Michael Burch - AI-Enabled Citizen Developers
When every employee can generate working software, who owns the risk? Michael Burch, VP of AI Enablement and Acceleration at Security Journey, explains how…
Listen to the episodeTopic
Getting into application security and going further — origin stories, hiring, mentoring, certifications, and teaching the next generation.
When every employee can generate working software, who owns the risk? Michael Burch, VP of AI Enablement and Acceleration at Security Journey, explains how…
Listen to the episodeWhat should OWASP become, and which leaders have a credible plan to get it there? In this special 2025 Board of Directors candidate debate, nine candidates…
Listen to the episodeSecurity champions programs rarely fail because the idea is bad; they fail because organizations launch without management support, meaningful incentives, or a plan to prove value.
Listen to the episodeFormer CISO Jim Routh discusses his perspective on retirement and career fulfillment in cybersecurity.
Listen to the episodePhilip Wiley shares his unique journey from professional wrestling to being a renowned pen tester. We define pen testing and the role of social engineering in ethical hacking.
Listen to the episodeDerek Fisher, an expert in hardware, software, and cybersecurity with over 25 years of experience is back on the podcast.
Listen to the episodeDavid Quisenberry shares about his journey into the security world, insights on building AppSec programs in small to mid-sized companies, and the importance of data-driven decision-making.
Listen to the episodeDevon Rudnicki, the Chief Information Security Officer at Fitch Group, shares her journey of developing an application security program from scratch and advancing to the CISO role.
Listen to the episodeDustin Lehr, Senior Director of Platform Security/Deputy CISO at Fivetran and Chief Solutions Officer at Katilyst Security, joins Robert and Chris to discuss security champions.
Listen to the episodeAppSec specialist Megan Jacquot joins Chris and Robert for a compelling conversation about community, career paths, and productive red team exercises.
Listen to the episodeRobert is joined by Bill Sempf, an application security architect with over 20 years of experience in software development and security.
Listen to the episodeArshan Dabirsiaghi of Pixee joins Robert and Chris to discuss startups, AI in appsec, and Pixee's Codemodder. io.
Listen to the episodeChris and Robert are thrilled to have an insightful conversation with Dr. Jared Demott, a seasoned expert in the field of cybersecurity.
Listen to the episodeWhat does an application security leader need to know before stepping into the CISO role?
Listen to the episodeTanya Janca, also known as SheHacksPurple, joins the Application Security Podcast again to discuss secure coding, threat modeling, education, and other topics in the AppSec world.
Listen to the episodeHasan Yasar believes that everyone shares the responsibility of creating a secure environment, and this can only be achieved by working collaboratively.
Listen to the episodeSix candidates for the 2023 OWASP Board of Directors debate the choices that shape the foundation and its community.
Listen to the episodeKevin Johnson is the CEO of Secure Ideas. He began his career as a developer but turned toward security when he discovered that the interface for an intrusion detection system, Snort, was out of date.
Listen to the episodeTony Quadros, the AppSec Lumberjack, shares the unique career path that led him to find his passion in Application Security.
Listen to the episodeJeevan Singh, the director of product security at Twilio, discusses the future of application security engineers.
Listen to the episodeChristian Frichot, an AppSec hacker, security leader, and developer of hcltm. He discusses the DevOps threat modeling tool he dreamed up and built.
Listen to the episodeRobyn Lundin started working in tech after a coding boot camp as a developer for a small startup.
Listen to the episodeJ. Wolfgang Goerlich is an Advisory CISO for Cisco Secure. He has been responsible for IT and IT security in the healthcare and financial services verticals.
Listen to the episodeAdam is a leading expert on threat modeling, and a consultant, expert witness, author and game designer. He has decades of experience delivering security.
Listen to the episodeTimo Pagel has been in the IT industry for over fifteen years. After a system administrator and web developer career, he advises customers as a DevSecOps consultant and trainer.
Listen to the episodeWhy do application security programs stall even after teams buy tools and define processes? James Ransome and Brook S. E.
Listen to the episodeCharles is a Senior Security Consultant for Red Siege. He has over 18 years of experience in IT.
Listen to the episodeBuilding a stronger security community means helping more kinds of people participate and succeed.
Listen to the episodeWhat happens when Chris and Robert trade a single interview topic for five current application security ideas?
Listen to the episodeIs becoming a CISO the next technical promotion, or a fundamentally different job? Marc French joins Chris and Robert to discuss the role through the eyes of an application security leader.
Listen to the episodeSeason 5 covered application security from tools and threat models to mentoring, self-care, coaching, dependency risk, and program design.
Listen to the episodeWhich parts of an AppSec program should change as a company grows, and which should stay the same?
Listen to the episodeSecurity testing is more likely to happen when it fits the way developers already work.
Listen to the episodeA successful security career can still become unsustainable when work crowds out everything else.
Listen to the episodeSecurity needs more experienced practitioners, but people do not become senior without guidance, advocacy, and opportunities to learn.
Listen to the episodeWhat does a bug bounty look like from both sides of the relationship? Adam Bacchus and Jon Bottarini of HackerOne compare the responsibilities of the…
Listen to the episodeHow can application security become a field where more women enter, contribute, and advance?
Listen to the episodeWhat separates a useful security consultant from someone who merely arrives with answers?
Listen to the episodeCan a career in library science become a foundation for information security? Tracy Maleeff joins Chris and Robert while making that transition, bringing…
Listen to the episodeTechnical ability can open a door in security, but communication and relationships often determine what happens next.
Listen to the episodeHow do you keep a secure development lifecycle useful as products, teams, and delivery methods change?
Listen to the episode