Conference Speaking

Bringing AppSec clarity to the stage

I speak at international developer and security conferences on application security program design, DevSecOps transformation, and the practical realities of building secure software at scale.

DevSecOps Application Security SAST / DAST AppSec Programs AI in Security Secure SDLC
Upcoming

Next on stage

Confirmed Speaker  ·  July 2026
WeAreDevelopers World Congress 2026
📅 8–10 July 2026 📍 CityCube Berlin 🇩🇪 Germany 👥 15,000+ attendees 🏢 8,000+ companies

Europe's largest developer conference. Julian will be speaking on the Application Security track, bringing a practitioner's perspective on how development managers and DevSecOps teams can build AppSec programs that actually stick — beyond the tool purchase.

🇩🇪
CityCube Berlin
Messe Berlin South
Talk Topics

Available keynotes & sessions

All talks are available as keynotes, deep-dive sessions, or panel contributions. Topics can be shaped around your audience and format.

Why Your DevSecOps Pipeline Is Failing — And It's Not a Tool Problem

Most AppSec programs fail before a tool is deployed because organisations solve a process problem with a technology purchase. This talk gives managers a framework for fixing that.

DevSecOpsStrategy

SAST vs. DAST vs. SCA — A Manager's Decision Framework

A structured breakdown of when each testing methodology applies, how to evaluate vendors without being a security expert, and what actually differentiates tools in practice.

SASTDASTSCA

How to Build an AppSec Program That Gets Funded

Translating security risk into business language. How to build the business case for AppSec investment and structure a programme your CISO and CFO will actually support.

CISOsBusiness Case

AI in Application Security Testing — What's Real, What's Hype

A grounded assessment of how AI is actually changing vulnerability detection, remediation guidance, and AppSec posture management — and what to look for from vendors claiming AI capabilities.

AIASPM

From DevOps to DevSecOps — What Actually Changes for Your Teams

The cultural, process, and tooling shifts that separate DevOps organisations that talk about security from ones that actually ship it. Practical, based on 15+ years of field experience.

DevSecOpsCulture

Container Security & IaC Scanning for Engineering Leaders

What development managers need to understand about container image scanning, IaC misconfiguration detection, and how to build shift-left security into cloud-native engineering workflows.

ContainersIaCCloud
Track Record

Previous engagements

Selected conferences, developer summits, and security events from the past four years — plus ongoing regular presence at European industry events.

2026

DACHsec IT Security Summit 2026

Frankfurt — April 2026
2025

UNICC Common Secure Conference 2025 ↗

"Is AI-Generated Code Secure?" — UN International Computing Centre, October 2025
2025

eCrime & Cybersecurity Congress Middle East 2025

Abu Dhabi — Application security track
2025

WeAreDevelopers World Congress 2025

Berlin — Application Security & AI track
2025

Enterprise:CODE Berlin

AppSec program design for enterprise engineering teams
2024

WeAreDevelopers World Congress 2024 ↗

Berlin · "Let's write an exploit using AI" — live demo using ChatGPT to build a working Log4Shell exploit
2024

Australian Cyber Conference 2024

Melbourne (AISA) · Application security session, November 2024
2023

WeAreDevelopers World Congress 2023

Berlin — Application Security track
2023

Salon Big Data & AI Paris 2023

Paris — Security implications of AI in software development
2022

AISA CyberCon Melbourne 2022

Melbourne — Australia's premier cyber security conference, October 2022
2021

Cybersecurity & Data Protection Forum 2021 ↗

Sofia — Hybrid conference, November 4, 2021
2018

heise devSec ↗

Heidelberg — "Sicherheitstests in der CI/CD-Pipeline"
Ongoing

DevOpsCon

DevSecOps & Application Security track — multiple European editions
Ongoing

it-sa (Nuremberg)

Germany's largest IT security trade show
Ongoing

BSides Events

Community security conferences across Europe
Ongoing

OWASP Chapter Events

DACH chapter presentations on AppSec tools and programs
Ongoing

Veracode Virtual Events

Webinars and online sessions for DACH, EMEA and APAC customers
Ongoing

Partner & Customer Conferences

Technical sessions for enterprise security teams across EMEA and APAC
Book Julian

Invite Julian to Speak

Available for keynotes, conference sessions, panels, corporate workshops, and podcast appearances. Topics tailored to your audience — managers, practitioners, or executive leadership.

Keynotes Conference Sessions Panel Discussions Corporate Workshops Podcasts Webinars
Get in Touch →