Gen's Curtis Koenig on treating AI agents like human users to prevent security failures

Your backlog of low and medium severity vulnerabilities just became a real threat. AI can now chain them into critical exploits, and the window between exploit discovery and active use is around eight hours. Curtis Koenig, Head of Application Security at Gen, joins the show to explain why treating AI agents like human users is the single most important step security teams can take this year.

CHAPTERS:

00:00 | AI as a security tool

03:09 | The code velocity problem

05:52 | Securing citizen developers

08:06 | Sage, the agent-on-agent model

12:33 | AI agent identity and secrets risk

14:17 | Why engineering shifted right

18:36 | AI-powered attack acceleration

24:02 | Chaining lows into criticals

31:11 | EU Cyber Resilience Act breakdown

38:00 | Getting ahead of AI risk

About the guest
Curtis Koenig is Head of Application Security at Gen, one of the largest consumer security companies, protecting more than 500 million customers. He has spent 25 years in tech security, with experience at Booking.com, Snap Inc., Wells Fargo, Mozilla, Humana, and Microsoft. His focus areas include application security program management, secure code training, bug bounty programs, SAST, SCA, DAST, API security, threat modeling, and secrets detection.

Resources mentioned
Sage (Gen's internal agent-on-agent governance tool)
EU Cyber Resilience Act (first obligations effective September 11; full enforcement December 2027)
Ghidra with MCP integration for reverse engineering
SBOM (Software Bill of Materials) for dependency tracking
Subscribe for more conversations with security leaders building the future of application security and secrets management.

Brought to you by: GitGuardian (https://www.gitguardian.com/)
Meet your host: Eric Fourrier, CEO, GitGuardian
Connect with Curtis Koenig: https://www.linkedin.com/in/curtisko/
Connect with Gen: https://www.linkedin.com/company/gendigitalinc/
Website: http://gendigital.com/