AI-Driven Identity Governance: How Testing Teams Secure Access in Zero Trust Environments
As organizations adopt Zero Trust Architectures, Identity and Access Management has become a critical security control that testing teams can no longer treat as a black box. Traditional role-based access models struggle to keep pace with dynamic cloud environments, non-human identities, and evolving threat patterns. This session explores how AI-driven identity governance transforms access validation into a continuous, testable security practice. Drawing from real enterprise implementations across finance, healthcare, and e-commerce, the presentation demonstrates how behavioral analytics, attribute-based access control, and machine learning models detect anomalous access patterns earlier than rule-based systems while reducing false positives. Attendees will learn how QA and security testing teams can validate AI-assisted IAM controls, test risk-adaptive authentication flows, and integrate identity testing into CI/CD pipelines. The session also addresses practical challenges including testing explainability in regulated environments, validating machine-to-machine identities, and preventing over-privileged access through continuous monitoring. By the end of this talk, participants will gain actionable strategies, testing approaches, and metrics to assess the effectiveness of AI-enhanced identity controls, enabling them to improve security posture without slowing delivery in modern DevSecOps environments.
Chandana Mulpuri is an Information Security and DevSecOps Engineer with over ten years of experience securing enterprise applications and cloud platforms. She currently works as an Application Security Engineer at IBM, where she integrates security testing tools such as Mend, Contrast, AppScan, and Invicti across the software development lifecycle. Her work has contributed to a significant reduction in application vulnerabilities through proactive remediation, secure design reviews, threat modeling, and SAST and DAST assessments aligned with OWASP Top 10 standards. Previously, Chandana served as a Senior Cloud Security Operations Engineer at State Farm, leading identity integrations, multi-factor authentication initiatives, and CI/CD pipeline automation. She specializes in cloud security, security testing, and DevSecOps practices.
