The Application Security Podcast

The Application Security Podcast

Podcast de Chris Romeo and Robert Hurlbut

Disfruta 30 días gratis

4,99 € / mes después de la prueba.Cancela cuando quieras.

Phone screen with podimo app open surrounded by emojis

Más de 1 millón de oyentes

Podimo te va a encantar, y no sólo a ti

Valorado con 4,7 en la App Store

Acerca de The Application Security Podcast

Chris Romeo and Robert Hurlbut dig into the tips, tricks, projects, and tactics that make various application security professionals successful. They cover all facets of application security, from threat modeling and OWASP to DevOps+security and security champions. They approach these stories in an educational light, explaining the details in a way those new to the discipline can understand. Chris Romeo is the CEO of Devici and a General Partner at Kerr Ventures, and Robert Hurlbut is a Principal Application Security Architect focused on Threat Modeling at Aquia.

Todos los episodios

341 episodios
episode Akansha Shukla - Modern AppSec: Securing APIs with Threat Modeling and DevSecOps artwork
Akansha Shukla - Modern AppSec: Securing APIs with Threat Modeling and DevSecOps

Our guest today is Akansha Shukla, an information security professional with over 10 years of experience in application security, DevSecOps, and API security. We’re discussing why API security remains one of the least mature areas of AppSec today and exploring the challenges developers face when securing APIs. Akansha shares her insights on incorporating APIs into threat modeling exercises, the ongoing struggles with API discovery and inventory management, and the authorization challenges highlighted in the OWASP API Security Top 10. The conversation also touches on whether "shift left" is truly dead and why we still haven't solved basic security problems like input validation despite having the frameworks to address them. FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @AppSecPodcast [https://twitter.com/AppSecPodcast] ➜LinkedIn: The Application Security Podcast [https://www.linkedin.com/showcase/83990241] ➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast [https://www.youtube.com/channel/UCfrTGqjSsFCQW4k6TueuY-A] Thanks for Listening! ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

02 sept 2025 - 35 min
episode Getting Ready for the EU CRA artwork
Getting Ready for the EU CRA

The European Union's Cyber Resilience Act is set to revolutionize how we approach product security worldwide. In this episode, we sit down with application security expert Nariman Aga-Tagiyev to break down everything you need to know about this legislation. Nariman has over 20 years of software development experience and today he’s sharing his expertise with us. Learn what the EU CRA is and why it matters for global software companies, key compliance requirements, and how OWASP SAMM can help you. FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @AppSecPodcast [https://twitter.com/AppSecPodcast] ➜LinkedIn: The Application Security Podcast [https://www.linkedin.com/showcase/83990241] ➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast [https://www.youtube.com/channel/UCfrTGqjSsFCQW4k6TueuY-A] Thanks for Listening! ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

20 ago 2025 - 40 min
episode Marisa Fagan - Measuring Security Culture artwork
Marisa Fagan - Measuring Security Culture

Marisa Fagan, Head of Product at Katilyst and veteran security culture expert joins us today to  share practical strategies for building and scaling security champions programs that actually work, from designing effective pilots to avoiding common pitfalls that can derail your initiatives. Learn how to motivate developers using the SAPs model (Status, Access, Power, Stuff), why getting management buy-in is crucial before launching, and discover the metrics that truly demonstrate security culture success. Marisa reveals why most programs fail, shares her blueprint for creating sustainable security culture initiatives, and discusses the evolution beyond security champions to include privacy and accessibility programs.  Resources Mentioned:  • Security Champion Success Guide: https://securitychampionsuccessguide.org/ [https://securitychampionsuccessguide.org/]  • OWASP Security Champions Guide: securitychampions.owasp.org [http://securitychampions.owasp.org]  • People-Centric Security [https://www.amazon.com/People-Centric-Security-Transforming-Enterprise-Culture/dp/0071846778] book by Lance Hayden  FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @AppSecPodcast [https://twitter.com/AppSecPodcast] ➜LinkedIn: The Application Security Podcast [https://www.linkedin.com/showcase/83990241] ➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast [https://www.youtube.com/channel/UCfrTGqjSsFCQW4k6TueuY-A] Thanks for Listening! ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

05 ago 2025 - 50 min
episode Aram Hovsepyan -- Your Security Dashboard is Lying to You: The Science of Metrics artwork
Aram Hovsepyan -- Your Security Dashboard is Lying to You: The Science of Metrics

Aram Hovsepyan joins the podcast today to chat about the misconceptions behind common security metrics. Aram tells us how total vulnerability counts and CVSS scores can be misleading and he introduces us to the Goal Question Metric framework, this framework is a better approach to building truly effective security dashboards. Learn about the critical qualities of good metrics and how to ensure that your metrics accurately reflect your organization's security posture and readiness. Also, discover overlooked metrics that could offer deeper insights into your application security. FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @AppSecPodcast [https://twitter.com/AppSecPodcast] ➜LinkedIn: The Application Security Podcast [https://www.linkedin.com/showcase/83990241] ➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast [https://www.youtube.com/channel/UCfrTGqjSsFCQW4k6TueuY-A] Thanks for Listening! ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

22 jul 2025 - 40 min
episode Sean Varga -- OWASP Top 10 for AppSec Sales artwork
Sean Varga -- OWASP Top 10 for AppSec Sales

We’re discussing the intersections of application security (AppSec) and sales strategy with our guest, Sean Varga. Sean shares the unique challenges and best practices in AppSec sales, like the importance of empathy, understanding customer needs, and community participation. Learn about the OWASP top 10 for AppSec Sales and discover how to achieve success by aligning with customer goals, maintaining detailed living documents, and fostering strong partnerships.  FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @AppSecPodcast [https://twitter.com/AppSecPodcast] ➜LinkedIn: The Application Security Podcast [https://www.linkedin.com/showcase/83990241] ➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast [https://www.youtube.com/channel/UCfrTGqjSsFCQW4k6TueuY-A] Thanks for Listening! ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

15 jul 2025 - 47 min
Soy muy de podcasts. Mientras hago la cama, mientras recojo la casa, mientras trabajo… Y en Podimo encuentro podcast que me encantan. De emprendimiento, de salid, de humor… De lo que quiera! Estoy encantada 👍
Soy muy de podcasts. Mientras hago la cama, mientras recojo la casa, mientras trabajo… Y en Podimo encuentro podcast que me encantan. De emprendimiento, de salid, de humor… De lo que quiera! Estoy encantada 👍
MI TOC es feliz, que maravilla. Ordenador, limpio, sugerencias de categorías nuevas a explorar!!!
Me suscribi con los 14 días de prueba para escuchar el Podcast de Misterios Cotidianos, pero al final me quedo mas tiempo porque hacia tiempo que no me reía tanto. Tiene Podcast muy buenos y la aplicación funciona bien.
App ligera, eficiente, encuentras rápido tus podcast favoritos. Diseño sencillo y bonito. me gustó.
contenidos frescos e inteligentes
La App va francamente bien y el precio me parece muy justo para pagar a gente que nos da horas y horas de contenido. Espero poder seguir usándola asiduamente.
Phone screen with podimo app open surrounded by emojis

Valorado con 4,7 en la App Store

Disfruta 30 días gratis

4,99 € / mes después de la prueba.Cancela cuando quieras.

Podcasts exclusivos

Sin anuncios

Podcast gratuitos

Audiolibros

20 horas / mes

Prueba gratis

Sólo en Podimo

Audiolibros populares