← All speakers

Bio, Work & Ideas

Eli Cohen

Conference affiliation: Snyk

On this page

Eli Cohen co-founded Helios and served as its CEO, building tools that used distributed tracing to help developers understand, troubleshoot, and test applications. His work subsequently moved into application security: the behavior of a running system can explain both why software fails and which vulnerabilities need attention.

From distributed-system testing to runtime security

Cohen moved from engineering into product and startup leadership. In a published interview about Helios, he describes a formative problem at a fintech company: a service change passed its individual tests but disrupted transactions after deployment into a larger microservices system. Engineers had to reconstruct interactions across services to diagnose the failure. Cohen and his co-founder saw an opportunity to use OpenTelemetry traces to automate parts of that investigation.

Helios made those traces useful for troubleshooting, reproducing failures, and generating tests. Cohen’s 2022 Postman integration guide explains why inspecting an HTTP response alone can miss important application behavior. A service may acknowledge a request while downstream work continues through message brokers such as Kafka or RabbitMQ. Tracing those operations lets developers follow what happened beyond the initial response and investigate failures across service boundaries.

Helios moved toward application security before its acquisition. The visibility that helped developers diagnose failures could also help security teams prioritize vulnerabilities in running applications. This extended the company’s existing technology into a new customer problem.

Snyk acquired Helios in January 2024, bringing its team into Snyk’s research and development organization. Helios contributed runtime intelligence collected through OpenTelemetry and eBPF to Snyk’s application security posture management work, connecting development-time findings with information about executing applications.

Testing security as applications change

Cohen’s later work addresses the pressure AI places on application security. In “AI Hackers Are Faster Than Your Pen Test”, recorded at the 2026 AI Engineer World’s Fair, he argues that increased code production and attackers’ use of AI make occasional penetration tests insufficient. His proposed response combines existing scanners with continuous offensive security: testing application behavior as software changes and validating whether suspected vulnerabilities can actually be exploited.

Three ideas explain this approach:

  • Runtime context for prioritization: A vulnerability’s severity is only part of the decision about what to fix. Information about the running application helps teams interpret findings and decide what deserves investigation. This carries forward Helios’s emphasis on understanding interactions rather than examining components in isolation.
  • Complementary testing methods: Cohen distinguishes the limits of static scanning, dynamic testing, and human penetration testing. Static checks can miss runtime issues; dynamic testing can miss business logic and authorization flaws; human engagements provide valuable investigation but occur infrequently and cost time and money. He advocates combining these methods, using scanner findings as context for further offensive testing.
  • Validated exploits as the standard: Cohen describes coordinated agents handling reconnaissance, vulnerability hunting, exploit validation, remediation, and reporting. The important distinction is between identifying a possible weakness and demonstrating an exploit that developers can reproduce. Validation aims to reduce false positives and make the resulting findings actionable.

His security work also extends to AI applications through agent red teaming. These systems add behavior that security teams must examine alongside conventional application vulnerabilities. Across observability and offensive testing, Cohen’s recurring concern is understanding how an application actually behaves well enough to turn a finding into a useful investigation or repair.

Read the topics behind these talks

1 conference talk

Key ideas

Scroll to read ↓

Eli Cohen explains Snyk’s approach to continuous offensive security: test each code change, give specialized agents application context, and validate exploits before asking developers to fix them.

  • Application context matters because attackers can chain smaller weaknesses and exploit business rules that predefined payloads do not fully capture.
    3:11 ↗
  • Cohen describes AI pen testing on every PR, with separate agents for reconnaissance, vulnerability hunting, exploit validation, remediation and reporting.
    11:17 ↗
  • Static and dynamic scanner findings can guide AI testing, while established scanners continue to cover known attack patterns.
    14:47 ↗
  • Evaluate AI pen testing through its cadence, application reasoning, context inputs and evidence of exploitability.
    17:16 ↗