Speaking
AI security practitioner with 15+ years in high-stakes environments (banking, defense, aerospace, automotive) — now focused exclusively on agentic AI attack surfaces. Every claim I make in front of an audience has been reproduced in a local lab first.
About
Amine Raji is an AI security practitioner and independent researcher with a PhD and CISSP certification, and 15+ years of applied security experience spanning banking, defense, aerospace, and automotive sectors.
He focuses at the intersection of cloud infrastructure and AI security — specifically how agentic architectures, MCP deployments, and LLM-integrated pipelines inherit and amplify cloud misconfigurations into a new class of attack.
His work is empirical: every claim he makes in front of an audience has been reproduced in a local lab first. He writes at aminrj.com, publishes the AI Security Intelligence newsletter, and contributes to the OWASP Agentic Security project.
He speaks to practitioners, security architects, and engineering leaders who are deploying AI to production and need to understand the attack surface before it becomes an incident.
Previous Talks
MCP Security, One Year In
Walks through three real MCP attack patterns — tool poisoning, meta-context injection, and cross-server hijacking — with live demonstrations and a concrete threat model for securing agent tool integrations.
View slides →Available Talks
The MCP Attack Surface: What Your Developers Are Installing Right Now
The Model Context Protocol has become the de facto standard for connecting AI agents to tools and data. It has also become the fastest-growing attack surface in enterprise AI deployments. This talk walks through three real attack patterns — tool poisoning, meta-context injection, and cross-server hijacking — with live code demonstrations and direct mappings to documented breaches from 2025–2026. Attendees leave with a concrete threat model and a prioritised list of controls they can implement before their next sprint ends.
OWASP Agentic Top 10 in Practice: Real Attack Chains, Real Mitigations
The OWASP Agentic Top 10 exists. Most teams have read the summary. Almost none have mapped it to their actual systems. This talk takes each of the ten risk categories from abstract definition to concrete attack chain — using real incidents, reproducible lab scenarios, and the specific architectural decisions that made each one possible. It closes with a defensive framework grounded in least agency, strong observability, and human-in-the-loop design. Practical, evidence-based, no vendor agenda.
Red Teaming AI Agents: A Practitioner's Field Guide
Traditional red teaming methodologies break against agentic AI systems. The attack surface is non-deterministic, execution paths are emergent, and blast radius crosses tool boundaries, memory stores, and inter-agent communication channels simultaneously. This talk presents a structured red teaming methodology for agentic AI — covering goal hijacking, tool chain weaponization, identity spoofing, memory poisoning, and cascading failure induction — built from direct adversarial testing with PyRIT, Promptfoo, and Garak against locally deployed agent architectures.
AI Security Threat Modeling Before You Ship
A complete 7-phase methodology for AI threat modeling in production, synthesizing MAESTRO, Microsoft's red team practice, and OWASP frameworks. This talk walks through a real-world threat register example, shows what deliverables look like at the end of a threat modeling exercise, and provides a pre-production checklist mapped to OWASP LLM Top 10 and Agentic Top 10. Practical, evidence-based, no vendor agenda.
Published Thinking
- aminrj.com — Research and writing on agentic AI security, cloud security, and defensive architectures
- AI Security Intelligence — Weekly newsletter: threats, vulnerabilities, and defensive innovations in AI security
- OWASP Agentic Security project — Contributor to the Agentic Security Initiative
Topics & Expertise
Formats
All technical talks are backed by reproducible local lab environments — no slide-only claims, no cloud dependencies on stage.
Session Recordings
Invite / Inquire
For speaking invitations, CFP questions, or programme committee discussions:
[email protected]I respond to all speaking enquiries within 48 hours.