Developing the Skills Needed for Modern Software Development - Keith Hoodlet, Shashwat Sehgal, Ron Rasin - ASW #376
好的,我现在需要帮用户总结一篇文章的内容,控制在100字以内。用户已经提供了文章的详细内容,包括未来的安全软件发展、人类与AI技能的结合、应用安全的趋势、新进入者的挑战,以及身份安全和AI代理的风险。 首先,我得确定文章的主要主题。看起来主要讨论的是安全软件的未来,涉及到人类技能和AI的结合,应用安全的变化,以及身份安全和AI带来的风险。 接下来,我需要将这些信息浓缩到100字以内。要抓住关键点:未来的安全软件是人类技能和AI的结合;应用安全可能面临变化;新进入者需要掌握核心技能;身份安全和AI代理的风险也在增加。 然后,组织语言,确保流畅且信息完整。可能需要提到应用安全的未来趋势、核心技能的重要性、以及身份安全面临的挑战。 最后,检查字数是否在限制内,并确保没有使用“文章内容总结”等开头词。 </think> 未来的安全软件将结合人类与AI技能,应用安全领域可能发生变化。新进入者需掌握核心技能以应对行业挑战。同时,身份安全与AI代理的风险日益突出。 2026-3-31 09:0:0 Author: sites.libsyn.com(查看原文) 阅读量:1 收藏

Mar 31, 2026

The future of secure software is going through a mix of skills expected of humans and skills files created for LLMs. We might even posit that appsec as a discipline will fade (and that might not even be a bad thing!). Keith Hoodlet describes the skills he was looking for in building teams of security researchers and why there's still an emphasis on the ability to learn about and understand how software is built.

But figuring out what skills will get you hired and what skills are valuable to invest in still feels daunting to new grads and others entering the security industry. We discuss where the role of appsec seems to be heading and a few of the security and software fundamentals that can help you follow that direction.

Segment resources

Then, we rebroadcast two interviews from RSAC 2026.

The Identity Crisis of Agentic AI

Identity security is being stretched between legacy infrastructure that was never built to be secure and rapidly emerging AI agents and non-human identities that organizations are quickly adopting. As AI accelerates, identity risk grows alongside it, making agentic security fundamentally an identity challenge—because the more access AI has, the greater both its power and potential risk. In this session, Ron Rasin explores how past gaps in areas like Active Directory and machine identities created today’s blind spots, and why identity must now act as the control plane for AI-driven enterprises, with real-time enforcement before access is granted. He also highlights new innovations and partnerships enabling embedded identity controls across human, non-human, and AI identities, emphasizing that at machine speed, reactive security is no longer enough.

To learn more about Silverfort and their AI Agent product, visit https://securityweekly.com/silverfortrsac.

Privileged by Design: AI Agents and the New Identity Risk to Production Systems

At RSAC this year, the AI conversation is getting more practical. Less “look what agents can do” and more “who’s actually in control when an autonomous system can take real actions across business apps and infrastructure.”

The Moltbook breach and the growing attention on OpenClaw-style agent vulnerabilities put real weight behind that question because they show how quickly agent ecosystems can scale past oversight.

Today we’re talking with Shashwath, CEO of P0 Security, about why identity and authorization are the quiet enablers of modern AI, where teams are losing control as non-human identities explode and what security leaders can do to keep innovation moving without turning access sprawl into enterprise risk.

To learn more about P0 Security, visit: https://securityweekly.com/p0rsac.

Visit https://www.securityweekly.com/asw for all the latest episodes!

Show Notes: https://securityweekly.com/asw-376


文章来源: http://sites.libsyn.com/18678/developing-the-skills-needed-for-modern-software-development-keith-hoodlet-shashwat-sehgal-ron-rasin-asw-376
如有侵权请联系:admin#unsafe.sh