Insecure Agents is a podcast that curates the most important conversations and trends in AI security. AI engineers, CISOs, and security practitioners listen to learn how to give their agents the security they need to reach higher levels of capability and autonomy.

Allie Howe

ALLIE HOWE HOST

Allie Howe is a Member of Technical Staff at Keycard and has a background in security engineering. She is a core contributor to the OWASP Agentic Security Initiative and has spoken at AI Engineer World's Fair and AI Agent Security Summit.

𝕏 @vtahowe in /allisonhowe

Back to episodes
Jet Anderson — Distinguished Engineer at GEICO
#57 Sep 3

Episode 57 · Sep 3

The Agentic SDLC: Why Most of Software Security Has to Change, with Jet Anderson (GEICO)

Jet Anderson · Distinguished Engineer at GEICO

--:--

Jet Anderson is a Distinguished Engineer at GEICO and leads the transformation of their product security function. He joins us to discuss the agentic SDLC and why most of what security teams do has to change while the first principles should stay the same.

We get into why static analysis and human triage no longer keep pace when models write the code, why we need new AI infrastructure, and why the Hugging Face sandbox escape was a decade-old Kubernetes misconfiguration found at machine speed.

Jet tells us the story of when he asked his own agent to "wrap this up" and it merged the PR and did an unauthorized production deploy. He walks through the pre-commit hooks and branch protections he built to prevent this from happening again so that deploys still get an approval gate and an audit trail.

He also explains why teams that skip ideation, design, and specification to go straight to code end up with less secure software the more they iterate, and why the unglamorous answer is doubling down on least privilege, egress control, and build containment.

Listen on