Bobby Schwass

Back to the list of Speakers and Sessions

Bobby Schwass , White Knight Labs

Robert Schwass is a senior security engineer and offensive security practitioner with 15+ years of experience designing, breaking, and securing modern application and cloud platforms. He specializes in application security, CI/CD and software supply-chain security, and API security, with deep hands-on expertise across AWS, Kubernetes, GitHub Advanced Security, and infrastructure as code. Robert has led red-team operations, penetration tests, and large-scale security assessments that uncover real-world attack chains—from source control to production—while also building practical security controls that developers actually adopt.

Currently a Principal Product Security Engineer, Robert is known for building enterprise SSDLC programs, automating security at scale, and embedding security directly into code pipelines. His work bridges offensive security and engineering, enabling organizations to ship faster without increasing risk. He holds a Master's in Information Security and multiple industry certifications, including OSCP and several SANS credentials.


Training: Attacking & Securing CI/CD Pipeline Certification (ASCPC)

The Attacking & Securing CI/CD Pipeline Certification (ASCPC) is a practical, results focused course designed for DevOps professionals, security engineers, and developers who need a working understanding of how to secure the fast-changing threat landscape around CI/CD pipelines. The program mixes guided labs with real attack scenarios, so participants learn by doing, not just watching. Throughout the course, learners work directly with modern CI/CD tools such as GitHub Actions, CircleCI, Docker, Kubernetes, Azure DevOps, and AWS CodeBuild. Each lab mirrors realistic threat paths, highlights common weaknesses, and reinforces defensive engineering techniques that teams can apply immediately in their own environments.