Session

Beyond the Scanner: Frontier AI vs. Traditional DevSecOps in the Real World

Abstract
As frontier AI models become more capable, engineering teams are increasingly tempted to point LLMs at everything from static code analysis to threat modeling and incident response. But are frontier models actually here to replace your existing DevSecOps toolchain, or are they expensive hammers looking for the wrong nails?

This talk cuts through the hype to provide a pragmatic, battle-tested framework for combining frontier AI models with traditional DevSecOps tools. We will examine the distinct strengths and failure modes of both paradigms—comparing deterministic tools (SAST, DAST, SCA, linters) with probabilistic reasoning engines (frontier LLMs).

What You Will Learn:
The Core Divide: A clear breakdown of what deterministic security tools do best (speed, compliance, syntax) versus where frontier models excel (contextual reasoning, complex architectural review, nuanced threat modeling).

The Cost-Benefit Reality: How to evaluate latency, token costs, hallucination risks, and data privacy constraints against traditional scanning overhead.

Real-World Anti-Patterns: Common mistakes teams make when trying to use LLMs as drop-in replacements for standard security gates.

The Hybrid Playbook: How to build an integrated pipeline where traditional tools handle the heavy lifting and deterministic gating, while frontier models handle deep context analysis, remediation advice, and triage.

Whether you are a security engineer looking to adopt AI safely or a developer trying to cut through tool fatigue, you will walk away with a clear roadmap for when to leverage frontier AI—and when to stick to proven DevSecOps infrastructure.


Intermediate level talk, preferred duration 30-45min. Can be also a 2h workshop by running a lab where we would be running real world vulnerability scanning with agentic models and existing DevSecOps tools and comparing the results with a specific evaluation criteria

Javier Garza

Staff Developer Advocate at Snyk

San Carlos, California, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top