EASE 2026
Tue 9 - Fri 12 June 2026 Glasgow, United Kingdom

Background. DevOps has become a dominant paradigm in modern software engineering, while low-code development platforms (LCDPs) are increasingly adopted to streamline software development. The integration of these approaches promises efficiency gains but also raises critical concerns regarding security and governance. Despite their growing use, insufficient attention has been given to the implications of these platforms for security and governance in DevOps environment. Aim. This study investigates practitioners’ perspectives on the security and governance implications of LCDPs in DevOps environments. Method. Twelve semi-structured interviews were conducted with IT professionals experienced in low-code and DevOps practices. The data were analysed using a grounded theory approach to identify emergent themes. Results. Findings reveal that LCDPs helps in automation of tasks, however, they increase security risks and governance challenges, highlighting the need for robust practices and a security-conscious culture. Conclusion. This study suggests that the crossroads of DevOps and LCDPs require careful governance and proactive security practices. Addressing these issues is essential for organisations to unlock the potential of LCDPs while safeguarding resilience, compliance, and the needs for developers.

Fri 12 Jun

Displayed time zone: London change

09:00 - 17:00
Software Security Engineering WorkshopSSE-26 Workshop on Software Security Engineering at JMS 707
Chair(s): Mohammad Alshayeb King Fahd University of Petroleum & Minerals, Mahmood Niazi King Fahd University of Petroleum and Minerals
09:00
15m
Day opening
Welcome by the Organizers
SSE-26 Workshop on Software Security Engineering

09:15
15m
Talk
A Multi-Agentic AI Pipeline for Iterative Vulnerability Detection and Auto-Remediation in Python
SSE-26 Workshop on Software Security Engineering
09:30
15m
Talk
An Empirical Security Evaluation of LLM-Generated Cryptographic Rust Code
SSE-26 Workshop on Software Security Engineering
Mohamed Elsayed , Kenneth Fulton , Jeong Yang Texas A&M University-San Antonio
09:45
15m
Talk
Symbolic Execution Meets Multi-LLM Orchestration: Detecting Memory Vulnerabilities in Incomplete Rust CVE Snippets
SSE-26 Workshop on Software Security Engineering
Zeyad Abdelrazek , Young Lee Texas A & M University - San Antonio
10:00
15m
Talk
Low-Code Paradox in DevOps: Security and Governance Insights from Practitioners
SSE-26 Workshop on Software Security Engineering
Muhammad Azeem Akbar LUT University, Saima Rafi Edinburgh Napier University, Arif Ali Khan University of Oulu
10:15
15m
Talk
An Empirical Study of Challenges for Developing Global Cybersecurity Culture
SSE-26 Workshop on Software Security Engineering
Nisar Muhammad , Siffat Ullah Khan University of Malakand, Mahmood Niazi King Fahd University of Petroleum and Minerals, Mohammad Shameem
10:30
30m
Break
Coffee Break
SSE-26 Workshop on Software Security Engineering

11:00
15m
Talk
Pick and Sort for Graphical Authentication
SSE-26 Workshop on Software Security Engineering
Argianto Rahartomo TU Clausthal, Amirhossein Jamshidipoor , Mohammad Ghafari Tehran Institute for Advanced Studies (TEIAS)
11:15
15m
Talk
Runtime Governance of Agent Actions in Agentic AI: Design and Evaluation of a Governance Proxy
SSE-26 Workshop on Software Security Engineering
Petru-Liviu Bouruc , Ciprian Păduraru University of Bucharest, Alin Stefanescu The Institute for Logic and Data Science (ILDS), and University of Bucharest
11:30
15m
Talk
Empirical Evaluation of TLS Communication Overhead in Federated Learning Systems
SSE-26 Workshop on Software Security Engineering
11:45
15m
Talk
Understanding Security Issues in Open-Source Agentic AI Frameworks: An Empirical Analysis
SSE-26 Workshop on Software Security Engineering
Muhammad Hamza Lappeenranta-Lahti University of Technology (LUT), Muhammad Azeem Akbar LUT University, Wardah Naeem Awan LUT University, Muhammad Shoaib