Saquib Saifee

Saquib Saifee

Security Engineer @ IBM, CISSP, eCPPT

Raleigh, North Carolina, United States

Actions

Saquib Saifee is a Security Engineer in IBM's Product Security organization, where he develops security automation platforms that enhance software transparency and vulnerability response at scale. His work has helped establish capabilities that are now leveraged and extended by teams across IBM. His expertise spans software supply chain security, vulnerability lifecycle management, AI security, offensive security, and Software Bill of Materials (SBOM), where he serves as a Subject Matter Expert.

A dedicated advocate for the profession, Saquib volunteers with ISC2 as a Subject Matter Expert for Certified in Cybersecurity (CC) exam development and with the Center for Cyber Safety and Education as a scholarship reviewer. He regularly speaks at conferences and universities, including BSides Las Vegas, and mentors aspiring cybersecurity practitioners and early-career professionals.

Saquib holds the CISSP and eCPPT certifications and earned a Master's Degree in Cybersecurity from The George Washington University. He is currently expanding his focus on application security and the evolving challenges of securing AI-enabled systems.

Badges

Area of Expertise

  • Information & Communications Technology

Topics

  • AI and Cybersecurity
  • Cybersecuirty
  • Cyber Security basics
  • AI Builder
  • AI Security
  • GenAI Security
  • AI Security Testing
  • CISSP
  • Offensive AI
  • Offensive Security
  • offensive cyber security
  • Application Security

MCP Servers Are a New Attack Surface: How to Securely Build and Use Them

Model Context Protocol (MCP) is only as secure as the server you build it on. In under two years, it has become the standard integration layer connecting AI agents to enterprise systems, databases, source code, and production APIs. However, an agent crosses a trust boundary on every tool call and resource fetch, and the protocol leaves the server to decide what is allowed. If the server does not enforce those boundaries, nothing else will.

Grounded in real-world incidents and contributions to the OWASP GenAI Security Project, this practitioner-focused talk provides an actionable builder’s guide to securing MCP architectures.

We address both sides of the trust boundary, how to build secure MCP servers and how to vet third-party ones:
⚬ Architecture & Attack Surface: Why choosing the smallest deployment model (stdio vs. HTTP) and building focused, task-shaped tools drastically reduces prompt injection and tool-poisoning risks.
⚬ Builder's Defense Triad: Practical implementation of input validation, policy enforcement, and process containment.
⚬ Consumer Vetting Checklist: Essential checks to sandbox, isolate, and monitor third-party MCP servers before connecting them to your models.

Attendees will leave with a clear mental model of MCP trust boundaries and a concrete set of guardrails to apply on Monday morning.

Delivered at BSides Las Vegas 2026 to an engaged audience of security engineers and AI practitioners. The session is practical and vendor-neutral, drawing on my experience as a security engineer and contributor to the OWASP GenAI Security Project guidance on third-party MCP usage.

Quality Over Quantity: A Targeted Approach to Breaking Into Cybersecurity

You can apply to hundreds of jobs and hope something sticks. That is spray and pray. It can work, but it wears you down, scatters your effort, and leaves your results to chance. There is a steadier way that keeps you consistent inside a scope you can actually sustain. It is not a secret, but a system.
With no US work history and no network to inherit, this targeted approach landed me interviews at Meta, Palo Alto Networks, TikTok, and IBM. The system is simple: build a short list of target companies, rank them by what genuinely matters to you, and work the list from least-preferred to most-preferred so every interview becomes practice for the one that counts.
Whether you are an international student, a career changer, a bootcamp grad, or early in your career trying to level up, you will leave with:
⚬ Target List Framework: How to build, filter, and score a manageable 30–40 company list.
⚬ Bottom-Up Strategy: Using early interviews for deliberate practice to eliminate nerves before top-choice interviews.
⚬ Frictionless Networking: Leveraging conference scholarships, meetups, and quick-connect pitches that get responses without asking for favors.
⚬ The 10-2-1 Action Plan: A concrete, weekly execution cadence to start immediately.

This talk was accepted and delivered to an engaged, standing-room audience at BSides Las Vegas 2026. The content and timing are polished, and the delivery is fully dialed in for a high-impact 30-minute session tailored to BSides RDU's Career Village.

Your First Open Source Security Contribution: A Practical Guide to Getting Started

Most security practitioners assume contributing to open source security projects requires being a recognized expert first. It does not. These communities need practitioners doing real work, and the path from first-time contributor to named contributor is far more accessible than most people believe.

This talk is a practical, beginner-friendly guide to making your first open source security contribution, drawn from the speaker's own path from zero contribution history to contributing across OWASP projects, the CycloneDX ecosystem, and a CISA federal publication within about 18 months.

It covers how to find a project that matches your actual expertise, what a good first contribution looks like (and what gets ignored), how the contribution ladder works from lurker to reviewer to named contributor, and how showing up consistently translates into real community standing. Attendees leave knowing the specific first step they can take this week.

Shift Left, Actually: Catching Vulnerable Dependencies Before Code Leaves Your Machine

Most shift-left talks end at the pull request. Dependabot opens a PR, your scanner opens a PR, and you call it shifted. But by then the vulnerable dependency is already committed, pushed, and flagged back to you days later. The shift-left happened on someone else's calendar.

This talk presents a developer-side workflow that catches outdated dependencies, missing requirements, and policy violations before code ever leaves the local machine, using pre-commit hooks, deterministic dependency pinning with pip-tools or uv, and a small set of linting and type checks wired into one fast commit-time gate.

It covers the classic failure it eliminates (a package installed locally, never pinned, that passes on your machine and breaks in CI), how this layer complements rather than replaces Dependabot and downstream scanners, and how to roll it out across a team without making developers hate you. Attendees leave with a working configuration they can adopt the same day.

From Consuming to Contributing: How We Built the Space That Was Missing

Many of us naturally drift from consuming OWASP resources to contributing to them. At some point you stop just reading the Top 10 and start showing up at a chapter, submitting a pull request, or volunteering at a conference. But what often gets lost is the "together" part. The shared strategy, the mutual encouragement, a place where experienced contributors can mentor others and people new to contributing can find their footing without having to figure it out alone.

It started when two of us ran into each other at the Boston Application Security Conference. Same organization, same department, had no idea the other was there. That conversation grew into three people, then a cross-regional group, and eventually an initiative with executive sponsorship built around a simple question: what if there was a structured space where people at all levels of OWASP engagement could come together, share what they know, coordinate where to show up, and help each other go deeper?

That is what we built. A space where seasoned contributors have a home for their work and a way to pass it on, and where people curious about OWASP but not sure where to start can learn, get mentored, and take their first real steps. Contribution gets tracked, progress gets shared, and the work gets recognized internally in ways it never was before.

In this talk we share our journey, what the initiative looks like in practice, what we have achieved together so far, and what you can take back to your own organization.

Saquib Saifee

Security Engineer @ IBM, CISSP, eCPPT

Raleigh, North Carolina, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top