Harnessing AI for Enhanced Application Security with Sudhir Patamsetti | Black Hat 2025
Sudhir Patamsetti from Traceable by Harness discusses the integration of AI in application security through their DevSecOps platform. He outlines five key security modules, including Security Testing Orchestration, which aids developers in prioritizing vulnerabilities. The conversation highlights the increasing adoption of AI by practitioners for coding and automation, emphasizing the importance of Application Security as development expands. Sudhir also hints at future AI innovations from Harness.
Transcript
Hey everyone, it's Alan Shimel for Tech Trunk tv. We're back here continuing our coverage of Black Hat on the show floor. It's early in the morning.
Keynotes are going on, so it's not as crazy here, and it's a little better quiet and we can do some talking. I am at the harness booth. Of course, it's traceable by harness as well.
Uh, but we're here to talk harness with Sudir Pati Sudir. First of all, welcome to Text Stroke tv. It's great to have you on.
Yeah, Allen. Uh, thank you so much for having me. Uh, it's great to be talking to you today.
Alrighty. So Sudir, as I mentioned, it's quiet right now so we can talk without all of the stuff going on. Why don't we start with a little bit about you Sudir?
Sure. Uh, I work as a Senior Director of product management, uh, at Harness, uh, with a focus on, uh, runtime protection, uh, products. Okay.
And also on the platform capabilities. Very good. And, um, before Harness, kinda what's your background?
Uh, my background has been mostly in the application security space. Uh, worked at several, uh, large enterprise organizations like F five and Akamai. Okay.
Uh, before joining Harness. Uh, so, so that's So but on the more on the vendor than the practitioner kind of thing? Exactly, yeah.
I've been, I, I started as an engineer in my career. Uh, and then, uh, post MBAI actually moved into product management. Very cool.
com Right. And so we obviously cover Harness. I have covered harness from the day it was launched, but we're here at Black Hat a security show.
And of course, look, DevOps is DevSecOps, right? You can't do security or you can't do DevOps without security. Yep.
However, let's focus in on security. I mentioned traceable, traceable ai of course, was a kind of a sister company founded by the same team and, and investors is harnessed. They've recently merged.
I guess that's gotta be six or eight or more months ago now, nine, 10 months ago. But there's more to security at harness than just traceable. So assuming our audience knows Harness, they may not really know the harness security side of things.
If you wouldn't mind, let's start there. Give us sort of an overview of harnesses security capabilities. Yeah.
So, so we harness as an AI native DevOps platform, but now we are an AI native DevSecOps platform. Yep. So we help developers ship secure code faster and in a reliable way.
Right. That means we help embed security in every phase of the software development lifecycle, all the way from design to runtime, right. From the time when developers are coding to when the applications are running in production.
So we have tools at every phase of the SDLC that help secure the applications and APIs, uh, as they go from code to production. Perfect. And let's get specific about the, the offerings, right?
com, we're Security Boulevard. com. These are your people.
Let's peel that onion back a few layers. What specific security ai, security DevSecOps, whatever you wanna call it, what are the specific things that Harness is offering? So, uh, with the merger of Traceable, uh, we have like five modules now within harness, within the security pillar.
Uh, I'll go through one by one. Okay. The, maybe from left to right, all the way from Code to runtime.
So the first module is called Security Testing Orchestration. Okay. Uh, The goal of this product, uh, is to help developers prioritize vulnerabilities and to focus on the right vulnerabilities that they need to fix.
So the challenge that we see right now is there's so many tools out there, uh, for different types of scanning like SaaS or SCA or secret scanning, so Container Security das. So there's so many tools and each tool has its own format. So what we do with security testing orchestration is we bring, uh, the outputs of all these tools in the CICD pipeline.
We reduplicate the findings from the tools and create that list of vulnerabilities based on a specific criteria prioritized in an order. So developers can fix those vulnerabilities in an easy way by leveraging ai. So, so we have AI embedded in our platform.
So in order only tell you what are the important vulnerabilities you need to fix, but with the help of ai, we also show what you need to do in the code specifically and help developers create pull requests automatically with ai. And when you say AI is doing this thing, is, is it more of a kind of a chat bots with suggestions or is it more of an agentic AI that's autonomously doing these things? Or maybe both?
So we have a combination of both. Uh, we have different agents, uh, in the platform. There's a DevOps agent, there's a security AppSec agent.
So there are agentic flows where you can give an outcome, uh, to the ai and the AI will do all the steps for you. Or you can also interact with the AI in a chat bot style conversation, uh, to, to kind of question and answer format. Very good.
Alright. io. Yes.
io. Okay. Let's talk black hat day two here, Thursday of the, of the expo floor.
Of course, the conference and training's been going on now for four or five days. What, is this your first black hat? Have you been here before or No?
I think, uh, if I remember, I think this is my fifth black Hat. Fifth, okay. Yeah.
Fifth. Yeah. What do you think about this year's Black hat?
It's, it's, uh, great, uh, to be here. Uh, first of all, you, you get to learn so much, uh, from practitioners. Mm-hmm.
Uh, also from different vendors. Yes. Uh, and there's a separate area for AI innovation.
Uh, yeah, there is. I checked out yesterday, which is really cool. Uh, and, uh, it's great to see all the innovation happening in the security space, uh, with respect to ai.
It, it, there is certainly a lot of AI here, especially when you go both booth to booth. Um, what are you hearing from real life practitioners who come by here and talk? Are they so bought into ai?
Are they just all AI too? Or is it, I I often wonder are we as practitioners, not as practitioners, as vendors pushing AI on practitioners? Are they as eager to take that AI and use it as vendors are to sell it?
I would say if it was maybe one year ago, uh, practitioners were cautious about ai, but now they're realizing that it's, it's a real thing with, uh, for example, with AI now with the concept of vibe coding. Yes. Now it's so easy to write code and everyone started realizing that it's a real thing.
And you see in the news that like 30 or 40% of the code will be written by ai. So there stats like that, which is a real thing. And, and not only vendors, but practitioners have started adopting ai.
So it's a combination of human and ai. So how AI can help you automate a lot of your day-to-day tasks and free you up with a lot of, uh, manual tedious work so that you can focus on the more important things and AI can do all the, uh, the grant work or the, the cu cumbersome work for you. Sure.
So as I, you know, bring this full circle, blackouts, a security show, we think of Harness DevOps, DevSecOps, of course, there's much more to security that even just AppSec or, or DevSecOps. What percentage of the attendees that you speak to you think are interested in DevSecOps or even AppSec versus some of the other things we're seeing? Cloud security, endpoint security, threat modeling, you know, all, all the different flavors of cyber today?
No. We see a good traction at our booth. Uh, as I said, with more and more code being produced now, AppSec is gonna become even more important.
Mm-hmm. Uh, it's equally important, like the other pillars of security, like cloud security or endpoint security, because it all starts with applications and applications are growing day by day. Uh, so, so yeah.
I mean, like, it's a, it's a 50 50 split, I would say. Uh, and AppSec is gonna get bigger and bigger. Alright.
Last question for you. Was there any news or any kind of thing that harness announced around the show that we can tell our audience back home about Very soon? We are gonna bring out new announcements, uh, maybe to give you just A sneak.
Don't say anything that's gonna get us in trouble. Okay. But give us a little Yeah.
Sneak peek into, uh, it's gonna be about ai. Okay. Uh, so that's a sneak peek.
Fair Enough. Yeah. Enough.
So see a lot of cool, uh, new innovation and products from Harness. Fantastic. Hey, I want to thank you for coming in early before the floor open to do this with us.
Continue to success to you and Jody and the whole harness team. Of course. We'll always be following it along here at Techstrong, but we're gonna let you get back to it 'cause I think they're about to open the floor.
Thank you so much, Alan. Uh, great talking to you. And you have a good time.
Have the conference. Thank you. Thank you.
All right. We're here at Black Hat. We'll be continuing our, I'm just waiting for some trucks to go by here.
It sounds like we'll be continuing our coverage of Black Hat throughout the day and you'll be seeing it on Text Trunk tv. But until then, this is Alan Shimel. We're out.