ADVERTISEMENT

Hands-on with Kiro: How AWS is transforming AI-powered software engineering

Published Aug 22, 2026 11:12 am
Select members of the local media were recently invited to the Amazon Web Services (AWS) Philippines office in BGC for an exclusive hands-on workshop centered around Kiro and the AWS Security Agent. The session was structured around “Build with Kiro and Secure with Security Agent” — a Level 200 (Intermediate) course hosted under the AWS Workshop Studio. Designed specifically to be accessible for people new to the cloud, the workshop promised to walk us through building an application, rapidly creating interactive content using vibe mode, and architecting a content publishing platform using Spec mode.
Coming from a developer background where my work historically focused on browser-level coding — though nowadays my technical routine is mostly limited to troubleshooting websites — I was curious to see how much the modern development lifecycle had truly evolved. Guided on-site by the expert AWS team led by Joel Garcia, Head of Technology for Singapore Enterprise at AWS, alongside Solutions Architects Joben Genesis Rara, Zenon Saavedra, and Kate Viloria, we jumped right into the environment
We began the first exercise using Kiro’s “Vibe Mode,” an intuitive interface designed for rapid iteration. To put it to the test, I decided to build a browser version of the classic Snake game, the iconic mobile title that dominated older Nokia phones of yesteryears. Through pure vibe coding, I prompted the IDE, evaluated its logic, and watched the application assemble itself in real time without writing the underlying boilerplate from scratch. Seeing how effortlessly the game came together, I even joked to Joel: where were these kinds of tools back when we were still in school taking up Computer Science?
For the second part of the workshop, we shifted gears from casual iteration to structured engineering by creating an application in “Spec Mode”. This approach addresses a fundamental challenge in generative AI development: natural language prompts are inherently ambiguous, and passing them directly to an AI agent often creates a chaotic web of decisions and unpredictable outputs. In Spec Mode, Kiro eliminates this ambiguity by automatically generating three core specification files prior to writing code: a requirements document (requirements.md), a system design document (design.md), and a task list (tasks.md). By allowing developers to iterate on these specifications first, Kiro shifts human judgment from manual coding to strategic architecture and governance. The tool also incorporates native Model Context Protocol (MCP) integration for external tools, project-specific steering files, and a timeline checkpointing mechanism to safely roll back code states.
The final segment of the workshop focused on Security Testing, tackling the growing tension where development velocity outpaces security verification. Industry metrics presented during the session revealed that while 60% of organizations update web applications weekly, 75% test application security monthly or less frequently, with traditional manual penetration testing costing between $5,000 to $50,000 per application and taking 3 to 6 weeks. Furthermore, modern AI agents have made it easier to chain minor vulnerabilities into multi-step exploits.
To demonstrate how to secure applications built at machine speed, we tested the AWS Security Agent — a tool within the AWS Continuum platform designed to automate proactive security across the software development lifecycle. Unlike traditional human penetration testing that typically targets only public endpoints late in development on an annual basis, the AWS Security Agent provides continuous, automated coverage across AWS, hybrid, multi-cloud, and SaaS endpoints. During our hands-on security exercises on a sample vulnerable web application, the agent executed threat model reviews in minutes, performed near real-time source code scans, and ran automated penetration testing to discover and chain multi-step attack scenarios in hours.
Stepping out of the AWS BGC office, the ultimate takeaway from the experience was crystal clear: software engineers aren’t going to lose their jobs to AI anytime soon, but the nature of the work is fundamentally shifting. Rather than replacing human talent, tools like Kiro and the AWS Security Agent redefine the developer’s role from manual, line-by-line code execution to high-level system governance.
While AI can scaffold application architecture or hunt down vulnerabilities at record speeds, it still lacks the critical business context, ethical reasoning, and nuanced strategy that only a person can provide. Having a human in the loop remains absolutely essential. At the end of the day, these autonomous systems are only as smart as the direction we give them; developers are still firmly in the driver’s seat, steering intelligent agents to build rapidly, make sound judgment calls, and secure applications continuously.

Related Tags

AWS Kiro AI
ADVERTISEMENT
.most-popular .layout-ratio{ padding-bottom: 79.13%; } @media (min-width: 768px) and (max-width: 1024px) { .widget-title { font-size: 15px !important; } }

{{ articles_filter_1561_widget.title }}

.most-popular .layout-ratio{ padding-bottom: 79.13%; } @media (min-width: 768px) and (max-width: 1024px) { .widget-title { font-size: 15px !important; } }

{{ static_articles_1562_widget.title }}

.most-popular .layout-ratio{ padding-bottom: 79.13%; } @media (min-width: 768px) and (max-width: 1024px) { .widget-title { font-size: 15px !important; } }

{{ articles_filter_1563_widget.title }}

{{ articles_filter_1564_widget.title }}

.mb-article-details { position: relative; } .mb-article-details .article-body-preview, .mb-article-details .article-body-summary{ font-size: 17px; line-height: 30px; font-family: "Libre Caslon Text", serif; color: #000; } .mb-article-details .article-body-preview iframe , .mb-article-details .article-body-summary iframe{ width: 100%; margin: auto; } .read-more-background { background: linear-gradient(180deg, color(display-p3 1.000 1.000 1.000 / 0) 13.75%, color(display-p3 1.000 1.000 1.000 / 0.8) 30.79%, color(display-p3 1.000 1.000 1.000) 72.5%); position: absolute; height: 200px; width: 100%; bottom: 0; display: flex; justify-content: center; align-items: center; padding: 0; } .read-more-background a{ color: #000; } .read-more-btn { padding: 17px 45px; font-family: Inter; font-weight: 700; font-size: 18px; line-height: 16px; text-align: center; vertical-align: middle; border: 1px solid black; background-color: white; } .hidden { display: none; }
function initializeAllSwipers() { // Get all hidden inputs with cms_article_id document.querySelectorAll('[id^="cms_article_id_"]').forEach(function (input) { const cmsArticleId = input.value; const articleSelector = '#article-' + cmsArticleId + ' .body_images'; const swiperElement = document.querySelector(articleSelector); if (swiperElement && !swiperElement.classList.contains('swiper-initialized')) { new Swiper(articleSelector, { loop: true, pagination: false, navigation: { nextEl: '#article-' + cmsArticleId + ' .swiper-button-next', prevEl: '#article-' + cmsArticleId + ' .swiper-button-prev', }, }); } }); } setTimeout(initializeAllSwipers, 3000); const intersectionObserver = new IntersectionObserver( (entries) => { entries.forEach((entry) => { if (entry.isIntersecting) { const newUrl = entry.target.getAttribute("data-url"); if (newUrl) { history.pushState(null, null, newUrl); let article = entry.target; // Extract metadata const author = article.querySelector('.author-section').textContent.replace('By', '').trim(); const section = article.querySelector('.section-info ').textContent.replace(' ', ' '); const title = article.querySelector('.article-title h1').textContent; // Parse URL for Chartbeat path format const parsedUrl = new URL(newUrl, window.location.origin); const cleanUrl = parsedUrl.host + parsedUrl.pathname; // Update Chartbeat configuration if (typeof window._sf_async_config !== 'undefined') { window._sf_async_config.path = cleanUrl; window._sf_async_config.sections = section; window._sf_async_config.authors = author; } // Track virtual page view with Chartbeat if (typeof pSUPERFLY !== 'undefined' && typeof pSUPERFLY.virtualPage === 'function') { try { pSUPERFLY.virtualPage({ path: cleanUrl, title: title, sections: section, authors: author }); } catch (error) { console.error('ping error', error); } } // Optional: Update document title if (title && title !== document.title) { document.title = title; } } } }); }, { threshold: 0.1 } ); function showArticleBody(button) { const article = button.closest("article"); const summary = article.querySelector(".article-body-summary"); const body = article.querySelector(".article-body-preview"); const readMoreSection = article.querySelector(".read-more-background"); // Hide summary and read-more section summary.style.display = "none"; readMoreSection.style.display = "none"; // Show the full article body body.classList.remove("hidden"); } document.addEventListener("DOMContentLoaded", () => { let loadCount = 0; // Track how many times articles are loaded const offset = [1, 2, 3, 4, 5, 6, 7, 8, 9, 10]; // Offset values const currentUrl = window.location.pathname.substring(1); let isLoading = false; // Prevent multiple calls if (!currentUrl) { console.log("Current URL is invalid."); return; } const sentinel = document.getElementById("load-more-sentinel"); if (!sentinel) { console.log("Sentinel element not found."); return; } function isSentinelVisible() { const rect = sentinel.getBoundingClientRect(); return ( rect.top < window.innerHeight && rect.bottom >= 0 ); } function onScroll() { if (isLoading) return; if (isSentinelVisible()) { if (loadCount >= offset.length) { console.log("Maximum load attempts reached."); window.removeEventListener("scroll", onScroll); return; } isLoading = true; const currentOffset = offset[loadCount]; window.loadMoreItems().then(() => { let article = document.querySelector('#widget_1690 > div:nth-last-of-type(2) article'); intersectionObserver.observe(article) loadCount++; }).catch(error => { console.error("Error loading more items:", error); }).finally(() => { isLoading = false; }); } } window.addEventListener("scroll", onScroll); });

Sign up by email to receive news.