Merging Security with Development with Katie Paxton-Fear | RSAC Conference 2025
Katie Paxton-Fear discusses the critical intersection of security and development at RSAC. The focus is on integrating security into the developer experience, highlighting the shift towards DevSecOps. AI coding tools present security risks, requiring developers to think critically. The concept of vibe coding raises concerns about insecure code implementation. Security professionals must collaborate with developers to enhance trust and prevent vulnerabilities, as illustrated by a success story in the finance sector.
Transcript
Hey, welcome back to Text on tv Live from the show floor at RSAC in Moscone West in San Francisco. I'm your host, Lisa Martin. We have great conversations lined up today, Tuesday, Wednesday, and Thursday.
So stick around. Lots of great content coming your way. My next guest is Dr.
Katie Paxton-Fear, principal security research engineer at Traceable by Harness. Dr. Katie, it's great to have you on text on tv.
It's so exciting to be here. It's so great. I love it.
Like the energy, the mo, like this is so cool. It is. Cool.
Well we appreciate your time. So traceable by harness, this merger was only announced in February. Yes.
It's been a whirlwind too. I bet It has. So really aiming to create this new leader and secure software delivery.
Talk to us about that and how these two powerhouses are going to do just that. So I think quite a lot of the traditional security model has been really focused on security teams. And while that is great and we'd obviously love talking to security teams, actually, you know, it's not just about security teams.
There's a whole, you know, other range of people in an organization. The most important people there are developers, right? And at the end of the day, they're the ones that are developing secure software, right?
They're the ones who are, whose that is their job. That is their mission, their purpose, right? And if you have a software solution, like a security solution, that only speaks to the security engineers, you've kind of missed out a major part of the kind of story there because what about the people who write the code?
And I think really what traceable y Harness is doing and kind of pushing for in the industry has been this move to be, you know, it's not just about security, it's about the developer experience. It's about developers and how do we merge those two worlds together. And often when we speak to our customers, and obviously Harness is a sister company to us and Harness and I, and we share a lot of customers, right?
Okay. Um, when we speak to them, they are the same buyer. They are interested, they want to get both solutions.
Yeah. And so as we see this kind of push towards, you know, from two separate ideas, developers and security Yeah. To DevSecOps.
Yeah. But everything's gotta adapt with IT. Security solutions are moving towards, you know, it's not just about security teams, it's about the developer experience as well.
Are you seeing this kind of rapid convergence of DevOps and security? We've been talking about DevSecOps for a while, but it's a cultural shift, right? Yeah, for sure.
And I think a lot of the early movements of like DevSecOps were very much the cultural, more than the actual shift. Okay. And they still had like quite siloed responsibilities.
And actually what we're now seeing is way more convergence of that and way more, you know, it's not just about security teams and in organizations where developers outnumber security people by, you know, hundreds in some teams, you can't forget them. No. And it's not, you can't be in a situation where you are telling the developers what to do.
It doesn't work. It doesn't feel good for the developers. They don't wanna engage in security.
You have to work with them instead of trying to work against them. Yeah. And I think bringing those two worlds together and really bringing the kind of, making security something developers want to do.
Yeah. Make it something they're excited about, make it products that they really love, will give us so much more secure software. Absolutely.
AI coding tools. I mean, we can't go a day without talking about AI anymore since chat. GPT burst under the scene.
You're an OG AI expert. I'm a hipster. I'm a ai.
Hipster. Hipster. Hipster.
Hipster. I'm Cool. And no, it's cool.
Yeah. But AI coding is also introducing some security risks. Oh yeah.
A hundred. How come Little bit about some of those doors that's opening up and how your solution helps to close those doors. So obviously we've heard a lot about vibe coding.
Yes. That is the term, you know, no programming, no thinking, just vibing with the ai. Just being like, make me a game that allows me to, you know, buy, buy, uh, like cities and buildings and make me a city builder game.
And the AI just does it for you. Yeah. You don't have to think about it.
The problem is you don't have to think about it. Problem. And a lot of developers are using this code and just copying and pasting it and putting it straight in.
And the problem is with ai, you know, security, if you think about the history of computing is such a new kind of idea. You know, these security events like RSA that we're going to now, they're really have become more popular kind of in the last, you know, 10 years. Right.
Programming has been around for years before then. Right. And think about ai, AI statistics.
It has so many more examples of broken code, of code that is insecure because it wasn't much of a thing at the time that it's not surprising that it doesn't know how to secure it. Yeah. Because security is something new.
It's something in the grand scheme of things that is like a blip. And I think really with like vibe coding, you know, it's all about how do we enable developers to use ai. Yeah.
Because we want them to, because this can take, I actually did a vibe coded application recently. I did it in language. I didn't know anything about as like a little test.
Uh, one as someone who knows about security, I was not thinking about security at the time. I wrote it the second it started generating code. Even as someone who has a PhD in security, who knows this is a problem.
Yeah. I just copy and pasted it. I was like, this is too easy.
I'm just gonna get AI to do it all. Okay. And It's a double-edged sword it sounds like.
Yeah, for sure. Yeah. And it's how do we, you know, enable developers to use things like ai but also to think critically about it and actually have, you know, we hear a lot about human in the loop.
Absolutely. Making sure, you know, you're not just coding based on vibes. Yeah.
You are are also coding based on security. Absolutely. Um, and I think really when it comes to what, you know, security solutions, like traceable by harness really do enables that AI revolution gets, you know, that AI develop in the developer's hands, get them using it, get them, you know, experiments with it, having them rely on ai but in a secure way.
Right. In a way where, you know, we are a security company, we thought about security, we know security. Yeah.
And really seeing, you know, that perspective when we're developing the AI and enabling those developers. Right. It, it needs to be factored in and the security from the beginning cannot be bolt on or an afterthought.
Absolutely. And I think when it comes to, you know, the real risk of ai, the real risk of AI is not necessarily in say, AI performing security attacks or anything like that. The real risk is if you've got developers who are just implementing code uncritically Yeah.
And just copying and pasting, you know, whatever the AI gives them, you are just gonna introduce the same security vulnerabilities we solved five 10, like plus years ago. Okay. And my real worry, and you know, the real problem that I think we are gonna start to see really crop up is those old vulnerabilities we've considered solved Yeah.
That we are not even thinking about anymore. Right. Right.
Move past Them and then we are just reintroducing them. Okay. They're gonna get a new lease of life.
And that's what we've seen across quite a lot of, uh, security research. So Vibe coding is also a relatively new concept. This is a buzzword, but this is, this was coined in February Yeah.
A couple of months ago. Are you seeing more of your work really revolving around enabling the developers to understand how, not how to rely on it securely versus just blindly relying on it? It's interesting because I don't think there's a lot of discussion about it at the moment.
Uh, I think there's a lot of like how we enable developers to use ai, but the securely has kind of been missing a little bit. It's kind of not really been talked about as much because I think when it comes to vibe coding at the moment, the problem is, I dunno if you've seen this, there's a Twitter post of somebody who's like, I I coded an application. I don't know anything about programming in this many hours.
Here's the link. And uh, maybe like 12 hours later he followed up with, please stop hacking my application. Oh no.
Um, and then after that he's like, I fixed this problem. And then there was more security anymore. Sure.
Because, and at the end of the day, developers aren't security experts. Right. They're not.
And they don't have to be. And they don't have to be. And you know what?
AI should be secure. That can be a security expert, that can be a security like, um, resource that developers use. It can help them do it.
Unfortunately, kind of what we have at the moment in a lot of the kind of vibe coding application space is more of like a prompt that ends with please implement securely. Ah, and that's it. Like, and if you look at the advice as well, if you look on Twitter and talk, see developers talking about this, uh, they actually list front and center that, um, security is optional.
Really? Yeah. In 2025.
Yeah. They're still thinking Like that. Yeah.
That Shocks me. But I tempting though, like I have to say, as somebody who did this, I was able to implement an application that would've taken, you know, me doing it properly like a, like a week, maybe two weeks in six hours. Wow.
Yeah. And that's the problem. Yeah.
That you wanna have that advantage. The Productivity advantage is there. It's Insane.
It's such a good advantage and to like discount. It is. It's, it's unthinkable.
So we really need to think about, you know, enabling developers, uh, whether or not that looks like, you know, having security in things like the security in the pipeline. Yeah. The ICD.
Yeah. A lot of the work we do at Traceable by Harness is how do we put, uh, API security testing in the CI/CD pipeline, have it something that's automatic, have it something the developers don't think about. And that's, that's kind of where we wanna get to.
We wanna get to a way where they're using the products and they're not really thinking about it. They Don't have to. Right.
Exactly. But it, it seems like from a vibe coding perspective, a lot more awareness needs to be done consistently. What's the ideal in, in this AI era that we're all living and working in?
What's the ideal developer experience? Honestly, that security should be as invisible as we can get it, but still something developers want to engage with. Yeah.
The problem is, is if you are a developer and security becomes a blocker for you, if it's you are trying to write code and it's like, no, sorry, you can't do that. No. This has got, you know, this many vulnerabilities, fix them, you're not able to do it.
If we have that kind of mentality, we are almost like not we're short, like we're just getting in the way and making it annoying. We're making security be the department of no. Mm.
We want to be the people on the development team who know about security, who you can come to. Yeah. We're not gonna add workload to you.
Right. We are gonna be enablers for you. We're gonna make it as easy as possible for you to do your job.
Yeah. That is our job as security, uh, folks and having solutions that kind of use that mentality of, you know, the ideal developer experience is the security team does it. The idea security team experience is that developers do, there's gotta be a middle ground there.
And I think it's how do we invite developers into security spaces, into security tools, get them hands on, get them excited about security, and also be a like member of the team who will say, you vibe code an application. That's so cool. Let's run a security test.
And if it passes, like let's, let's see how we can put this into production or put it into, you know, maybe an internal tool. Right. It's that kind of change from being No, you can't do that.
That's bad security to Yeah. We have tools that can do things like security scanning for this application. You don't have, have worry about it.
Yeah. If it comes back clean, we'll do it. Yeah.
Let's do it. Let's do this together. And if it Doesn't, we can fix it.
All the vulnerabilities Anyway. Yeah. We can fix it together.
It's not, you fail bad, you went f right. You failed your test. Yeah.
It's, we will work together to get your like goal out there. So are are, do you see yourself as a facilitator of the DevSecOps movement and is that evolving fast Enough? I I think every security professional needs to think of themselves as like an ambassador for developers.
You know, I don't think it's as simple as saying, I'm in the security team. That's not my job. Right.
It's moving to a situation where, you know, developers aren't, they don't have to know about security. They have to know maybe a little bit, but they're not experts in it. Yeah.
And they, they don't have to be, they shouldn't have to be. And they wanna, you wanna have a relationship with them where they feel like they can come to you and I And trust. And trust.
Yeah. And once you lose that trust Yeah. Once the developer considers you like a blocker in their workflow, it's so hard to get it back.
Sure. It's so, so hard. Yeah.
And honestly, it's like how do you make your developers not hate you as a security professional? Yeah. But the thing is, we've got a great opportunity, I wanna say that we have a great opportunity to use AI as a bridge between the two and to use it to make both of our lives easier.
I love that. And to, as a bridge enable us. Yeah.
Yeah. So yeah, I do, I see myself as an ambassador and I wanna be the kind of security person who will be there for developers that is on their side that is not working against them. Yes.
But working with them With them Absolutely. In collaboration. Yeah.
And any security person who doesn't see their role like that I think has like a very dated mindset of, you know, what security looks like now in 2025. Yeah. Time to modernize.
I love that you kind of wrap things up with looking at AI as that bridge between the developer, between security and a lot of opportunity there. Last question for you, Katie. Favorite customer story that every really shines light on the value that you're delivering.
So I work in, I work in like the security research side of things. So I obviously see quite a lot of, uh, security attacks. And I will look at attacks and look at, you know, when we see a new vulnerability being released, I'll look at the data and see whether or not our customers have been affected by it.
It's not just me that we've got an entire team that does it. Um, so I would tell you a story from one of these incidents. So we were looking at a, a customer, they worked in the finance industry, so really sensitive regulated.
Yeah. Very regulated. And they, they was, we were noticing some traffic on their servers were a little bit anomalous.
It wasn't an attack per se. This wasn't like, you know, screaming alerts going off, you know, panic, panic, panic. It was just a little bit weird.
Mm. So we went and investigated. We looked at the behavior and we noticed a pattern.
We could see that there were these attacks, these campaigns that attackers were running 80% of traffic on one of their APIs was all attackers. 80%. 80%.
Wow. Now here's the best bit. We looked at this, we gave the results to customers, like, Hey, we blocked it for them.
Of course. Like they were fine. Yeah, yeah.
Yeah. Again, it wasn't that they had like gained a lot of access. It was like an ongoing campaign.
We actually caught them before they were able to do quite a lot of the wow. Kind exfiltration part of it. Fantastic.
So we're like, Hmm, I wonder if this is true for other customers. And we found another customer. We found the same campaign.
Oh, wow. So we were able to detect this. It was for, for the technical people watching, it was inboxing.
We were able to detect it on not just one customer, but multiple. Yeah. And I think it was, so for me as a researcher, it was so cool one to do, to catch it ahead of time.
Sure. Yes. Like, as someone who's a hacker, I spent quite a lot of time talking about the after effect.
Right. Rather than the pre. Um, but it was just so cool to see, hey, you know, this isn't something that just applied to one person.
It's something applied to multiple customers. Yeah. And it's, they're not the only ones that gonna be affected.
No, of course not. It's, it's probably just gonna proliferate. Exactly.
You can spot it, you can find it, you can remedy it. Yeah. Exactly.
Awesome. Great stuff. Katie, thank you so much for joining me on Textron.
I really enjoyed our conversation, really how you're an ambassador. You're, you're an AI hipster. I love that.
An ethical hacker. But thank you for sharing what you're seeing out there and how AI can be that bridge between the developers and the security folks. We appreciate your insights.
Thank you so much for having me. My pleasure, pleasure. Good For Dr.
Katie Paxton-Fear. Fear. I'm Lisa Martin.
You're watching Text on TV Live from RSAC at Moscone West in San Francisco. Stick around. We have more great content coming up.
I'll be back with my next guest in just a few minutes.