Akansha Shukla - Modern AppSec: Securing APIs with Threat Modeling and DevSecOps
APIs power modern applications, yet many AppSec programs still cannot reliably inventory them, model their threats, or enforce authorization.
Listen to the episodeTopic
Security inside the pipeline — CI/CD, automation, shift left, and the difference between a gate and a guardrail.
APIs power modern applications, yet many AppSec programs still cannot reliably inventory them, model their threats, or enforce authorization.
Listen to the episodeKayra Otaner joins the podcast today to discuss DevSecOps and answer the question, is it dead? Kayra is the Director of DevSecOps at Roche and is highly involved in the DevSecOps community.
Listen to the episodeFrançois Proulx shares his discovery of security vulnerabilities in build pipelines. Francois has found that attackers can exploit this often overlooked side of the software supply chain.
Listen to the episodeMatt Rose, an experienced technical AppSec testing leader discusses his career journey and significant contributions in AppSec.
Listen to the episodeHasan Yasar believes that everyone shares the responsibility of creating a secure environment, and this can only be achieved by working collaboratively.
Listen to the episodeVarun Badhwar is a three-time founder, a luminary in the cyber security industry, and a clear communicator.
Listen to the episodeHarshil Parikh is a seasoned security leader with experience building security and compliance functions from the ground up.
Listen to the episode"Visualizing the Software Supply Chain" is a project which aims to kick off a discussion about the scope and breadth of the software supply chain.
Listen to the episodeSoftware supply chain -- how deep does the problem go? François is here to help us realize how deep the rabbit hole of the supply chain is and enlighten us with strategies to get out of the hole.
Listen to the episodeChristian Frichot, an AppSec hacker, security leader, and developer of hcltm. He discusses the DevOps threat modeling tool he dreamed up and built.
Listen to the episodeDerek is the author of “The Application Security Handbook. ” He is a university instructor at Temple University, where he teaches software development security to undergraduate and graduate students.
Listen to the episodeTiago Mendo is a co-founder and CTO of Probely. He has extensive experience in pentesting applications, training, and providing all-around security consultancy.
Listen to the episodeBrett Smith is a Software Architect/Engineer/Developer with 20+ years of experience.
Listen to the episodeHow can a startup build meaningful AppSec when it cannot hire a dedicated security specialist?
Listen to the episodeCI/CD systems hold code, credentials, and production access, yet many organizations still treat them as internal plumbing rather than a critical attack surface.
Listen to the episodeWill Ratner is a software security professional with extensive experience building and implementing security solutions across a myriad of industries…
Listen to the episodeSecrets management fails in surprisingly ordinary ways: credentials land in code, deployment files, containers, and cloud resources, then quietly become part of the system’s attack surface.
Listen to the episodeSimon Bennetts is the OWASP Zed Attack Proxy (ZAP) Project Leader and a Distinguished Engineer at StackHawk, a company that uses ZAP to help users fix…
Listen to the episodeTimo Pagel has been in the IT industry for over fifteen years. After a system administrator and web developer career, he advises customers as a DevSecOps consultant and trainer.
Listen to the episodeMark Loveless - aka Simple Nomad - is a security researcher and hacker. He's spoken at numerous security and hacker conferences worldwide, including Blackhat, DEF CON, ShmooCon, and RSA.
Listen to the episodeThreat modeling needs to fit the way developers work if it is going to survive a fast delivery cycle.
Listen to the episodeJeroen Willemsen is a Principal Security Architect at Xebia. Jeroen is more or less a jack of all trades with an interest in infrastructure security, risk management, and application security.
Listen to the episodeSoftware security has spent decades alternating between prevention, detection, and response. Kevin Greene joins Chris and Robert to ask what a balanced approach should look like now.
Listen to the episodeAaron Rinehart is expanding the possibilities of chaos engineering to cybersecurity.
Listen to the episodeAlyssa Miller is a life-long hacker, security advocate, and cybersecurity leader. She is the BISO for S&P Global ratings and has over 15 years of experience in security roles.
Listen to the episodeRobert and I decided to talk about an article I wrote called "DevOps security culture: 12 fails your team can learn from". We hope you enjoy this walkthrough of the 12 fails.
Listen to the episodeA secure software pipeline is more than a collection of scanners. Jim Routh joins Chris and Robert to explain how organizations can build repeatable…
Listen to the episodeCindy Blake is the Senior Security Evangelist at GitLab. Cindy collaborates around best practices for integrated DevSecOps application security solutions with major enterprises.
Listen to the episodeSeason six closes by revisiting five conversations that capture the breadth of application security.
Listen to the episodeAutomating security tests is useful, but it does not by itself make a development team secure.
Listen to the episodeWhat changes when security becomes part of delivering software instead of a separate gate?
Listen to the episodeContainers can improve your security story, but not simply because they are called containers.
Listen to the episodeWhy can a technically sound DevSecOps initiative fail before it changes how anyone works? Geoff Hill joins Chris and Robert to discuss the diplomacy behind application security transformation.
Listen to the episodeWhy doesn't an executive mandate and a scanning tool add up to a software security program?
Listen to the episodeHow does an intentionally vulnerable application become a community learning movement?
Listen to the episodePutting an application in Kubernetes does not solve the problem of getting secrets to it safely.
Listen to the episodeWhat if a security team measured success partly by making developers’ work easier? Travis McPeak explains that approach to SecOps through concrete examples from Netflix’s cloud environment.
Listen to the episodeA threat model that lives in an old document rarely keeps pace with the code it describes.
Listen to the episodeHow do you know a security control will work when the system around it fails? Aaron Rinehart introduces chaos engineering as a way to test assumptions about…
Listen to the episodeLearning DevSecOps is hard when setting up the lab becomes a project of its own. Mohammed Imran introduces DevSecOps Studio, an environment designed to help…
Listen to the episodeHow can a small AppSec team make sense of thousands of applications and a growing pile of security work?
Listen to the episodeCan security become a normal part of DevOps without turning every release into an audit? Julien Vehent, author of Securing DevOps, shares what his team learned protecting Firefox services at Mozilla.
Listen to the episodeFinding a vulnerable library in one build is only the beginning: how do you find every affected application across an organization?
Listen to the episodeMoving a security scanner earlier in the pipeline is not the same as building security into development.
Listen to the episodeSecurity testing loses value when its results arrive outside the developer’s normal workflow.
Listen to the episode