Speaking
SPEAKER

Speaking

AI security practitioner with 15+ years in high-stakes environments (banking, defense, aerospace, automotive) — now focused exclusively on agentic AI attack surfaces. Every claim I make in front of an audience has been reproduced in a local lab first.

PhD CISSP 15+ years

About

Amine Raji is an AI security practitioner and independent researcher with a PhD and CISSP certification, and 15+ years of applied security experience spanning banking, defense, aerospace, and automotive sectors.

He focuses at the intersection of cloud infrastructure and AI security — specifically how agentic architectures, MCP deployments, and LLM-integrated pipelines inherit and amplify cloud misconfigurations into a new class of attack.

His work is empirical: every claim he makes in front of an audience has been reproduced in a local lab first. He writes at aminrj.com, publishes the AI Security Intelligence newsletter, and contributes to the OWASP Agentic Security project.

He speaks to practitioners, security architects, and engineering leaders who are deploying AI to production and need to understand the attack surface before it becomes an incident.


Previous Talks

OWASP Stockholm MCP Security talk - first slide

MCP Security, One Year In

OWASP Stockholm · May 2026

Walks through three real MCP attack patterns — tool poisoning, meta-context injection, and cross-server hijacking — with live demonstrations and a concrete threat model for securing agent tool integrations.

View slides →

Available Talks

1

The MCP Attack Surface: What Your Developers Are Installing Right Now

Security engineers, AppSec teams, DevSecOps leads 30–45 min keynote or technical session

The Model Context Protocol has become the de facto standard for connecting AI agents to tools and data. It has also become the fastest-growing attack surface in enterprise AI deployments. This talk walks through three real attack patterns — tool poisoning, meta-context injection, and cross-server hijacking — with live code demonstrations and direct mappings to documented breaches from 2025–2026. Attendees leave with a concrete threat model and a prioritised list of controls they can implement before their next sprint ends.

2

OWASP Agentic Top 10 in Practice: Real Attack Chains, Real Mitigations

Security architects, risk teams, engineering managers 40–60 min keynote or workshop

The OWASP Agentic Top 10 exists. Most teams have read the summary. Almost none have mapped it to their actual systems. This talk takes each of the ten risk categories from abstract definition to concrete attack chain — using real incidents, reproducible lab scenarios, and the specific architectural decisions that made each one possible. It closes with a defensive framework grounded in least agency, strong observability, and human-in-the-loop design. Practical, evidence-based, no vendor agenda.

3

Red Teaming AI Agents: A Practitioner's Field Guide

Red teamers, penetration testers, security researchers 45–60 min technical session

Traditional red teaming methodologies break against agentic AI systems. The attack surface is non-deterministic, execution paths are emergent, and blast radius crosses tool boundaries, memory stores, and inter-agent communication channels simultaneously. This talk presents a structured red teaming methodology for agentic AI — covering goal hijacking, tool chain weaponization, identity spoofing, memory poisoning, and cascading failure induction — built from direct adversarial testing with PyRIT, Promptfoo, and Garak against locally deployed agent architectures.

4

AI Security Threat Modeling Before You Ship

Security architects, engineering leaders, CISOs 45–60 min keynote or workshop

A complete 7-phase methodology for AI threat modeling in production, synthesizing MAESTRO, Microsoft's red team practice, and OWASP frameworks. This talk walks through a real-world threat register example, shows what deliverables look like at the end of a threat modeling exercise, and provides a pre-production checklist mapped to OWASP LLM Top 10 and Agentic Top 10. Practical, evidence-based, no vendor agenda.


Published Thinking

Topics & Expertise

MCP Security OWASP Agentic Top 10 Cloud-Native AI Attack Surfaces Agentic AI Red Teaming RAG Pipeline Security LLM Prompt Injection Multi-Agent Trust Failures AI Incident Response Non-Human Identity & Access Agent Supply Chain Security

Formats

Keynote
20–45 min, all audience levels
Technical Deep-Dive
45–60 min, practitioner audiences
Panel
Practitioner or executive rooms
Workshop
Hands-on, facilitated sessions

All technical talks are backed by reproducible local lab environments — no slide-only claims, no cloud dependencies on stage.

Session Recordings

Slides from past talks will be posted here as they become available.

Follow LinkedIn or X/Twitter for updates.

Invite / Inquire

For speaking invitations, CFP questions, or programme committee discussions:

[email protected]

I respond to all speaking enquiries within 48 hours.