ConversingLabs Podcast
ConversingLabs Podcast

Building Secure AI - A Conversation With Steve Wilson of Exabeam

04 June 2026 50:10 ReversingLabs

Listen to episode

About this episode

Host Paul Roberts welcomes Conversing Labs  guest Steve Wilson, Chief AI and Product Officer at Exabeam and co-chair of the OWASP GenAI Security Project. Steve discusses his path from early programming to AppSec at Contrast Security and leading the OWASP Top 10 for LLMs, which grew into a large community and later an Agentic Top 10.

Wilson explains AI’s recent leap via transformer architecture, cloud scale, and GPUs, and describes Exabeam’s evolution from SIEM and behavior analytics to generative and agentic AI with multiple security agents. He summarizes his 2024 O’Reilly book expanding OWASP risks into case studies and secure development practices, emphasizing that AppSec alone is insufficient for autonomous agents, requiring monitoring and “agent behavior analytics.” The conversation highlights AI supply chain risks (models, plugins/MCP, OpenClaw skills, fake Chrome extensions), scoping/least privilege, and the practical impact of tools like Claude Code on AppSec and security operations.

00:00 Welcome and Guest Intro
02:35 Steve’s Cyber Journey
04:13 OWASP LLM Top 10 Origins
06:21 From LLMs to Agents
06:59 Tron and AI History
09:32 Why Transformers Changed Everything
11:35 What Exabeam Actually Does
16:08 Writing the LLM Security Book
20:27 Agent Risks Beyond AppSec
22:05 What Changed Since 2024
23:30 Reasoning Models and Strawberry
26:18 Agentic Top 10 and Supply Chain
27:11 Hallucinated Dependencies
27:47 Model Supply Chain Trust
28:57 Plugins And Agent Exploits
29:58 MCP And Skills Risks
31:01 Chrome Plugin Trap
33:47 RAISE Framework Overview
35:12 Monitoring Digital Workers
38:40 Scoping And RAG
41:44 Excessive Agency Controls
43:02 Sandboxed Assistant Build
45:16 AI Impact On Infosec
49:15 Closing And Contact

Want to find AI jobs?

Join thousands of AI professionals finding their next opportunity

We respect your inbox. Unsubscribe at any time.

© 2026 ConversingLabs Podcast. All rights reserved.

Common Questions

Frequently asked questions

Quick answers about how DevFound's AI matching, resumes, and referrals work.

DevFound's AI Copilot ingests your profile, goals, and live job data to deliver curated matches in seconds. Every match includes a resume variant, suggested referrals, and interview prep so you can act immediately. The more feedback you provide, the sharper the Copilot becomes.

AI-led job searches shrink the hours spent sifting through boards and formatting resumes. DevFound pairs automation with your personal outreach, so you reserve energy for interviews and negotiation. Traditional networking still matters, but AI gives you a lift before you even send a message.

Modern AI roles expect comfort with production-grade code, data fluency, and practical ML tooling. The strongest candidates pair deep technical chops with storytelling—translating model impact to product, GTM, and exec partners. Continuous learning keeps you ahead as stacks evolve.

DevFound rewards active seekers. Keep your profile fresh, respond to match quality prompts, and enable alerts so you never miss a role. The AI prioritizes companies and teams that align with your feedback, accelerating both introductions and interview invites.

High-density tech hubs continue to host the deepest AI talent pools, yet distributed teams are catching up fast. Use DevFound filters to hone in on onsite, hybrid, or fully remote roles and watch openings expand across time zones.

DevFound aggregates thousands of remote AI openings and flags the nuances—core hours, async culture, and visa needs—up front. The Copilot also recommends how to position your distributed work experience so hiring managers know you can thrive on a remote team.