Your AppSec Bottleneck Is a People Problem
Most security champions programs don't fail on tooling — they fail on people. Lisi Hocke spent three years as a champion before moving fully into product…
Listen to the episodeTopic
Standing up and growing an application security function — maturity models, champions, metrics, and getting the budget.
Most security champions programs don't fail on tooling — they fail on people. Lisi Hocke spent three years as a champion before moving fully into product…
Listen to the episodeSecurity champions programs rarely fail because the idea is bad; they fail because organizations launch without management support, meaningful incentives, or a plan to prove value.
Listen to the episodeA dashboard full of green indicators can still describe an insecure organization. Aram Hovsepyan, founder and CEO of Codific and an OWASP SAMM contributor,…
Listen to the episodeDag Flachet joins us to discuss the concept of Kaizen and its application in improving application security.
Listen to the episodeKalyani Pawar shares critical strategies for integrating security early and effectively in AppSec for startups.
Listen to the episodeMilan Williams discusses the importance of application security metrics and how to make them both meaningful and actionable.
Listen to the episodeMo Sadek shares his unique journey of building an Application Security program from scratch at Roblox.
Listen to the episodeIrfaan Santoe joins us for an in-depth discussion on the power of strategy in Application Security.
Listen to the episodeJahanzeb Farooq discusses his journey in cybersecurity and the challenges of building AppSec programs from scratch.
Listen to the episodeDevon Rudnicki, the Chief Information Security Officer at Fitch Group, shares her journey of developing an application security program from scratch and advancing to the CISO role.
Listen to the episodeDustin Lehr, Senior Director of Platform Security/Deputy CISO at Fivetran and Chief Solutions Officer at Katilyst Security, joins Robert and Chris to discuss security champions.
Listen to the episodeIs application security dead, or does it need to grow into something larger? CoverMyMeds security leaders Jay Bobo and Darylynn Ross challenge the…
Listen to the episodeEitan Worcel joins the Application Security Podcast, to talk automated code fixes and the role of artificial intelligence in application security.
Listen to the episodeWhat does an application security leader need to know before stepping into the CISO role?
Listen to the episodeJeff Willams of Contrast Security joins Chris and Robert on the Application Security Podcast to discuss runtime security, emphasizing the significance of…
Listen to the episodeApplication security teams rarely have enough specialists to embed one expert with every development team.
Listen to the episodeJeevan Singh, the director of product security at Twilio, discusses the future of application security engineers.
Listen to the episodeDerek is the author of “The Application Security Handbook. ” He is a university instructor at Temple University, where he teaches software development security to undergraduate and graduate students.
Listen to the episodeAlex leads the Cyber Security Consulting Group, part of Rakuten's Cyber Security Defense Department.
Listen to the episodeBrenna Leath is currently the Head of Product Security for a data analytics company where she sets the application security strategy for R&D and leads a team of security architects.
Listen to the episodeTimo Pagel has been in the IT industry for over fifteen years. After a system administrator and web developer career, he advises customers as a DevSecOps consultant and trainer.
Listen to the episodeWhy do application security programs stall even after teams buy tools and define processes? James Ransome and Brook S. E.
Listen to the episodeBefore taking the plunge into information security leadership, Dustin Lehr spent over a decade as a software engineer and architect in a variety of…
Listen to the episodeA secure software pipeline is more than a collection of scanners. Jim Routh joins Chris and Robert to explain how organizations can build repeatable…
Listen to the episodeHow does an organization improve software security without reducing maturity to a checklist?
Listen to the episodeMark Merkow works at WageWorks in Tempe, Arizona, leading application security architecture and engineering efforts in the office of the CISO.
Listen to the episodeWhy can a technically sound DevSecOps initiative fail before it changes how anyone works? Geoff Hill joins Chris and Robert to discuss the diplomacy behind application security transformation.
Listen to the episodeWhere should a small application security team begin when it cannot do everything? David Kosorok joins Chris and Robert with a practical framework: prevent, detect, and react.
Listen to the episodeWhich parts of an AppSec program should change as a company grows, and which should stay the same?
Listen to the episodeWhy doesn't an executive mandate and a scanning tool add up to a software security program?
Listen to the episodeSecurity programs improve when developers have someone who can help them want to get better, not merely tell them what they did wrong.
Listen to the episodeChanging security culture requires more than distributing policies or buying another training platform.
Listen to the episodeWhat does a bug bounty look like from both sides of the relationship? Adam Bacchus and Jon Bottarini of HackerOne compare the responsibilities of the…
Listen to the episodeWhich practices belong in a complete application security program? The Season 3 finale answers by assembling clips that move from early development…
Listen to the episodeWhat if the strongest argument for funding application security is better software delivery rather than fear of a breach?
Listen to the episodeBuying more scanners does not automatically create a better application security program.
Listen to the episodeWhat is a security champion, and how can an organization build a program that lasts? Chris and Robert compare definitions, alternative titles, and the qualities that make a champion effective.
Listen to the episodeEvery software organization accumulates technical debt, but security debt raises the cost and risk of every future change.
Listen to the episode