Discussion with Omar Santos, Distinguished Engineer at Cisco.
Omar Santos: https://www.linkedin.com/in/santosomar/
CoSAI: https://www.coalitionforsecureai.org/
Summary
In this conversation, Omar Santos, a distinguished engineer at Cisco, discusses his extensive background in cybersecurity and the evolving role of AI in security practices. He shares insights on the challenges of network security, the importance of responsible AI, and the impact of open source on vulnerability management. The discussion highlights the dual nature of AI technology, emphasizing both its potential benefits and the pressing challenges it presents in the cybersecurity landscape. In this conversation, Omar Santos and Justin Somaini discuss the evolving landscape of open source security, the formation of the Coalition for Secure AI (CoSAI), and the introduction of Code Guard as a solution to enhance security in AI development. They emphasize the importance of collaboration among organizations to address vulnerabilities and the need for compensating controls in the face of rapid technological advancements. The discussion highlights the significant impact of Code Guard in reducing vulnerabilities in AI-generated code and the straightforward implementation process that can be adopted across various coding agents. In this conversation, Omar Santos and Justin Somaini discuss the evolving role of AI in software development, particularly in code review and vulnerability management. They explore the challenges of human coding practices, the potential of AI to refactor and modernize code, and the importance of eliminating unused features to reduce risk. The discussion also touches on the differences between corporate and production AI adoption, the need for centralized services for secure development, and the call to action for improving open source security practices.
Chapters
00:00 Introduction to Omar Santos and AI Security
01:15 Omar Santos' Background and Career Journey
03:13 Challenges in Network Security and Maintenance
06:29 The Role of AI in Security Practices
07:11 Omar's Early Experiences with AI and Machine Learning
10:07 Responsible AI and Its Importance
12:57 Cisco's Exploration of LLMs and AI Integration
17:07 The Dual Nature of AI in Security
19:14 Current Vulnerability Management Challenges
24:40 The Impact of Open Source on Security
28:04 The State of Open Source Security
31:43 Introducing CoSAI: Coalition for Secure AI
37:24 Code Guard: Enhancing Security in AI Development
46:57 Implementation and Impact of Code Guard
53:51 The Evolution of AI in Code Review
55:11 Human vs AI: Coding Vulnerabilities
56:27 Refactoring Code with AI
58:23 Eliminating Unused Features to Reduce Risk
60:28 The Importance of Modernizing Technology
62:00 The Challenge of Unused Features in Software
64:30 Corporate vs Production AI Adoption
66:53 Centralized Services for Secure Development
69:03 The Wild West of AI Experimentation
72:33 Preparing for AI Security Challenges
75:15 Call to Action for Open Source Security
Keywords
AI security, Omar Santos, Cisco, vulnerability management, machine learning, responsible AI, network security, open source, cybersecurity, incident response Open Source Security, AI, CoSAI, Code Guard, Vulnerability Management, Cybersecurity, Cisco, Machine Learning, Security Best Practices, Software Development Life Cycle AI, code review, vulnerabilities, refactoring, software security, open source, corporate adoption, technology modernization, risk management, coding agents