Gen's Curtis Koenig on treating AI agents like human users to prevent security failures
Your backlog of low and medium severity vulnerabilities just became a real threat. AI can now chain them into critical exploits, and the window between exploit discovery and active use is around eight hours. Curtis Koenig, Head of Application Security at Gen, joins the show to explain why treating AI agents like human users is the single most important step security teams can take this year.
CHAPTERS:
00:00 | AI as a security tool
03:09 | The code velocity problem
05:52 | Securing citizen developers
08:06 | Sage, the agent-on-agent model
12:33 | AI agent identity and secrets risk
14:17 | Why engineering shifted right
18:36 | AI-powered attack acceleration
24:02 | Chaining lows into criticals
31:11 | EU Cyber Resilience Act breakdown
38:00 | Getting ahead of AI risk
About the guest
Curtis Koenig is Head of Application Security at Gen, one of the largest consumer security companies, protecting more than 500 million customers. He has spent 25 years in tech security, with experience at Booking.com, Snap Inc., Wells Fargo, Mozilla, Humana, and Microsoft. His focus areas include application security program management, secure code training, bug bounty programs, SAST, SCA, DAST, API security, threat modeling, and secrets detection.
Resources mentioned
Sage (Gen's internal agent-on-agent governance tool)
EU Cyber Resilience Act (first obligations effective September 11; full enforcement December 2027)
Ghidra with MCP integration for reverse engineering
SBOM (Software Bill of Materials) for dependency tracking
Subscribe for more conversations with security leaders building the future of application security and secrets management.
Brought to you by: GitGuardian (https://www.gitguardian.com/)
Meet your host: Eric Fourrier, CEO, GitGuardian
Connect with Curtis Koenig: https://www.linkedin.com/in/curtisko/
Connect with Gen: https://www.linkedin.com/company/gendigitalinc/
Website: http://gendigital.com/