Developer & security researcher
Erlend
Erlend
Oftedal
Two decades building and breaking systems — now turning hard security problems into tools developers actually use.
01
What I do
- Security research and development of security and AI solutions.
- Tailored talks and trainings.
- Agenda lead for NDC Conferences and co-organizer of BSides Oslo.
- Chapter leader of OWASP Norway since 2011 .
- Author and maintainer of open source security tools, and a frequent speaker on application security, secure-by-design and AI.
02
Experience
- 2025 — 2026 Senior Technical DirectorRSAC
- 2022 — 2025 Director, Security ResearcherCrosspoint Labs
- 2021 — 2022 Senior Principal Security EngineerAutodesk (Spacemaker)
- 2016 — 2021 Partner & CTOBlank AS
- 2015 — 2016 Senior Security ConsultantF-Secure (nSense)
- 2012 — 2013 Invited Expert, Web App Security WGW3C
- 2004 — 2015 Managing consultant & security practice leadBekk Consulting
03
Projects
retire.js
★ 4.1kA free, open source scanner that detects use of JavaScript libraries with known vulnerabilities, and generates a software bill of materials. Ships as a CLI, browser extensions, and Burp / ZAP plugins.
github.com/RetireJS/retire.js ↗writings
★ 175Blog posts — security research, secure development and notes from the field, including scans of the web for vulnerable JS libraries.
github.com/eoftedal/writings ↗
04
Talks
- Security in agentic coding — learning lab (with Armin Buescher)
- Securing your AI code generation workflow — workshop
- The missing S in MCP (with Ståle Pettersen)
- Secure coding: Back to basics
- AppSec is changing keynote
- Application security keynote
- Modern web application vulnerabilities 2020
- Modern web application vulnerabilities
- Broken crypto is broken
- Kubernetes security with Istio
- Fuzzing with AFL
- Threat modeling — workshop
- An introduction to threat modeling
- Continuous security (with Stein Inge Morisbak)
- Your web application is already out of date
- Securing a modern JavaScript based single page web application
- RESTful security
- Practical attacks on web crypto
Also at OWASP AppSec, NDC (Oslo / Security / London / Sydney / Minnesota), JavaZone, Øredev and many meetups and user groups.