© Mapbox, © OpenStreetMap

Speaker

Farshad Abasi

Farshad Abasi

Founder | Application & Pipeline Security Architect | OWASP SPVS Co-Author

Vancouver, Canada

Actions

Farshad Abasi has been building and breaking software systems for nearly three decades, starting in the 80s on a Sinclair ZX Spectrum and never quite losing the curiosity that came with it.

He began his career as a software engineer at Motorola and later as a Senior Software Engineer at Intel before transitioning into security architecture. Farshad spent almost nine years at HSBC Global as a Software Security Architect, gaining deep experience in enterprise architecture, large-scale systems, and regulated environments.

Today, he is the Founder of Forward Security and co-founder of Eureka DevSecOps, where he focuses on application security, cloud security, and securing modern software delivery pipelines. He is also the co-author of the OWASP Secure Pipeline Verification Standard (SPVS) and has taught network and application security for over 20 years.

Farshad has spoken at ISC², LASCON (multiple times), DeveloperWeek, FinTech DevCon, OWASP AppSec events, and several BSides conferences including Vancouver, Calgary, and Toronto.

He remains interested in one persistent question: where security intent diverges from what systems actually become.

Area of Expertise

  • Information & Communications Technology

Topics

  • Application Security
  • Cloud Security
  • DevSecOps
  • ASPM
  • Application Security Architecture
  • Security Architecture
  • AI Security
  • Software Security
  • Pentesting
  • mobile security
  • api security
  • OpenID Connect
  • OAuth2
  • FAPI
  • Software Architecture & System Design

Your Threat Model Is Lying to You: Why Modeling the Design Isn’t Enough in 2026

Most teams threat model what they intended to build, not what is actually deployed. This talk exposes that blind spot and shows how to extend threat modeling beyond design by incorporating real SAST, SCA, DAST, IaC, and cloud findings.

Farshad Abasi

Founder | Application & Pipeline Security Architect | OWASP SPVS Co-Author

Vancouver, Canada

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top