
Joseph Katsioloudes - Code Security Reinvented: Navigating the era of AI - AI Native DevCon June 26
Source: YouTube · AI Native Dev · published Jul 13, 2026 · 35:08
AI can help bridge the massive gap between security specialists and developers (1:100 ratio), but it requires a human-in-the-loop approach to handle inherent limitations like hallucinations and non-determinism 2:03-2:18.
Key Takeaways:
• The real cybersecurity challenge is a fixing problem, not a detection problem—AI excels as a reasoning layer to accelerate remediation 6:31-6:59.
• Model Context Protocol (MCP) extends AI context by pulling server-side security findings into your CLI or IDE, enabling more focused reasoning 10:12-10:58.
• Combining MCP with structured "skills" creates auditable, maintainable workflows that translate findings into automated fix-and-PR pipelines 11:08-12:14.
• Fixing vulnerabilities directly in pull requests makes teams 3x faster—GitHub fixed 600 vulnerabilities in two weeks using this approach 14:37-15:27.
• Agentic workflows allow tailored security scanning with custom scripts, while "task flows" codify expert researcher knowledge for automated manual-style reviews 16:01-19:45.
AI is not a replacement for traditional static analysis or good security hygiene—it's a complementary layer that, when combined with deterministic tooling and human oversight, can meaningfully close the security talent gap.
Sources:
- 2:03-2:18 The 1:100 security-to-developer gap and AI's opportunity
- 6:31-6:59 Cybersecurity has a fixing problem, not a detection problem
- 10:12-10:58 MCP servers pull server-side findings to extend AI context
- 11:08-12:14 Skills provide auditable structure for security workflows
- 14:37-15:27 PR-based fixing yields 3x speed improvement
- 16:01-19:45 Agentic workflows and task flows for tailored security
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
So our first talk today is by the one and only Joseph Katsioloudes. Joseph is a senior developer advocate at a company called GitHub. Raise your hand
if you have heard of GitHub. Okay. Okay, so you're getting a little traction. Good for you guys. Really proud of you. So no pressure to speakers after this. But Joseph has spoken in over 25 countries and has over
2.8 million views on his videos. Again, no pressure, but he is a
seasoned pro so you're in very good hands. Can we get a little round of applause
for Joseph, please? Take it away. Okay. Good morning everybody. Well, perfect. Welcome to Code Security Reinvented. Navigating the area
of artificial intelligence. My goal today is to show you practical ways to use
artificial intelligence for security use cases.
Whatever I show you, you can…