Session

Harnessing Agentic DevOps & Security Compliance with A.I

Security compliance has a reputation problem: it's seen as paperwork that slows delivery down. Haggai argues the opposite — when compliance is treated as an engineering discipline and paired with agentic AI, it becomes a delivery accelerator.

Drawing on hands-on experience leading cloud compliance programs (FIPS 140-3 and FedRAMP) for regulated SaaS products, Haggai walks through how his team harnesses AI agents across the entire lifecycle: from planning (translating control frameworks into epics, backlogs, and architecture decision records), through implementation (compliant-by-default Terraform/Terragrunt modules, hardened container image curation, CI pipelines with zero static credentials), to delivery and evidence (automated SCA/policy scanning, IaC as continuous audit evidence, and agents that draft, verify, and maintain compliance documentation).

The session covers the practical harness: how to structure agent workflows, skills, and guardrails so AI output is trustworthy enough for auditors — and where humans must stay in the loop. Attendees leave with a repeatable pattern for turning any security standard into an agentic, automated DevOps workflow, plus the pitfalls learned the hard way.


Target audience: DevOps / Platform Engineers, SREs, security engineers, and engineering leaders working in (or heading toward) regulated environments — GRC-curious developers welcome. Best suited for mid-to-senior level; no prior compliance knowledge required.
Track fit: Sits at the intersection of DevOps Pro Europe and CyberWiseCon Europe; also relevant to the AI & ML Integration and Platform Engineering tracks.
Preferred duration: 40–45 min talk (can be adapted to 30 min);
Technical requirements*: Standard A/V (HDMI, screen, mic); internet connection preferred for the live demo but not mandatory.
First public delivery — this exact session has not been delivered publicly before. It builds on material from the speaker's "FedRAMP, From the Platform Side" blog series and prior conference talks on Agentic AI in DevOps (Reversim Summit, DevOps Days).
Language: English.
Content notes: All examples are anonymized from real client engagements; no vendor pitch, tooling shown is open source or widely available (Terraform/Terragrunt, GitLab CI, OPA, Syft/Grype, Claude/agent runtimes).

Haggai Philip Zagury

DevOps Group & Tech Lead @Tikal Knowledge

Tel Aviv, Israel

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top