BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Beyond the Flag: How CTF Players Become Product Secu
 rity\n   Engineers\n   Tags: Red Team Village | Misc\n   When: Sunday\, Au
 g 9\, 10:00 - 10:59 PDT\n   Where: LVCCW Level 1 Hall 1 309 (Red Team Vill
 age) Workshop Tactic\n   Table 5 - [1]Map\n\n   Description:\n   Abstract:
 \n\n   Capture The Flag competitions are often dismissed as “just games\
 ,”\n   but modern Product Security teams increasingly rely on the exact\
 n   skills they develop: adversarial thinking\, vulnerability analysis\,\n
    exploit chaining\, and secure design under pressure. Whether you are an
 \n   aspiring security professional or an experienced offensive security\n
    practitioner\, in this session\, you will learn a structured CTF-driven
 \n   learning roadmap for developing practical security skills and will\n 
   learn how hands-on\, real-world customer-facing offensive engagements\n 
   contribute to building deep product security expertise. We will also\n  
  cover how AI capabilities are accelerating this journey of learning\n   a
 nd securing the systems. Attendees will participate in a hands-on\n   exer
 cise to explore the challenge through the lenses of CTF problem\n   solvin
 g\, penetration testing\, and Product Security.\n\n   ====================
 ===============================\n\n   Introduction: (1 minute)\n\n   Sessi
 on Overview: (2 mins) • During this session\, you will see a\n   practic
 al framework to become a trusted partner in building secure\n   applicatio
 ns rather than being a gatekeeper. Starting with a practical\n   framework
  of learning and approaching CTFs\, to using it as an\n   offensive securi
 ty practitioner to develop stronger application\n   security capabilities.
  We also see how AI can accelerate and reshape\n   modern security workflo
 ws. • In this session\, attendees will be\n   given a challenge designed
  to get hands-on experience of solving the\n   CTF\, creating an offensive
  security report\, and sharing\n   recommendations from a product security
  engineer's perspective to\n   secure the applications/systems. After the 
 session\, I will review each\n   participant's approach and award swag to 
 the top performers.\n\n   Intended Audience: (2 mins) • Aspiring securit
 y professionals •\n   Experienced penetration testers • Security engin
 eers • Students\n   entering cybersecurity\n\n   Capture the Flag (7 min
 utes) • What is CTF? • Why is CTF crucial?\n   • Hands-on experience
  • Risk-free environment • Collaboration\n   and teamwork • Skills t
 hat CTFs actually teach • Avoiding rabbit\n   hole • Structured approa
 ch to learn concepts • OWASP Top 10 •\n   Domains: APIs\, Web Applicat
 ion\, Crypto\, Cloud • A few common\n   vulnerability areas to consider:
  Injection\, File Upload\n   Vulnerabilites\, AuthN\, AuthZ\, Remote Code 
 Execution\n\n   Penetration Testing (7 minutes) • What is penetration te
 sting? •\n   Map skills learned in CTF to organizational context using d
 ifferent\n   methods (black box\, white box\, and grey box testing) • Wh
 at is the\n   focus area: • Effective technical reports that include: 
 Details\n   on the process: environment considerations\, recon\, scanning
 \, and\n   exploitation • List of Findings with details about: What exac
 tly is\n   the specific finding\, Severity\, Impact\, How to remediate the
  finding\n\n   • CTF becomes pentesting when you stop asking: • Can I 
 exploit\n   this? • Where can I find the flag? • And start thinking: 
  What\n   does this mean for customers? • How does it impact their pro
 duct?\n\n   • Note: One starts to build customer trust by helping them w
 ith the\n   business context of findings and how to reduce the risk\n\n   
 Product Security Engineer (7 minutes) • Shift in mindset from\n   “fin
 d the bug” to “how do we prevent this everywhere? With the\n   knowled
 ge gained from CTF and real-world pentesting.” • Holistic\n   approach
  of shifting left the security: • Threat Modeling •\n   Implementing S
 ecurity Best Practices: • Integration of the SAST tool\n   into the CI/C
 D pipeline • Logging and monitoring • Cloud\n   Configuration reviews 
 • Least privileges • Vulnerability\n   Management Comparison • Compa
 re with the Software Engineer journey\n   to Programming -> Data Structure
 s -> Front End Developer -> Full Stack\n   Developer\n\n   Resource: (2 mi
 nutes) • Ask the audience for any recommendations\n   that helped them b
 e strong at what they do • Provide resources that\n   I found useful\n\n
    Recap: (2 minutes) [CTF - “How do I break this to get the flag?”\n 
   → Pentest - “How bad is this?” → Product Security Engineer -\n  
  “How do we prevent this everywhere?”] → AI - “How do we move\n   
 faster without losing depth?”\n\n   Task (2 minutes): • Give them deta
 ils about the challenge\n   environment • Explain to them the expectatio
 ns • Find the flag •\n   Penetration Test Report • Explain their app
 roach to secure the\n   feature (Secure Design review\, SAST recommendatio
 n\, how would you\n   prevent it across the application?) • The winner w
 ill get swag\n\n   Key Takeaways: (3 minutes) • Security is not just: 
  Finding\n   security gaps • Shipping reports • Security engineers be
 come\n   trusted partners when they: • Know the attacker's mindset • H
 ave\n   hands-on experience in ethical hacking • Understand product goal
 s\n   • Understand how systems fail • Gives practical guidance by bein
 g\n   part of secure development with developers • Communicate risk\n   
 clearly • Improve application security at scale\n\n   Q&A (5 minutes)\n\
 n   Speakers:Drew Thompson\,Monish Alur Gowdru\n\n   SpeakerBio:  Drew Tho
 mpson\n\n   Drew Thompson is a Principal Consultant at UltraViolet Cyber\,
  where he\n   specializes in cybersecurity training\, offensive security\,
  and\n   AI-enabled security practices. He designs and delivers hands-on\n
    training for security practitioners\, develops technical enablement\n  
  programs\, and works closely with consultants and customers to\n   transl
 ate emerging attack techniques into practical defensive\n   capabilities. 
 Drew is passionate about making complex security topics\n   accessible thr
 ough real-world demonstrations\, interactive labs\, and\n   practical rese
 arch.\n\n   SpeakerBio:  Monish Alur Gowdru\n\n   Monish Alur Gowdru is a 
 cybersecurity professional with over 6 years\n   of experience in applicat
 ion security and software development. He\n   enjoys helping product teams
  to secure applications end-to-end\n   throughout the software development
  lifecycle. He actively contributes\n   to the cybersecurity community as 
 a speaker\, mentor\, and judge. His\n   ongoing involvement includes promi
 nent work with DEF CON and BSides\n   Edmonton.\n\n   LinkedIn: https://ww
 w.linkedin.com/in/ag-monish/\n\n   '\n\n   1. #LVCCW_Level1_Hall1\n\n\n
DTEND:20260809T175900Z
DTSTART:20260809T170000Z
LOCATION:Red Team Village - LVCCW Level 1 Hall 1 309 (Red Team Village) Wor
 kshop Tactic Table 5
SUMMARY:Beyond the Flag: How CTF Players Become Product Security Engineers
END:VEVENT
END:VCALENDAR
