About the Speaker
  • speaker photo
    André Van Klaveren
    Co-Leader, St. Louis OWASP Chapter

    André builds security organizations that scale and that enable business through alignment to strategy. Over the past 15+ years, he's focused on embedding security into the way products are designed, built, and delivered—not as a checkpoint, but as a strategic capability.

    Most recently, he led a global Security Advisory organization supporting more than 1,100 annual secure design engagements across U.S. and International portfolios. By implementing risk-based governance and AI-enabled process innovation, they increased operational capacity by 53% while reducing review cycle time by up to 32%.

    Beyond operational performance, he's contributed to enterprise-wide security maturity transformation from Gartner 1.1 to 4.0 by implementing threat modeling methodology and integrating security-by-design principles into SDLC governance and aligning effort to measurable risk.

    His work increasingly sits at the intersection of product security and emerging technology risk. He's partnered with cross-functional leadership to:
    • Develop enterprise Post-Quantum Cryptography strategy
    • Establish AI governance frameworks aligned to legal and regulatory expectations
    • Refactor third party risk evaluation workflows to help identify and close security blind spots
    • Provide executive-level product risk visibility to CISO, CTO, and Board stakeholders

    He is particularly energized by building operating models that allow security teams to focus on the risks that matter most, while enabling engineering velocity.

    In addition to enterprise leadership, he serves as Co-Leader of the OWASP St. Louis chapter and regularly speaks on secure design, AI risk, and modern security concerns.

    If you’re building or transforming a Product Security or Application Security function and want to discuss scalable approaches to risk-based governance, he's always open to thoughtful conversation.