Your AppSec Bottleneck Is a People Problem
Most security champions programs don't fail on tooling — they fail on people. Lisi Hocke spent three years as a champion before moving fully into product…
Listen to the episodeTopic
Why developers do or do not adopt security — empathy, blamelessness and influence rather than mandates — and looking after the people doing the work, from burnout to neurodiversity.
Most security champions programs don't fail on tooling — they fail on people. Lisi Hocke spent three years as a champion before moving fully into product…
Listen to the episodeSecurity champions programs rarely fail because the idea is bad; they fail because organizations launch without management support, meaningful incentives, or a plan to prove value.
Listen to the episodeWe’re discussing the intersections of application security (AppSec) and sales strategy with our guest, Sean Varga.
Listen to the episodeKalyani Pawar shares critical strategies for integrating security early and effectively in AppSec for startups.
Listen to the episodeDavid Quisenberry shares about his journey into the security world, insights on building AppSec programs in small to mid-sized companies, and the importance of data-driven decision-making.
Listen to the episodeDustin Lehr, Senior Director of Platform Security/Deputy CISO at Fivetran and Chief Solutions Officer at Katilyst Security, joins Robert and Chris to discuss security champions.
Listen to the episodeIs application security dead, or does it need to grow into something larger? CoverMyMeds security leaders Jay Bobo and Darylynn Ross challenge the…
Listen to the episodeEitan Worcel joins the Application Security Podcast, to talk automated code fixes and the role of artificial intelligence in application security.
Listen to the episodeWhat does an application security leader need to know before stepping into the CISO role?
Listen to the episodeSix candidates for the 2023 OWASP Board of Directors debate the choices that shape the foundation and its community.
Listen to the episodeHarshil Parikh is a seasoned security leader with experience building security and compliance functions from the ground up.
Listen to the episodeJeevan Singh, the director of product security at Twilio, discusses the future of application security engineers.
Listen to the episodeAlex leads the Cyber Security Consulting Group, part of Rakuten's Cyber Security Defense Department.
Listen to the episodeJ. Wolfgang Goerlich is an Advisory CISO for Cisco Secure. He has been responsible for IT and IT security in the healthcare and financial services verticals.
Listen to the episodeBrenna Leath is currently the Head of Product Security for a data analytics company where she sets the application security strategy for R&D and leads a team of security architects.
Listen to the episodeLeif Dreizler is the manager of the Product Security team at Segment. Leif got his start in the security industry at Redspin doing security consulting work and was later an early employee at Bugcrowd.
Listen to the episodeNetwork engineers and application security teams depend on each other, yet often struggle to understand each other’s responsibilities.
Listen to the episodeBuilding a stronger security community means helping more kinds of people participate and succeed.
Listen to the episodeWhy can a technically sound DevSecOps initiative fail before it changes how anyone works? Geoff Hill joins Chris and Robert to discuss the diplomacy behind application security transformation.
Listen to the episodeWhere should a small application security team begin when it cannot do everything? David Kosorok joins Chris and Robert with a practical framework: prevent, detect, and react.
Listen to the episodeWhich parts of an AppSec program should change as a company grows, and which should stay the same?
Listen to the episodeWhy should kindness matter in an industry responsible for protecting money, systems, and sometimes lives?
Listen to the episodeSecurity programs improve when developers have someone who can help them want to get better, not merely tell them what they did wrong.
Listen to the episodeA successful security career can still become unsustainable when work crowds out everything else.
Listen to the episodeHow can hackers and corporate security teams work together when each sees the other through a different set of assumptions?
Listen to the episodeChanging security culture requires more than distributing policies or buying another training platform.
Listen to the episodeA bug bounty can create a productive relationship with security researchers—or damage trust on both sides.
Listen to the episodeCould familiar hiring and management practices be keeping talented people out of security?
Listen to the episodeIn a profession that rewards constant vigilance, how do you recognize when dedication has become burnout?
Listen to the episodeWhat is a security champion, and how can an organization build a program that lasts? Chris and Robert compare definitions, alternative titles, and the qualities that make a champion effective.
Listen to the episodeWhat separates a useful security consultant from someone who merely arrives with answers?
Listen to the episodeA security awareness program needs to change daily behavior, not simply record who completed a course.
Listen to the episodeHow do you keep a secure development lifecycle useful as products, teams, and delivery methods change?
Listen to the episode