Aaron Bronow
Building robust software, resilient teams, and zero-nonsense architecture.
Seattle, Washington, United States
Actions
Hey there! I’m Aaron Bronow—engineering leader, startup builder, and relentless tinkerer who bridges the gap between deep systems architecture and high-impact human teams. Whether diving into the nuances of supply chain security and cloud-native infrastructure or scaling engineering culture without the corporate fluff, I bring practical, battle-tested insights straight from the terminal to the stage.
My mission? Demystifying complex technical ecosystems, turning chaotic pipelines into elegant systems, and empowering engineers to build boldly, ship securely, and actually enjoy the process. Expect actionable takeaways, zero slide-filler, and a healthy dose of pragmatic enthusiasm.
Links
Area of Expertise
Topics
Getting Started with SLSA, SBOMs, and Attestation Without Breaking the Build
With impending regulatory standards like the EU Cyber Resilience Act (CRA) and the rise of automated, agentic code generation, securing software supply chains is no longer optional—it is an operational mandate. However, for most engineering teams maintaining mission-critical libraries and pipelines, implementing SLSA frameworks, generating meaningful SBOMs, and establishing cryptographic attestations can quickly become a bottleneck that grinds developer velocity to a halt.
Drawing from hands-on work modernizing CI/CD pipelines across foundational open-source ecosystems (including go-yaml and pyyaml), this session provides a practical, zero-fluff walkthrough of implementing supply chain security without breaking existing build workflows.
Key Takeaways:
Demystifying the Acronyms: Cutting through the noise of SLSA levels, in-toto attestations, and SBOM standards (SPDX vs. CycloneDX).
Pragmatic CI/CD Integration: How to automate artifact signing and provenance generation in GitHub Actions with minimal build friction.
CRA & Regulatory Readiness: Understanding what EU compliance realistically requires from maintainers and enterprise engineering teams.
The Agentic CI/CD Era: Ensuring pipeline integrity when AI agents contribute directly to the commit graph.
Presented for Cloud Native Foundation Seattle
Format: Standard Presentation / Tech Talk (30–45 min)
Track: DevSecOps / Cloud Native Infrastructure / Supply Chain Security
Preparing Your GitHub Supply Chain for the EU Cyber Resilience Act (CRA)
The EU Cyber Resilience Act (CRA) is reshaping how software is built, distributed, and maintained globally. If your product ships software components to European users or relies on open-source dependencies, your engineering organization must adapt its development lifecycle to meet stringent provenance, vulnerability management, and reporting requirements.
This hands-on workshop walks engineering leaders, founders, and DevSecOps practitioners through auditing and hardening their GitHub supply chain for compliance. We will move beyond abstract policies to examine actual repository configurations, automated dependency vetting, and compliance-ready pipeline architecture that protects your product without suffocating developer momentum.
Key Takeaways:
Deconstructing CRA Requirements: What software makers and maintainers actually need to document and verify.
Hardening GitHub Workflows: Enforcing branch protections, secret hygiene, and provenance attestation at the repository level.
Automated Dependency Governance: Strategies for scanning, tracking, and remediating upstream supply chain risks in real time.
Actionable Compliance Blueprint: A concrete checklist you can take directly back to your team to assess compliance readiness.
Prepared for LA Tech Week October 2026
Format: Interactive Workshop / Deep-Dive Session (45–60 min)
Track: Engineering Leadership / DevSecOps / Product Compliance
How Does the User Experience This? A Front-End Journey from ARPANET to the Cloud
From text-only terminals, IBM-era spellcheckers, and Lynx browsers to complex, cloud-hosted web applications, the tools we use to build for the internet have radically transformed. Yet across three decades of evolving standards—table layouts, CSS resets, JavaScript frameworks, and mobile-first responsive design—one foundational engineering question has remained constant: How does the user actually experience this?
Drawing from over a decade of hands-on front-end development, remote engineering, and enterprise architecture, this talk takes a practical, reflective look at the history of web technology. We will trace how early constraints shaped modern web practices, explore the balance between design and developer workflows, and examine why accessibility, globalization, and user-centered thinking matter just as much when architecting back-end APIs as they do when building the UI.
Key Takeaways:
From ARPANET to the Modern Cloud: Tracing the evolution of markup, styling, and client-side execution from raw documents to interactive web apps.
Lessons from the Trenches: How developers historically solved layout hurdles (tables, transparent pixels, CSS box models) and what modern tooling can learn from those constraints.
Accessibility as a First Principle: Practical accessibility insights, from using text browsers like Lynx for screen-reader audits to designing inclusive interfaces for a global audience.
Bridging Design and Engineering: Integrating design thinking early into the software development lifecycle (SDLC) to reduce friction between design labs and production code.
The Core North Star: Applying a user-first mindset across the entire stack—from UI layout down to database schemas and API design.
Presented at Seattle Central Community College
Format: Standard Presentation / Breakout Session (30–45 min) Track: Front-End
Architecture / Web Development History / User Experience & Accessibility
From Markup to Modern Layouts: Mastering HTML, CSS Architecture, and Web Fundamentals
Every web interface relies on the seamless convergence of structured content, intentional design, and resilient code. Navigating the full spectrum of fundamental web development—from the initial document structure to complex visual layouts—requires understanding not just the syntax, but how browsers interpret and render digital experiences.
This session delivers a comprehensive, practical walkthrough of foundational web technologies. We will explore the mechanics of semantic HTML5, dissect the CSS cascade and specificity rules, and dive into the CSS box model and positioning engines. Beyond styling, the session covers developer tooling, asset optimization, web typography, accessible forms and tables, and version control workflows essential for collaborating on production-ready websites.
Key Takeaways:
Semantic Document Architecture: Structuring robust HTML5 documents with semantic elements (header, nav, section, article, footer), valid metadata, accessible link paths, and optimized media assets.
The CSS Cascade & Specificity: Controlling presentation by understanding style inheritance, load order (far-to-near, top-to-bottom), and selector specificity (classes, IDs, and pseudo-classes).
Mastering the Box Model & Layout Flow: Managing content dimensions, padding, borders, and margins, while mastering element display types (block, inline, inline-block), float clearing techniques (clearfix, overflow), and positioning contexts (static, relative, absolute, fixed).
Web Typography, Backgrounds & UI Components: Implementing responsive background images, gradients, Google Fonts, font-face rules, and icon fonts to build modular UI components.
Data Presentation & User Input: Building structured tabular layouts with table elements and zebra-striping (:nth-child), alongside fully labeled, accessible interactive user forms.
Professional Tooling & Workflows: Managing clean file directory structures, naming conventions, browser DevTools inspection, and version control using Git and GitHub.
Prepared for School of Visual Concepts, Seattle
Format: Comprehensive Technical Workshop / Deep-Dive Tutorial (60–90 min)
Track: Front-End Development / Web Design & Architecture / UI Engineering
Aaron Bronow
Building robust software, resilient teams, and zero-nonsense architecture.
Seattle, Washington, United States
Links
Actions
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top