Jim Manico on stage

Talks, workshops, and events

Jim teaches developers how to build secure software with a focus on AI security and methods. This page keeps a verified list of upcoming public sessions and a curated archive of past talks on AppSec, OWASP, React security, supply chain risk, and AI-assisted secure coding.

Last researched and verified from public conference pages on April 8, 2026.

  • 7 upcoming sessions on the calendar
  • 9 selected past talks
  • Focus: AppSec, OWASP, React, AI security
Secure Coding Defensive engineering for web apps, APIs, authentication, dependency risk, and practical mitigation.
AI Security Using AI safely for code creation and securing AI systems, pipelines, prompts, and model operations.
Modern Frontend React security, XSS prevention, SSR tradeoffs, component boundaries, and client-side trust failures.

Upcoming Talks

Upcoming speaking engagements and training sessions.

Verified Public Event

Secure Code with AI: Live Workshop

  • Date: Thursday, April 9, 2026, 10:00 AM PT
  • Venue: Live on Zoom
  • Location: Remote

Join Jim Manico for a free 60-minute live session on setting up a secure Claude Code environment, using the Manicode Secure Coding Prompts, and coding with Claude Code and Codex together.

  • Live demos with secure defaults, prompts, and workflow guidance.
  • Practical examples you can apply to your own codebase immediately.
  • Open Q&A for setup, prompts, and secure AI coding questions.
Verified Public Event

OWASP London Chapter Meetup [IN-PERSON]

  • Date: April 14, 2026, 6:00 PM BST
  • Venue: OWASP London
  • Location: London, United Kingdom

The OWASP London chapter lists this as an in-person meetup with livestream availability and a recording to follow on the chapter's YouTube channel. The public listing does not yet expose the final talk lineup in the search snippet, so the page keeps the event visible now and can be updated with Jim's exact session title once published.

  • OWASP chapter talks are where practical AppSec ideas usually get sharpened the fastest.
  • Local communities still matter because they convert standards into field-tested advice.
  • Good AppSec talks leave teams with actions, not slogans.
Verified Public Training

AppSec and AI Security for Developers with Jim Manico

  • Date: June 22-24, 2026
  • Venue: OWASP Global AppSec EU 2026 training
  • Location: Vienna, Austria and remote

A three-day hybrid beginner course where students choose the modules that matter most, spanning core AppSec, API security, OWASP Top 10 for LLM Applications, AI for code creation, and React security prompt engineering.

  • Pick-your-path training works because engineering teams do not all need the same material.
  • Modern developer training has to connect classic AppSec with AI-native risks.
  • React security prompt engineering is now part of real secure coding practice.
Direct Calendar Entry

OWASP Los Angeles Chapter Appearance

  • Date: July 22, 2026
  • Venue: OWASP Los Angeles
  • Location: Los Angeles, California

This chapter date is on the calendar and will be updated with the final session title and registration link once the public OWASP LA listing is posted.

  • Chapter sessions are often the best place to pressure-test new secure coding material.
  • Security education lands better when it is rooted in examples engineers actually ship.
  • AI security and AppSec are converging into one engineering conversation.

Selected Past Talks

This is a curated archive, not a complete speaking history. Each entry is backed by an official conference page, chapter page, or direct recording link.

June 2, 2025

Using AI to write Secure React.JS code

  • Venue: SecAppDev 2025
  • Location: Leuven, Belgium

A deep-dive lecture on improving AI-assisted code generation for React so the output is not just functional, but structurally safer and more reviewable.

June 6, 2025

Secure Coding Workshop

  • Venue: SecAppDev 2025
  • Location: Leuven, Belgium

A full-day hands-on workshop covering injection, XSS, authentication weaknesses, insecure dependencies, secure APIs, file upload risk, and AI-assisted code generation in practice.

May 29, 2025

Leveraging AI for Secure React Development with Effective Prompt Engineering

  • Venue: OWASP Global AppSec EU 2025
  • Location: Barcelona, Spain

A conference session on teaching AI coding assistants the React security rules they need so generated code is less fragile, less unsafe, and easier to ship responsibly.

June 3, 2024

AI Security: Essentials to Advanced

  • Venue: SecAppDev 2024
  • Location: Leuven, Belgium

A concise map of AI security issues spanning LLM risk, reliability, privacy, regulation, threat modeling, and the operational decisions that shape safe deployment.

June 4, 2024

Building Secure ReactJS Applications

  • Venue: SecAppDev 2024
  • Location: Leuven, Belgium

A React-focused security lecture covering XSS, props, JSON embedding, CSS, template injection, SSR, and the framework-specific places developers still get cut.

June 14, 2023

Third-party library security management

  • Venue: SecAppDev 2023
  • Location: Leuven, Belgium

A practical dependency-management talk on reducing library sprawl, vetting what you import, and keeping components current enough to avoid self-inflicted supply-chain risk.

June 14, 2023

The unabridged history of application security

  • Venue: SecAppDev 2023 keynote
  • Location: Leuven, Belgium

A keynote that argues AppSec history is not a story of endless failure, but of slow, measurable improvement in standards, defaults, and defensive engineering.

August 2023

Architecting Fortresses: ReactJS Security

  • Venue: OWASP Cincinnati with CinciJS
  • Location: Cincinnati, Ohio

An advanced React security talk on client-side trust boundaries, XSS defense, component attack surface, template injection, and server-side rendering concerns.

November 2019

The Unabridged History of Application Security

  • Venue: AppSec California 2019 closing keynote
  • Location: Santa Monica, California

A well-known keynote tracing AppSec from the early era of plaintext passwords and poor defaults to the present, with the core message that the industry is improving faster than many practitioners admit.

Research Topics

  • Secure coding practices as a primary risk reduction strategy, including in AI-assisted development workflows
  • Human oversight requirements for AI-generated code: standards, review, and testing
  • Frontend trust boundaries and the limits of framework-level security
  • Security implications of third-party dependency management
  • Applying OWASP guidelines as practical engineering decision frameworks

Event Notes

  • Archive entries are intentionally selective and source-backed rather than exhaustive.
  • Where recordings or slides were easy to verify, they are linked directly.
  • If you want a talk listed here, email jim@manicode.com.