This is a hybrid workshop.
You MUST also register at this WSC website: TBD
After you register at the WSC site, you will receive Zoom information.
A free parking pass will be provided after registration. For detailed instructions on how to find the parking lot and venue, please go to the ‘How to find us’ section below the map.
Title: Intro to DevSecOps in an Agentic AI World
Location: Long Beach City College (in-person) and Zoom (virtual) Date: Saturday, October 3, 2026 Time: 9 AM PT - 12 PM PT (Pacific Time)
Workshop Level: Beginner 101
This workshop is a Level 101 introduction to DevOps and DevSecOps, then turns to how agentic AI is changing that world. We'll walk through the DevOps/DevSecOps lifecycle and guiding principles, then focus on what's new: AI coding agents and autonomous pipelines acting inside that lifecycle, and why they need to be treated as identities subject to the same least-privilege and Zero Trust principles as human developers. The session includes two hands-on components: a small-group tabletop exercise mapping AI-agent risk scenarios to the DevSecOps stage and control that should catch them, and a live lab where attendees use a pre-built, browser-based GitHub Codespace to prompt an AI coding agent to modify a sample application, then add security gates to its pipeline as a group.
The core DevOps and DevSecOps lifecycle (Plan, Develop, Build, Test, Release, Deploy, Operate, Monitor, Feedback) and the principles behind it (the Three Ways, guiding principles for DevSecOps culture)
How agentic AI tools -- coding agents, autonomous CI/CD -- are now operating inside that lifecycle, and why passing tests or code review doesn't automatically mean an agent's output is safe
How to extend least-privilege and Zero Trust thinking to AI agents as identities, not just human users
Hands-on practice identifying which lifecycle stage and control should catch a specific AI-agent risk scenario
First-hand experience prompting an AI coding agent inside a real pipeline, and adding a security gate to catch what it might miss
Prerequisites: No coding or hands-on DevOps experience required -- this is a Level 101, concept-first workshop. Attendees will need a free GitHub account for the hands-on lab; setup instructions will be sent in advance so no time is lost creating accounts during the session. No local software installation is required -- the lab runs entirely in the browser via GitHub Codespaces. Optional: hands on agentic coding tool such as Claude Code or Codex – bring your own account (free tiers can work) -- if you don't have one set up, you'll pair with someone who does for that portion.
Technical/Hardware Requirements:
- A laptop with modern web browser
- Free Github account (setup instructions provided in advance)
- The hands-on lab runs entirely in GitHub Codespaces in the browser
- If you choose to do the agentic AI coding work, bring your own tool and account.
Agenda (All times are in Pacific Time) 9:00:09:10 - Welcome & why this matters now 9:10-9:50 -- DevOps & DevSecOps 101: the lifecycle, the Three Ways, guiding principles 9:50-10:00 -- Break 10:00-10:30 -- AI focus: agentic AI in the pipeline, and treating AI agents as identities (least-privilege, Zero Trust) 10:30-10:55 -- Hands-on tabletop exercise: “Who Should Have Caught This?” -- small groups map AI-agent risk scenarios to the DevSecOps stage/control that should catch them 10:55-11:00 -- Break 11:00-11:45 -- Hands-on lab: using a pre-built GitHub Codespace, prompt an AI coding agent to modify a sample application, then add security gates to its pipeline as a group 11:45-12:00 -- Wrap-up, resources, Q&A
Instructor: Scott Bly Bio: Scott Bly is a Field CISO and independent security advisor with 20+ years in cybersecurity, cloud, and networking. He created Hermia, an open-source framework for evaluating LLM security and reliability across heterogeneous inference hardware. Based in the Santa Monica, CA area.