Roman Zhukov

Principal Security & Community Architect at Red Hat

Speaker's Bio

Roman is a cybersecurity expert, engineer, and leader with over 17 years of hands-on experience securing complex systems and products at scale. Currently Principal Architect at Red Hat, he leads open-source security strategy, upstream collaboration, and cross-industry initiatives focused on building trusted ecosystems. He has built and scaled programs across security architecture, threat modeling, secure development, vulnerability management, incident response, and security education – for both engineers and senior leadership. His work spans trusted AI, privacy, compliance, and secure software supply chains. Previously, Roman led Product Security & Privacy for Data Center and AI software at Intel. He is a Security Champion for several open-source projects and an active contributor to working groups under the OpenSSF, Eclipse Foundation, and other global initiatives. He is an official member of CEN/CLC and ETSI standardization groups, contributing to the EU Cyber Resilience Act (CRA).

Roman is a cybersecurity expert, engineer, and leader with over 17 years of hands-on experience securing complex systems and products at scale. Currently Principal Architect at Red Hat, he leads open-source security strategy, upstream collaboration, and cross-industry initiatives focused on building trusted ecosystems. He has built and scaled programs across security architecture, threat modeling, secure development, vulnerability management, incident response, and security education – for both engineers and senior leadership. His work spans trusted AI, privacy, compliance, and secure software supply chains. Previously, Roman led Product Security & Privacy for Data Center and AI software at Intel. He is a Security Champion for several open-source projects and an active contributor to working groups under the OpenSSF, Eclipse Foundation, and other global initiatives. He is an official member of CEN/CLC and ETSI standardization groups, contributing to the EU Cyber Resilience Act (CRA).

2025 AI

Restoring Trust in Open-Source AI: Security Starts with Provenance

Fri 21 Nov 2025 • AI • 15:00 (CET)
Stage 2

Open-source AI is shaping how we build, deploy, and scale systems and applications today, right into production. But with the rapid adoption of upstream AI models, datasets, and orchestration tools comes a critical question: can we trust what we’re using and how it was originally created? According to PwC survey, about 50% of surveyed company leaders in 2025 admitted they don’t trust AI to be embedded in their core operations.
Unlike focusing on securing AI systems themselves, in this talk we’ll explore often overlooked topic – how data provenance, model transparency, and AI-specific supply chain security are becoming essential for building trustworthy AI systems.
I’ll cover the importance of data provenance and how they reduce risks like data poisoning, bias, and adversarial manipulation; the rise of the AI Software Bill of Materials (AI SBOM) to document model components and inference behavior; open-source tools that bring it all to life: Sigstore, KitOps, Model and Data Cards.
I will also share updates from our work in top AI standardization organizations like OASIS, OpenSSF, and LF AI & Data to define and support AI provenance standards, automation, and trusted AI guidelines.

Agentile Teams: Where AI, Platform Engineering, and Human Creativity Redefine Software Delivery

What if your engineering team could move at the speed of AI – without sacrificing quality, security, or control? Enter the Agentile Team: a lean, AI-powered, and platform-enabled evolution of Agile, designed to amplify human creativity.

In this session, we’ll explore how Agentile teams codify architectural tradeoffs (security, capacity, cost) into specs, templates, and guardrails, enabling rapid experimentation and smarter decision-making from day one. Drawing on real-world experiments and platform engineering principles, Suzanne will share practical strategies for developers and platform engineers to thrive in this new era of agentic, high-velocity software delivery.

Context Engineering Workshop: Make the most out of your AI Tools

Most developers use AI coding tools like a search engine: type a question, hope for a good answer. But the teams getting real results are engineering the context: configuring system prompts, structuring project knowledge, and managing the AI’s working memory like a first-class architectural concern.

This workshop is built around a real coding project. Participants will receive a small application to build – and throughout the session, they’ll apply each technique as they learn it, experiencing firsthand how context engineering transforms their AI’s output quality.

We’ll cover:

– **The context window** – what tokens are, what counts as context, and why your AI gets worse mid-conversation (context rot)
– **Basic prompting techniques** – prompt engineering is no longer as important, but can still improve your results
– **System prompts as project configuration** – set up instruction files (CLAUDE.md, copilot-instructions.md) that make every AI interaction project-aware
– **Grounding techniques** – anchor AI output in real data instead of letting it guess, using file uploads, documentation references, and structured retrieval

Each concept is immediately put into practice on the project – so by the end, participants will have both a working application and a repeatable playbook for getting better results from any AI coding tool.

Targeted to software engineers, bring a laptop with an AI coding assistant installed.

The Missing Protocol: How MCP Bridges LLMs and Data Streams

Nobody’s talking about this: MCP isn’t just another way to build chatbots. It’s the bridge we’ve been missing between AI reasoning and real-time data systems.
Teams build AI applications that work great in demos but fall apart with production data. Your agents analyze historical reports but can’t tell what’s happening in your Kafka streams. They’re blind to schema changes and disconnected from events that matter to your business.
Instead of treating streaming platforms like black boxes, you expose them directly to your agents via MCP protocol. Suddenly, your AI doesn’t just read about data—it lives inside your data flows.
Learn what becomes possible when you stop thinking about AI as an external service and start treating it as part of your streaming architecture. We’ll build systems where agents subscribe to real-time events, reason about evolving schemas, and make decisions that ripple through your data platform.

Architectural Katas: Practicing System Design

Architectural Katas were created by Ted Neward to solve a problem: architects rarely practice their craft. Most people design systems only a handful of times in their careers, so they never develop the judgment that comes from repetition.

The kata format creates those practice opportunities. Teams work on realistic architectural problems, make design decisions, and defend those decisions when challenged. The learning happens when you see other teams solve the same problem differently and understand the assumptions behind each approach.

We run these sessions at Epignosis because our engineers need that practice too. It’s one of the few ways to develop architectural judgment outside of production systems.

This workshop is for anyone who wants that practice. You might be a developer learning to think architecturally, a tech lead seeking feedback on your decisions, or an architect wanting more repetitions. The format works because it forces clear articulation and exposes you to alternatives.

Elephant Carpaccio: the art of thin slicing

Most features arrive late, break things, and hide complexity until it hurts. Branch deployments are a rigged game: merge early and you break things, merge late and integration becomes a nightmare. Whatever you do, you lose. The only way to win is to stop playing.

Enter Elephant Carpaccio, a software development exercise that teaches vertical slicing, incremental delivery, and how to keep software deployable at all times. Instead of delivering the whole elephant at once, you learn to carve it into the thinnest possible slices: each one small, end-to-end, deployable, and providing visible progress. The goal isn’t to finish the feature. It’s to learn how to evolve software safely.

In this hands-on workshop, you’ll practice exactly that. You’ll feel the difference between fat slices and thin ones, and walk away with a technique you can apply the very next day.

If you’ve got PTSD from releases, this one’s for you.

Disclaimer: No actual elephants will be harmed during this workshop

Zero to MVP: Build & Deploy an Airbnb Clone with AI in 60 Minutes

The traditional barrier to entry for building software is gone. We have officially entered the era of “Vibecoding” and Agentic Engineering, where AI agents act as your personal development team, and your main job is to orchestrate them.

In this highly interactive, 60-minute code-along workshop, we will demystify AI-Augmented Development. You don’t need months of tutorials to build a startup MVP. Together, we will build a functional booking platform UI (an “Airbnb clone”) from scratch using Next.js and Tailwind CSS, entirely guided by AI.

Zero Setup Required: We will use browser-based AI IDEs (like Replit Agent or v0 by Vercel) so you can start building immediately without installing anything.

Workshop Agenda (60 Minutes):

[00:00 – 00:10] The New Builder Stack & R.A.C.E. Framework: Introduction to Agentic Engineering and how to write production-grade prompts (Role, Action, Context, Expectation).

[00:10 – 00:25] Generating the Foundation: Setting up our web IDE and prompting the AI to generate our core Next.js & Tailwind CSS layout (navbars, hero sections, property grids).

[00:25 – 00:45] Iteration & Fixing Hallucinations: AI isn’t perfect. We will learn how to act as “Tech Leads” to debug, refine the UI, and add interactive booking components.

[00:45 – 00:55] The Magic Trick (Live Deployment): With one click, we will deploy our web apps live to the internet. You will leave this room with a working public URL on your phone!

[00:55 – 00:60] Q&A & Next Steps: How to take your MVP to the next level.

Prerequisites: Just bring a laptop and your creativity! No prior React/Next.js experience is strictly required, though a basic understanding of how websites work is helpful.