AppSec Flash Talks: Secure Coding Ind. Ctrl. Systems, Automating ZAP and more!

Опубликовано: 20 Февраль 2026
на канале: OWASP Vancouver
62
2

Welcome to the OWASP Vancouver chapter Youtube channel. We are located in the beautiful province of British Columbia, on the West Coast of Canada.

Our mission is to enrich Vancouver’s application security community. We hope you can join us in accomplishing that.

This is the Flash Talk edition of the OWASP Vancouver meet-up series featuring 4 speakers! You will be able to enjoy this series from wherever you are in the world :)

00:07 1st Speaker: Vivek Ponnada

Secure Coding of Industrial Control Systems

Abstract: Industrial Control Systems have historically been insecure by design. Several years into customizing and applying best practices from IT gave rise to secure protocols, use of encryption, network segmentation & isolation etc. However, to date, there has not been a focus on using the characteristic features in the PLCs and DCS for security, or how to code/program PLCs with security in mind.

Speaker Bio: Vivek Ponnada works for GE as a Service Manager and is responsible for GE’s Gas Power transactional customers (Utilities and Co-generation) across Canada. Prior to this role, he was in Sales & Business development (Control system upgrades and Cybersecurity solutions), and started his career as a Field Engineer, commissioning turbine controls systems in Europe, Africa, Middle-East and SouthEast Asia. Vivek is passionate about industrial controls cybersecurity and enjoys learning & contributing to the security community.

_____________________________________________________________________________________

21:32 2nd Speaker: Jared Meit

Automate ZAP In Any Language

Abstract: OWASP's ZAP is one of the top tools when it comes to Dynamic Application Security Testing (DAST). Written by developers for developers, ZAP provides power functions to scan applications, including modern REST API based ones. In this brief talk, you will learn how to script ZAP scanning with any language and without having to use a ZAP library.

Speaker Bio: Jared has always had a passion for taking things apart, learning how they work, and forgetting how to put them back together. He brings more than 12 years of professional software development, and a zeal for all things security. His AppSec experience at one of the “Big Four” accounting firms informs the deep level of care and scrutiny that he applies to all projects.
  / jared-meit-069ba014  

_____________________________________________________________________________________

42:51 3rd Speaker: Harsh Modi

Learning Cybersecurity, the hard way

Abstract: The flash talk will focus on different dimensions of building technical skills and mindset to become a skilled cybersecurity professional. This talk will enrich the knowledge of participants regarding OWASP framework and methodology, capture the flag competitions and real time labs like Hackthebox, TryHackme and Portswigger labs. Also, the pentesterlabs are my favourite.

A short introduction on research skills required in the InfoSec industry and will finish with intro to bug bounty.

Speaker Bio: Harsh has 2 years of experience as a penetration tester with various orgs including within Vancouver. He is a dedicated cybersecurity professional and mentors six people worldwide on various ethical hacking techniques. In his spare time Harsh likes to get extremely technical with his security skills and looks forward to writing his OSCP and Synack Red Team exams in the near future.

_____________________________________________________________________________________

58:30 4th Speaker: Donovan Ellison

An Introduction to AWS Systems Manager

Abstract: In this talk, we will discuss the requirements for Systems Manager, their useful capabilities to enhance your security posture, and less well documented facts about how those capabilities actually work. For example, the documentation for State Manager says it "runs associations on instances", which could entail a variety of things, but what actually happens is State Manager sends the association to the SSM agent on the instance to process and execute.

Speaker Bio:   / donovan-ellison-631825182  


Recorded date: 2021-08-19

You can find us:
Site: https://owasp.org/www-chapter-vancouver/
Meetups: https://www.meetup.com/OWASP-Vancouve...
Twitter:   / owaspvancouver  
MARS Slack: #owasp-vancouver