Vulnerability Jail and the AI-Era AppSec Engineer
Three years ago, Jeevan Singh mapped out what an application security engineer needed to know. AI has rewritten the job since.
Listen to the episodeTopic
SAST, DAST, IAST, fuzzing and penetration testing, and the false-positive problem that decides whether any of them get used.
Three years ago, Jeevan Singh mapped out what an application security engineer needed to know. AI has rewritten the job since.
Listen to the episodeMost fault trees get built on gut feeling. Petra Vukmirovic did something rarer: she borrowed the actual math from aviation and nuclear-plant safety engineering and pointed it at AI agents.
Listen to the episodeIs traditional DAST finally dead? James Berthoty came back to settle the argument that his last episode started.
Listen to the episodeTraditional SAST is deterministic but shallow; AI can reason about context but may answer differently every time. Can the two approaches make each other better?
Listen to the episodeSecurity education often struggles because the people in the room are being talked at instead of invited to participate.
Listen to the episodeWhat happens when teams add large language models to real applications and discover that familiar AppSec controls are no longer enough?
Listen to the episodeSecurity expert Tanya Janca discusses her new book "Alice and Bob Learn Secure Coding" and shares insights on making security accessible to developers.
Listen to the episodeSteve Wilson, the author of 'The Developer's Playbook for Large Language Model Security’ is back to dive into topics from his book like AI hallucinations, trust, and the future of AI.
Listen to the episodeJeff Williams, a renowned pioneer in the field of application security is with us to discuss Application Detection and Response (ADR), detailing its…
Listen to the episodePhilip Wiley shares his unique journey from professional wrestling to being a renowned pen tester. We define pen testing and the role of social engineering in ethical hacking.
Listen to the episodeTanya Janka, also known as SheHacksPurple, discusses secure guardrails, the difference between guardrails and paved roads, and how to implement both in application security.
Listen to the episodeJahanzeb Farooq discusses his journey in cybersecurity and the challenges of building AppSec programs from scratch.
Listen to the episodeMatt Rose, an experienced technical AppSec testing leader discusses his career journey and significant contributions in AppSec.
Listen to the episodeJames Berthoty, a cloud security engineer with a diverse IT background, discusses his journey into application and product security.
Listen to the episodeZAP supports an enormous share of the application security ecosystem, but who pays for the people keeping it reliable?
Listen to the episodeDevon Rudnicki, the Chief Information Security Officer at Fitch Group, shares her journey of developing an application security program from scratch and advancing to the CISO role.
Listen to the episodeFrancesco Cipollone, CEO of Phoenix Security, joins Chris and Robert to discuss security and explain Application Security Posture Management (ASPM).
Listen to the episodeJason Nelson, an accomplished expert in information security management, joins Chris to share insights on establishing successful threat modeling programs…
Listen to the episodeErik Cabetas joins Robert and Chris for a thought-provoking discussion about modern software security.
Listen to the episodeIs application security dead, or does it need to grow into something larger? CoverMyMeds security leaders Jay Bobo and Darylynn Ross challenge the…
Listen to the episodeChris John Riley joins Chris and Robert to discuss the Minimum Viable Secure Product. MVSP is a minimalistic security checklist for B2B software and business process outsourcing suppliers.
Listen to the episodeVarun Badhwar is a three-time founder, a luminary in the cyber security industry, and a clear communicator.
Listen to the episodeJeff Willams of Contrast Security joins Chris and Robert on the Application Security Podcast to discuss runtime security, emphasizing the significance of…
Listen to the episodeDevelopment, operations, and security teams generate oceans of data yet still struggle to answer basic questions about what code is running, who owns it, and which findings matter.
Listen to the episodeMaril Vernon is passionate about Purple teaming and joins Robert and Chris to discuss the intricacies of purple teaming in cybersecurity.
Listen to the episodeDan Küykendall visits The Application Security Podcast to discuss his series "Why All AppSec Products Suck" and explain why software companies should…
Listen to the episodeKevin Johnson is the CEO of Secure Ideas. He began his career as a developer but turned toward security when he discovered that the interface for an intrusion detection system, Snort, was out of date.
Listen to the episodeCloud security is on an evolutionary path, with newer platforms embracing secure-by-default settings.
Listen to the episodeZohar Shachar joins us to discuss the bug bounty process from both sides. Zohar has spent time as a bug bounty hunter and shares wisdom on avoiding bug bounty-causing issues for your AppSec posture.
Listen to the episodeDerek is the author of “The Application Security Handbook. ” He is a university instructor at Temple University, where he teaches software development security to undergraduate and graduate students.
Listen to the episodeRobyn Lundin started working in tech after a coding boot camp as a developer for a small startup.
Listen to the episodeAlex leads the Cyber Security Consulting Group, part of Rakuten's Cyber Security Defense Department.
Listen to the episodeMark Curphey is one of the creators of OWASP from the very early days. Mark worked in the background over the few decades of OWASP but has recently taken more to the spotlight.
Listen to the episodeTiago Mendo is a co-founder and CTO of Probely. He has extensive experience in pentesting applications, training, and providing all-around security consultancy.
Listen to the episodeSam Stepanyan is an OWASP London Chapter Leader and an Independent Application Security Consultant with over 20 years of IT experience and a background in…
Listen to the episodeChen Gour-Arie is the Chief Architect and Co-Founder of Enso Security. With over 15 years of hands-on experience in cybersecurity and software development,…
Listen to the episodeJosh Grossman has over 15 years of experience in IT Risk and Application Security consulting, and he has also worked as a software developer.
Listen to the episodeAlex Mor is a passionate cybersecurity defender or breaker depending on the time of day, providing expert technical guidance to product teams and building security in their platforms.
Listen to the episodeWill Ratner is a software security professional with extensive experience building and implementing security solutions across a myriad of industries…
Listen to the episodeKen Toler is a principal consultant at Kudelski Security and is passionate about building and optimizing application security programs that stick through strong adoption and ease of use.
Listen to the episodeInfrastructure as code gives security teams something they have wanted for years: a readable description of the systems surrounding an application.
Listen to the episodeSimon Bennetts is the OWASP Zed Attack Proxy (ZAP) Project Leader and a Distinguished Engineer at StackHawk, a company that uses ZAP to help users fix…
Listen to the episodeMazin Ahmed is a security engineer that specializes in AppSec and offensive security.
Listen to the episodeWhy do application security programs stall even after teams buy tools and define processes? James Ransome and Brook S. E.
Listen to the episodeMark Loveless - aka Simple Nomad - is a security researcher and hacker. He's spoken at numerous security and hacker conferences worldwide, including Blackhat, DEF CON, ShmooCon, and RSA.
Listen to the episodeJeroen Willemsen is a Principal Security Architect at Xebia. Jeroen is more or less a jack of all trades with an interest in infrastructure security, risk management, and application security.
Listen to the episodeBefore taking the plunge into information security leadership, Dustin Lehr spent over a decade as a software engineer and architect in a variety of…
Listen to the episodeAaron Rinehart is expanding the possibilities of chaos engineering to cybersecurity.
Listen to the episodeBrian Reed is Chief Mobility Officer at NowSecure. Brian has over 30 years in tech and 15 years in mobile, security, and apps dating back to the birth of…
Listen to the episodeWhich ideas from Season 7 deserve another listen? Chris and Robert assemble clips from across the season, creating a fast tour through secure development…
Listen to the episodeRuby on Rails can provide strong security defaults, but a framework cannot make every design decision for its developers.
Listen to the episodeCaroline Wong is the Chief Strategy Officer at Cobalt. io. You cannot hack yourself secure. The challenge is that developers get bored with hacking broken pieces of code after a while.
Listen to the episodeElie Saad is an application security engineer, leading three different OWASP projects.
Listen to the episodeDrew Dennison is the CTO & co-founder of r2c, a startup working to profoundly improve software security and reliability to safeguard human progress.
Listen to the episodeAaron Guzman specializes in IoT, embedded, and automotive security. Aaron is the Co-Author of “IoT Penetration Testing Cookbook”.
Listen to the episodeCindy Blake is the Senior Security Evangelist at GitLab. Cindy collaborates around best practices for integrated DevSecOps application security solutions with major enterprises.
Listen to the episodeFuzz testing can sound specialized and difficult, but Zsolt Imre argues that teams can start small and learn quickly.
Listen to the episodeAutomating security tests is useful, but it does not by itself make a development team secure.
Listen to the episodeHow did Microsoft's Security Development Lifecycle become a repeatable engineering practice rather than a one-time security push?
Listen to the episodeWhere should a small application security team begin when it cannot do everything? David Kosorok joins Chris and Robert with a practical framework: prevent, detect, and react.
Listen to the episodeWhat happens when Chris and Robert trade a single interview topic for five current application security ideas?
Listen to the episodeWhich parts of an AppSec program should change as a company grows, and which should stay the same?
Listen to the episodeWhy doesn't an executive mandate and a scanning tool add up to a software security program?
Listen to the episodeSecurity testing is more likely to happen when it fits the way developers already work.
Listen to the episodeHow does an intentionally vulnerable application become a community learning movement?
Listen to the episodeHow do you make a powerful security testing tool approachable to the developers who need it?
Listen to the episodeA secure mobile application can still sit on a compromised device or depend on an insecure cloud service.
Listen to the episodeMoving an application to Azure changes which security controls you operate yourself and which ones the platform can provide.
Listen to the episodeWhat can the wider AppSec community learn from Israel’s unusually dense security ecosystem?
Listen to the episodeWhy are SQL injection and cross-site scripting still with us after years of knowing how to prevent them?
Listen to the episodeMobile apps can hide credentials, expose powerful backend access, and repeat familiar web security mistakes.
Listen to the episodeA JavaScript library can keep working long after its security problems become public.
Listen to the episodeA threat model that lives in an old document rarely keeps pace with the code it describes.
Listen to the episodeFinding vulnerabilities is only part of improving software security; the harder work is changing how people build and operate applications.
Listen to the episodeCan security become a normal part of DevOps without turning every release into an audit? Julien Vehent, author of Securing DevOps, shares what his team learned protecting Firefox services at Mozilla.
Listen to the episodeWhich practices belong in a complete application security program? The Season 3 finale answers by assembling clips that move from early development…
Listen to the episodeA bug bounty can create a productive relationship with security researchers—or damage trust on both sides.
Listen to the episodeA log file does little good if nobody can use it to detect or investigate an attack.
Listen to the episodeWhat if the strongest argument for funding application security is better software delivery rather than fear of a breach?
Listen to the episodeA feature built into XML processing can become a path to file disclosure, internal requests, or denial of service.
Listen to the episodeBuying more scanners does not automatically create a better application security program.
Listen to the episodeMoving a security scanner earlier in the pipeline is not the same as building security into development.
Listen to the episodeAPIs may lack a visible interface, but that does not make them hidden or safe. Tanya Janca and Nicole Becher use OWASP DevSlop and its Pixi application to…
Listen to the episodeWhat can practitioners learn from a new OWASP document, an upcoming conference, and an industry analyst report in one conversation?
Listen to the episodeStatic analysis can help developers find security flaws early, but buying a scanner does not create an effective program.
Listen to the episodeSecurity testing loses value when its results arrive outside the developer’s normal workflow.
Listen to the episodeSecurity advice only helps when it connects to the needs of the people building and running the business.
Listen to the episodePart two follows Daniel Ramsbrock into the practical workflow of a web application penetration test.
Listen to the episodeWhat should developers and security teams understand before commissioning a web application penetration test?
Listen to the episodeWhich activities turn a secure development lifecycle from an aspiration into repeatable work?
Listen to the episode