SPEAKER · TRAINER · SECURITY & AI

Nobody ever fixed a system by watching a slide.

I run talks and workshops on security and AI where your engineers put hands on their own stack and leave with the thing built. Fifteen years doing the work, still doing it, allergic to fear-selling.

Ken Toler speaking at Filecoin Dev Summit
FILECOIN DEV SUMMIT — ON STAGE
OWASP GLOBAL APPSEC DUBLIN·BARCELONA·LASCON·FILECOIN DEV SUMMIT·APPSEC CALIFORNIA·DERBYCON

Workshops

8–30 PEOPLE · HALF OR FULL DAY · YOUR STACK, NOT A SANDBOX

I bring the structure, the failure modes, and the uncomfortable questions about what your controls actually prove.

FULL DAY Threat Modeling With Agents in the Loop Four questions against your live architecture with an agent driving. You leave with a validated model and the harness that keeps it current. FULL DAY Infrastructure as Remote Code Execution Your pipeline is a shell somebody else can reach. We break it, then fix it, and the fixes go home with you. HALF DAY Shipping Code Nobody Wrote Autonomous development moves the review gate. We build the pipeline that carries the judgment, without stopping delivery. HALF DAY A Program Engineers Don't Route Around Leadership session. Grade the program on evidence instead of paperwork, and find out which controls aren't real.
The Power of DevSecOps in Web3 and Blockchain, OWASP Global AppSec Dublin 2023 The Power of DevSecOps in Web3 & Blockchain OWASP GLOBAL APPSEC · DUBLIN 2023 · WATCH →
Ken at a whiteboard reading Infrastructure as Remote Code Execution LASCON — INFRASTRUCTURE AS RCE
Ken teaching lockpicking at an AppSec training event LOCKPICKING NIGHT — APPSEC TRAINING

Talks

A DECADE ON STAGE · MOST OF IT RECORDED
2025 OWASP Global AppSec EU, Barcelona Speaker.
2024 · WATCH Prove and Protect: Unsealing Project Success with the FF Maturity Model FIL Dev Summit, Brussels. We developed a new security maturity model for web3 — this is how projects use it to prove their security is real. 2023 · WATCH The Power of DevSecOps in Web3 & Blockchain OWASP Global AppSec, Dublin. Why decentralized systems still fail in centralized ways, and what a pipeline can prove.
2023 Infrastructure as Remote Code Execution LASCON. Two-day training with Mike McCabe. Also delivered as the workshop above.
2023 Security Leadership ModernCISO Cyber Summit. Speaker.
2019 · WATCH Cloud Security at Scale DevSecOps Days. What actually breaks when the account count outgrows the security team. 2016 · WATCH Metaprogramming with Ruby DerbyCon. Code that writes code, and the ways that goes wrong. 2015 · WATCH SQL Viking AppSec California, with Jonn Callahan. Pillaging databases the old-fashioned way. 2014 · WATCH Metaprogramming: How to Do It Wrong LASCON, with Mike McCabe.
Ken Toler
KEN TOLER · NEW YORK
FOUNDER, ASGARD SECURITY

Who's actually standing up there

Fifteen years building security programs inside companies that badly needed one — Web3 and blockchain, cloud at scale, and now AI systems that write and ship code. I run Asgard Security, and I co-host Relating to DevSecOps, where I've spent 80-something episodes asking practitioners what actually broke.

Off the clock: ESP32 boards and a soldering iron, a long-running Curse of Strahd campaign, singing, and strong opinions about headphones. I learn by building, which is the whole reason my workshops look the way they do.

Appearances

Other people's microphones. Full episodes, no charge.

RELATING TO DEVSECOPS
80+ episodes, still recording

Developers, operators and security folks on where the handoffs break. Unsponsored, and it's going to stay that way.

Book the room. I'll bring the hard questions.
ken@kentoler.com