free from reactive scans and architect continuous, predictive hardening on AWS, this session is your roadmap. This presentation is brought to you by Prowler, an AWS Partner.Session Type: Lightning talkLevel: 200 - IntermediateTrack: Governance, Risk, and Compliance
- Lightning talk300 - AdvancedThreat Detection and Incident ResponseGenerative AIAutomationAgentic AITuesday, Jun 173:00 p.m. Tuesday, Jun 17We stand at the dawn of a new security paradigm where autonomous systems on both sides of the battlefield are changing the dynamics of attack and defense. Drawing on recent Google Threat Intelligence findings, this session reveals how nation-state actors and cybercriminals are already weaponizing AI while showcasing how defensive AI agents can create self-improving security systems. Learn how the constraints of cost, latency, and efficacy are shaping this machine-vs-machine future, and discover how autonomous agents and domain-specific languages enable a continuous feedback loop to rapidly strengthen defenses. This presentation is brought to you by Sublime Security, an AWS Partner.Session Type: Lightning talkLevel: 300 - AdvancedTrack: Threat Detection and Incident Response
- Breakout session200 - IntermediateGenerative AIWednesday, Jun 1811:00 a.m. Wednesday, Jun 18Explore how the evolving threat landscape impacts AI applications in AWS. As AI usage and app development introduces new components like models, plugins, and datasets that access sensitive data, each element presents unique risks for attackers to exploit. Discover how Palo Alto Networks helps you manage these risks throughout the AI ecosystem. In this session, see how these solutions provide granular access control to 3rd party services and protect your entire AI stack - data, supply chain, applications, and runtime - ensuring your environments are secure and resilient to attacks. We’ll also showcase how our platform, powered by Precision AI, prevents polymorphic threats. This presentation is brought to you by Palo Alto Networks, an AWS Partner.Session Type: Breakout sessionLevel: 200 - Intermediate
- MeetupIdentity and Access ManagementAgentic AIWednesday, Jun 182:00 p.m. Wednesday, Jun 18Join peers to discuss evolving IAM challenges in a world of AI agents, automated workloads, and human users. Share approaches for implementing least-privilege access, managing machine identities, and securing service-to-service authentication. Exchange experiences with modern identity tools like AWS IAM Identity Center, Cognito, and Verified Permissions. Learn how organizations are adapting their IAM strategies for AI/ML workloads while maintaining security and compliance.Session Type: MeetupTrack: Identity and Access Management
- Breakout session300 - AdvancedThreat Detection and Incident ResponseResilienceCross-Industry SolutionsMonday, Jun 1610:00 a.m. Monday, Jun 16Enhance your threat detection capabilities by leveraging Amazon GuardDuty Extended Threat Detection alongside MITRE frameworks. In this session, Shane Steiger from MITRE Corp demonstrates how to effectively identify and respond to multi-stage security events in your AWS environment. Learn practical strategies for implementing detection controls, developing response procedures, and building resilient cloud architectures. Discover how integrating GuardDuty with MITRE frameworks can strengthen your event detection and response strategy.Session Type: Breakout sessionLevel: 300 - AdvancedTrack: Threat Detection and Incident Response
- Chalk talk300 - AdvancedThreat Detection and Incident ResponseAmazon GuardDutyAmazon InspectorAWS Security Hub10:00 a.m. Wednesday, Jun 18Wednesday, Jun 18Join this session to discuss managing security posture and risk across multiple accounts, regions, and resources. We will explore the decision-making process around how you prioritize security alerts and risk using AWS security services. After prioritization, we will discuss a framework for responding to and remediating security findings. We will talk through the decision-making process of responding to findings, considerations for auto-remediation, and how to facilitate a quick and thorough response to the most critical security findings.Session Type: Chalk talkLevel: 300 - AdvancedTrack: Threat Detection and Incident Response
- Lightning talk200 - IntermediateGovernance, Risk, and ComplianceTuesday, Jun 173:00 p.m. Tuesday, Jun 17In today’s cloud environments, real risk isn’t just about critical CVEs - it’s about what’s exploitable and exposed. As the cloud attack surface grows, proactive risk management and frictionless automation are essential from code to cloud to reduce remediation time and provide actionable context to IT and development teams. With Qualys, security teams move from alert overload to real-time action: orchestrating remediation, eliminating manual steps, and maintaining continuous compliance. Learn how Qualys enables AWS risk operations with TruRisk Prioritization, Attack Path Analysis, and QFlow for no-code remediation of misconfigurations and vulnerabilities. Join this session to see how Qualys helps enterprises operationalize risk management at scale. This presentation is brought to you by Qualys Inc., an AWS Partner.Session Type: Lightning talkLevel: 200 - IntermediateTrack: Governance, Risk, and Compliance
- Workshop300 - AdvancedGovernance, Risk, and ComplianceDevSecOpsSecurity AnalyticsThreat IntelligenceAmazon CloudWatchAWS CloudTrailAWS Config9:00 a.m. Wednesday, Jun 18Wednesday, Jun 18Get hands-on experience building security monitoring and compliance controls using AWS observability services. In this workshop, learn to implement real-time threat detection by configuring CloudWatch, CloudTrail and AWS Config. Practice creating dashboards, setting up automated alerts, and building response workflows. Through guided exercises, develop skills to maintain security compliance and respond to threats. You must bring your laptop to participate.Session Type: WorkshopLevel: 300 - AdvancedTrack: Governance, Risk, and Compliance
- Lightning talk300 - AdvancedThreat Detection and Incident ResponseGenerative AIAgentic AIThreat IntelligenceDevOps EngineerIT ExecutiveSolution / Systems ArchitectAmazon BedrockAmazon NovaEnergy & UtilitiesFinancial ServicesGovernmentTuesday, Jun 171:00 p.m. Tuesday, Jun 17Defenders face growing challenges with limited resources, complex environments, and evolving threats. Trellix introduces a breakthrough: Agentic Security powered by AI. This session explores how AI, fueled by data from AWS GuardDuty, email, endpoints, HR systems, IT tickets, and physical security can autonomously investigate threats, reduce alert fatigue, and surface hidden risks. Learn how Trellix leverages Amazon Bedrock to activate Agentic AI across its AI-powered security platform, delivering faster responses and deeper insights across silos. With Agentic AI, cybersecurity becomes proactive, persistent, and always-on because threats don’t wait for business hours. This presentation is brought to you by Trellix, an AWS Partner.Session Type: Lightning talkLevel: 300 - AdvancedTrack: Threat Detection and Incident Response
- Lightning talk200 - IntermediateApplication SecurityGenerative AIAgentic AICloud Security SpecialistData ScientistSolution / Systems ArchitectAmazon BedrockFinancial ServicesHealthcare & Life SciencesSoftware & InternetTuesday, Jun 175:00 p.m. Tuesday, Jun 17AI is poised to transform enterprise software, but its adoption exposes companies to new safety and security risks. With tens of thousands of companies using AWS Bedrock, chances are your developers are building innovative applications. AI and security leaders share the responsibility to ensure that those applications are secure, but in most cases, neither organization has the necessary visibility or safeguards. Join us to learn how Cisco AI Defense provides critical visibility, algorithmic red teaming, and runtime guardrails that you need to develop and deploy AI applications securely within your AWS environment. This presentation is brought to you by Cisco, an AWS Partner.Session Type: Lightning talkLevel: 200 - IntermediateTrack: Application Security
- Lightning talk300 - AdvancedApplication SecurityWell-Architected FrameworkDevSecOpsMigrationDeveloper / EngineerDevOps EngineerSolution / Systems ArchitectAWS Cloud Development Kit (AWS CDK)AWS Identity and Access Management (IAM)Cross-Industry SolutionsProfessional ServicesSoftware & Internet3:00 p.m. Wednesday, Jun 18Wednesday, Jun 18Vibe coding with GenAI is almost too easy... until your app goes live. Then come unauthenticated access alerts, surprise bills, DDoS attacks, Denial of Wallet events—or worse, a system take down. I’ve built AI-powered systems for millions of users, and I’ve seen how fast becomes fragile without security by design. In this talk, I’ll share what GenAI skips - and how to harden your stack by shifting security left with protective app layers, authentication patterns, Infrastructure as Code, and automated CI/CD deployments to go from vibes to resilient architecture. If you're building with AI, this talk might save your app - and your business.Session Type: Lightning talkLevel: 300 - AdvancedTrack: Application Security
- Workshop300 - AdvancedGenerative AICloud Security SpecialistDevOps EngineerSolution / Systems ArchitectAmazon BedrockAmazon SageMakerTuesday, Jun 173:00 p.m. Tuesday, Jun 17This workshop takes a hands-on approach to generative AI security, focusing on Amazon Bedrock, Amazon SageMaker, and related services. We'll begin by examining Bedrock's core security principles, including data protection during inference and in features like agents, guardrails, and knowledge bases. Participants will gain insights into the internal architectures and security implications of context windows, system prompts, agent orchestration, and more. The session then transitions into hands-on red teaming exercises using SageMaker. We'll subsequently explore defensive strategies against these threat vectors and discuss methods for integrating these practices into development workflows. Participants will leave equipped with a holistic understanding of generative AI security, from individual model protection to safeguarding complex, multi-component systems. You must bring your laptop to participate.Session Type: WorkshopLevel: 300 - Advanced
- Workshop400 - ExpertThreat Detection and Incident ResponseWednesday, Jun 1812:00 p.m. Wednesday, Jun 18This workshop will help you learn how to develop and deploy active defense strategies, such as deception, using Amazon Bedrock and Amazon SageMaker. Gain hands-on experience developing AI-driven responses for security operations. You will learn how to develop adaptive responses that mimic what an actor may be trying use against you. Discover implementation patterns for prompt engineering, deployment strategies, and monitoring methodologies. You must bring your laptop to participate.Session Type: WorkshopLevel: 400 - ExpertTrack: Threat Detection and Incident Response