Why AI Code Review Will Replace Human Review Faster Than You Think
Jim Manico thinks the era of human code review is ending, and that clinging to it will hurt your company.
Listen to the episodeTopic
Writing software that resists attack: secure defaults, guardrails, paved roads, code review, and training that developers will sit through.
Jim Manico thinks the era of human code review is ending, and that clinging to it will hurt your company.
Listen to the episodeThree years ago, Jeevan Singh mapped out what an application security engineer needed to know. AI has rewritten the job since.
Listen to the episodeAI is moving AppSec's control point out of CI and directly into the coding agent—but what happens when the model writing the code is also expected to secure it?
Listen to the episodeIf AI writes all the code and the developer barely reads it, where does AppSec fit?
Listen to the episodeSarah-Jane Madden joins Chris and Robert to ask what AI actually changes in software development—and what foundational practices still matter.
Listen to the episodeSecurity expert Tanya Janca discusses her new book "Alice and Bob Learn Secure Coding" and shares insights on making security accessible to developers.
Listen to the episodeMehran Koushkebaghi, a seasoned engineering expert, delves into the intricacies of systemic security.
Listen to the episodeTanya Janka, also known as SheHacksPurple, discusses secure guardrails, the difference between guardrails and paved roads, and how to implement both in application security.
Listen to the episodeTanya Janca, also known as SheHacksPurple, joins the Application Security Podcast again to discuss secure coding, threat modeling, education, and other topics in the AppSec world.
Listen to the episodeHarshil Parikh is a seasoned security leader with experience building security and compliance functions from the ground up.
Listen to the episodeKim Wuyts discusses her work in privacy threat modeling with LINDDUN, a framework inspired by Microsoft's STRIDE for security threat modeling.
Listen to the episodeRobyn Lundin started working in tech after a coding boot camp as a developer for a small startup.
Listen to the episodeIn this episode of the Application Security Podcast, Chris Romeo walks through the origin story of Security Journey and shares some experiences taking a security startup from bootstrap to acquisition.
Listen to the episodeKen Toler is a principal consultant at Kudelski Security and is passionate about building and optimizing application security programs that stick through strong adoption and ease of use.
Listen to the episodeDima Kotik is an Application Security Engineer at Security Journey and has been programming in Python for years.
Listen to the episodeAaron Rinehart is expanding the possibilities of chaos engineering to cybersecurity.
Listen to the episodeVandana Verma is the President of Infosec girls and Infosec Kids, a board of directors member for OWASP, and a leader for BSides Dehli. She joins us to introduce the OWASP Spotlight Series.
Listen to the episodeA secure software pipeline is more than a collection of scanners. Jim Routh joins Chris and Robert to explain how organizations can build repeatable…
Listen to the episodeNeil Matatall is a product security engineer at GitHub. He focuses on designing and engineering user experiences solutions related to authentication and account recovery.
Listen to the episodeElie Saad is an application security engineer, leading three different OWASP projects.
Listen to the episodeMark Merkow works at WageWorks in Tempe, Arizona, leading application security architecture and engineering efforts in the office of the CISO.
Listen to the episodeHow did Microsoft's Security Development Lifecycle become a repeatable engineering practice rather than a one-time security push?
Listen to the episodeSoftware producers, customers, and policymakers need a common way to discuss security without pretending that one checklist fits every product.
Listen to the episodeFramework defaults can prevent common vulnerabilities, but developers still need to understand when their code bypasses those protections.
Listen to the episodeWhat developers need from a threat model is often a clear set of requirements they can implement.
Listen to the episodeWhat changed when Chrome began labeling ordinary HTTP pages as not secure, and why did that decision provoke resistance?
Listen to the episodeWhat is a security champion, and how can an organization build a program that lasts? Chris and Robert compare definitions, alternative titles, and the qualities that make a champion effective.
Listen to the episodeWhere should the OWASP Proactive Controls go after giving developers a concise defensive counterpart to the Top 10?
Listen to the episodeHow should the OWASP Top 10 balance data, expert judgment, community feedback, and a format people can actually use?
Listen to the episodeA security awareness program needs to change daily behavior, not simply record who completed a course.
Listen to the episodeHow can a company build a security community when it has only a few interested people and little budget?
Listen to the episodeCan you learn enough about a development team’s security practices in an hour to give it useful direction?
Listen to the episodeWhich activities turn a secure development lifecycle from an aspiration into repeatable work?
Listen to the episodeIn the inaugural episode of the Application Security Podcast, Chris Romeo and Robert Hurlbut introduce themselves, trace the experiences that brought them…
Listen to the episode