Loading…
June 26, 2025 | Denver, Co
Learn More and Register To Attend

The Sched app allows you to build your schedule, but it is not a substitute for event registration. To participate in the sessions, you must be registered for OpenSSF Community Day NA 2025. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

Please note: This schedule is automatically displayed in Mountain Daylight Time. To see the schedule in your preferred timezone, please select from the drop-down located at the bottom of the menu to the right.

Schedule is subject to change.
Thursday June 26, 2025 4:10pm - 5:40pm MDT
The TTX is open to all Community Day attendees as audience observers and will be divided into two main phases:
  • Phase One: Scenario Walkthrough
    A moderated panel of experts will walk through a security incident scenario, each stepping into a specific role, such as an open source maintainer, a package registry operator, an open source software consumer, etc. Through roleplay, panelists will demonstrate how each stakeholder might respond during a real-world incident.
  • Phase Two: Postmortem & Discussion
    Following the scenario, panelists and selected contributors will engage in a collaborative debrief. They’ll reflect on how the incident played out, share insights, and identify opportunities for improving coordination, tools, and response processes.
This session brings together professionals with expertise in open source software production, distribution, vulnerability management, and incident response.
  • Audience members will have the opportunity to engage through a dedicated Q&A session and can submit questions throughout the exercise using Slido or a similar platform.
  • Through participation in the TTX, attendees will:
    • Deepen their understanding of open source software security and incident response.
    • Gain access to a template or framework for running their own tabletop exercises.
    • Explore how OpenSSF tools and technologies can support response efforts.
    • Discover opportunities for process improvement or new tooling in security workflows.

Speakers
avatar for Yesenia Yser

Yesenia Yser

Sr. Security Program Manager, Microsoft
As a cybersecurity expert, Yesenia has managed global crises with the unique skill set she’s gained as a practitioner and instructor in Brazilian Jiu Jitsu. During her 12 year career, she’s helped Fortune 100 companies strategize their software supply chain security risks and... Read More →
avatar for John Kjell

John Kjell

Principal Consultant, ControlPlane
John is a maintainer for the Witness and Archivista sub-projects under in-toto. Additionally, John is an active contributor to CNCF's TAG Security and multiple projects within the OpenSSF. Before TestifySec, John was an engineering leader at VMware, helping to bring supply chain security... Read More →
avatar for Tabatha DiDomenico

Tabatha DiDomenico

OSS Security Engineer, G-Research
Tabatha is an OSS DevRel Engineer at G-Research bringing over two decades of experience in community development, IT, and cybersecurity to the role. She holds an MS in Cybersecurity from the University of South Florida and a BA in Interdisciplinary Studies from the University of Central... Read More →
avatar for Seth Larson

Seth Larson

Security Developer-in-Residence, Python Software Foundation
Seth is the Security Developer-in-Residence at the Python Software Foundation working to improve the security posture of the Python ecosystem. Seth maintains widely used open source Python projects like urllib3, truststore, and Requests.
avatar for Mihai Maruseac

Mihai Maruseac

Staff Software Engineer, Google
Mihai Maruseac is a member of Google Open Source Security team (GOSST), working on Supply Chain Security, specifically for ML, but also a GUAC maintainer. Before joining GOSST, Mihai created the TensorFlow Security team after joining Google, moving from a startup to incorporate Differential... Read More →
avatar for Christopher Robinson

Christopher Robinson

Chief Architect - OpenSSF, OpenSSF
Christopher Robinson (aka CRob) is the Chief Security Architect for the Open Source Security Foundation. With over 25 years of Enterprise-class engineering, architectural, operational and leadership experience, CRob has worked at several Fortune 500 companies with experience in the... Read More →
Thursday June 26, 2025 4:10pm - 5:40pm MDT
Bluebird Ballroom 3B

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link