Skip to content
Artwork for Beyond Vibe Coding
Beyond Vibe Coding · August 13 · 52 min

#S2.10 When Coding Agents Ship at Machine Speed, AppSec Has to Move Into the Loop - Jan Brennenstuhl

In this episode of Beyond Vibe Coding, Sebastian Heide-Meyer zu Erpen and André Neubauer talk with Jan Brennenstuhl about application security in the age of agentic engineering. Jan explains how his own workflow already depends on long-running local agents, why the surrounding harness matters more than the frontier model, and why spec-driven approaches can be useful when agents make greenfield projects grow very quickly. The main conversation focuses on a structural shift in AppSec. Jan argues that traditional security gates, delayed scanner feedback, and ticket-based remediation cannot keep up with machine-speed code generation. Security has to move into the agent loop, into platform defaults and into standardized engineering infrastructure so that agents replicate secure patterns instead of every local workaround and architectural exception. The episode closes with a prediction: verification of intent becomes the premium engineering capability. As implementation gets cheaper, the valuable work shifts toward understanding what should be built, proving that it was built correctly, and designing engineering systems that can safely absorb autonomous change. -- Links and References Jan Brennenstuhl: https://www.janbrennenstuhl.eu/ AppSec in the Age of Agentic Engineering: https://www.janbrennenstuhl.eu/appsec-agentic-engineering/ Shift Down: Why Agentic Engineering Demands Platform-Level Security: https://www.janbrennenstuhl.eu/shift-down-appsec/ Hugging Face Security Incident Disclosure, July 2026: https://huggingface.co/blog/security-incident-july-2026 OpenAI and Hugging Face Security Incident Statement: https://openai.com/index/hugging-face-model-evaluation-security-incident/ AGNTCon + MCPCon Europe 2026: https://agntconmcpconeu26.sched.com/ Beyond Vibe Coding Podcast is a project by Sebastian Heide-Meyer zu Erpen and André Neubauer, partnering with Impala Search. The content is created by us and our guests. Join the discussion on LinkedIn or visit www.bvc.fm, where we publish all episodes. For questions and inquiries, feel free to contact us via LinkedIn⁠⁠. Thank you for your time and see you in the next episode.

0:00-52:46

transcript

No transcript — this publisher did not publish one.

show notes

In this episode of Beyond Vibe Coding, Sebastian Heide-Meyer zu Erpen and André Neubauer talk with Jan Brennenstuhl about application security in the age of agentic engineering. Jan explains how his own workflow already depends on long-running local agents, why the surrounding harness matters more than the frontier model, and why spec-driven approaches can be useful when agents make greenfield projects grow very quickly.

The main conversation focuses on a structural shift in AppSec. Jan argues that traditional security gates, delayed scanner feedback, and ticket-based remediation cannot keep up with machine-speed code generation. Security has to move into the agent loop, into platform defaults and into standardized engineering infrastructure so that agents replicate secure patterns instead of every local workaround and architectural exception.

The episode closes with a prediction: verification of intent becomes the premium engineering capability. As implementation gets cheaper, the valuable work shifts toward understanding what should be built, proving that it was built correctly, and designing engineering systems that can safely absorb autonomous change.

--

Links and References

links7