"I’m trying to set industry up for success to actually engage with us. We’re setting the framework in place to move out rapidly." That was Gabe Chiulli, the Acting CIO of the United States Army, opening Carahsoft’s Fourth annual DevSecOps Conference in Reston, Virginia — a gathering that brought federal CIOs, CISOs, and program leaders from the Army, Air Force, Navy, GSA, GAO, the Department of Agriculture, and NIST together to talk plainly about speeding software delivery without sacrificing security.
Gabe Chiulli and the Army’s push to align with industry
Chiulli framed the day around a simple operational problem: how to bridge commercial speed and government delivery. His keynote, “CIO Perspective: Army’s Vision for DevSecOps,” emphasized making it easier for vendors — “especially smaller, more agile companies” — to work with the Army, and creating “real pathways for ‘digital natives’ who expect to move quickly.” The explicit aim is to reduce paperwork and friction that slow procurement and instead "set industry up for success" so the Army can "move out rapidly."
Login.gov’s compressed assessments at GSA
Ed McLaughlin, Director of Platform and Product Security for GSA’s Login.gov platform, described his agency as “waterfall in compliance but agile in delivery” and offered a concrete process change: shortening assessment timelines “from three to five months to just three to five weeks.” He called Login.gov’s ongoing risk assessments a “significant game changer,” framing that compression as necessary because the previous pace was not “market speed.”

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildAir Force and Navy practices on AI: an intern that needs oversight
AI was pervasive in the conversations, but speakers stressed accountability over automation. Kurt Jarvis, CTO of the Air Force Sustainment Center Software Directorate, said, “When I look at AI, I don’t see it very much different than the new intern that we brought in,” and described his team’s approach as akin to paired programming: instead of pairing with another developer, “I’m a pairing programmer programming with an AI agent.” He said AI has not changed his team’s engineering standards or DevSecOps requirements; it simply “makes the pipeline run more often, and I’m running it faster.”
At the Naval Surface Warfare Center Dahlgren Division, Leroy Mrozowski, Software Modernization Lead, said developers retain final authority and that teams reject roughly 70 percent of AI-generated code before it reaches production. Kevin Walsh, GAO’s Director of IT and Cybersecurity, reinforced that stance: “If you have a 100% acceptance rate, that’s going to be some ugly code.” The message at the conference was consistent across civilian and defense programs: use AI to accelerate work, but keep humans responsible for outcomes.
Shift-left culture: SBOMs, provenance, and supply chain scrutiny
Speakers repeatedly described “shift-left” less as a single toolset than as a cultural change — integrating security early and continuously instead of adding it as a late-stage gate. Conference discussions included generating software bills of materials (SBOMs) during development, verifying code provenance, and applying the same supply-chain scrutiny to AI-generated code as to human-authored code. Jarvis argued that secure delivery depends as much on disciplined processes and culture as on tools, insisting that engineers, developers, and AI systems all operate under the same engineering standards and mission objectives.
What this means for technologists, procurement leaders, and agency executives
- Technologists and security teams: Expect continued emphasis on embedding security earlier — generating SBOMs, checking provenance, and rejecting poor AI suggestions (the conference reported roughly 70% rejection of AI code at one Navy division).
- Procurement and program leaders: The Army and GSA examples point to practical changes in vendor engagement and assessment timelines — Chiulli’s call to reduce paperwork for smaller vendors, and Login.gov’s move from months-long assessments to three- to five-week cycles, are concrete signals to adjust procurement processes.
- Agency executives and CIOs/CISOs: The balance presented at the conference is clear — move toward commercial agility while keeping engineering rigor; adopt AI as an accelerant but keep humans accountable for final acceptance.
The fourth annual DevSecOps Conference left a unified, pragmatic claim on the table: federal agencies are not arguing whether to modernize; they are committed to doing it in ways that preserve discipline. The record from Reston is specific — compressed assessments at Login.gov, an Army effort to make vendor engagement faster, teams rejecting a large share of AI output, and a steady push to bake security into the lifecycle — but it also poses a practical question the conference did not answer in detail: can those shortened timelines, cultural shifts, and human-in-the-loop safeguards be scaled and sustained across the many programs and procurement models that make up federal software development?




