Skip to content
Artwork for The Application Security Podcast
TechnologyNewsTech NewsBusinessEntrepreneurship

The Application Security Podcast

Chris Romeo and Robert Hurlbut

The Application Security Podcast is a practitioner-led show for anyone building or securing modern software—and now AI-powered applications. Hosts Chris Romeo and Robert Hurlbut talk with the people shaping application security about AI and LLM security, threat modeling, secure development, OWASP, cloud, DevSecOps, security champions, and building programs that help engineering teams move faster and safer. With more than 300 episodes, the show turns real-world experience into practical guidance for developers, architects, AppSec professionals, and security leaders.

Play
  • 20 episodes
  • fortnightly
  • Avg 44 min
  • English
  • S13 · E9
    Wednesday · 47 min

    AI Security: OWASP Meets Global Standards

    AI security has no shortage of standards—but how do we turn them into practical guidance? Rob van der Veer explains how OWASP, the AI Exchange, and MOSAIC are coordinating global AI security efforts. We also explore responsible AI, agentic red teaming, vulnerability discovery, and how AI could level the playing field between attackers and defenders. This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it. Learn more: Corgea.com About Corgea Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely. Learn more about Corgea → https://bit.ly/4wMCNUf FOLLOW OUR SOCIAL MEDIA: ➜ Twitter: @AppSecPodcast ➜ LinkedIn: The Application Security Podcast ➜ YouTube: @ApplicationSecurityPodcast FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @AppSecPodcast ➜LinkedIn: The Application Security Podcast ➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

  • S13 · E8
    August 17 · 40 min

    The Future of Open-Source Threat Modeling

    This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it. Learn more: Corgea.com You don’t have to let AI do the thinking for you. In this episode, Vikram shares why the smartest teams use AI as an accelerant — not a replacement — and why human judgment still matters most in threat modeling. We dig into the tension among speed, compliance, and real risk, and what it means to “fight the AI” so that critical thinking stays sharp. If you care about AppSec, AI, and the future of threat modeling, this conversation will give you a lot to think about. About Corgea Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting — helping security and engineering teams find risk earlier, fix what matters, and ship securely. Learn more about Corgea → Corgea.com FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @AppSecPodcast ➜LinkedIn: The Application Security Podcast ➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

  • S13 · E7
    July 28 · 49 min

    Isaac Evans - AppSec in the Age of AI

    In this episode, we sit down with Isaac Evans, co-founder and CEO of Semgrep, to talk about how AI is reshaping application security faster than almost anyone expected. Isaac walks us through why CI is losing its place as the central security control point, replaced by deep background jobs that hunt for vulnerabilities using large models and real-time plugins that sit inside coding agents and force them to regenerate code until it meets an organization's security bar. We dig into what this means for the role of the security engineer, why customization is replacing universal rule sets, and how trust, verification, and the limits of reasoning about model behavior remain the hardest problems in the room. We also talk about vibe coding at scale, the return of business logic flaws as SQL injection becomes easier for models to catch, and why Isaac sees more opportunity than threat in this shift, even as he expects a wave of new vulnerabilities and cleanup work along the way. FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @AppSecPodcast ➜LinkedIn: The Application Security Podcast ➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

  • S13 · E8
    July 21 · 52 min

    José Carlos Chávez - When Museums Get Hacked: OWASP Top 10 Lessons from Heists

    In this episode, we sit down with Jose Carlos Chavez from Okta to break down the OWASP Top 10 for 2025 and what actually changed since 2021. We trace Jose's path from software engineering and observability into security, dig into why broken access control still holds the number one spot despite mature tooling, and ask the question that never seems to get old: why is injection still a top five risk after decades of parameterized queries and ORMs? Jose walks us through the growing role of supply chain and software integrity failures, the surprisingly weak security posture around AI skills and agent permissions, and why immutable, reliable logging still matters as much as ever. We close on root causes that show up across nearly every category on the list and why ownership, not tooling alone, is what actually moves the needle on security. FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @AppSecPodcast ➜LinkedIn: The Application Security Podcast ➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

  • S13 · E6
    June 16 · 48 min

    Michael Burch - AI-Enabled Citizen Developers

    AI adoption is accelerating faster than most organizations know how to handle it, and the gap between curiosity and confident use is where things go wrong. Michael Burch, VP of AI Enablement and Acceleration, joins to break down what it actually takes to move teams from "interested in AI" to using it responsibly and effectively in their day-to-day work. He shares why successful adoption depends less on the technology itself and more on trust, clear guidance, and making AI approachable for non-technical teams. Whether you are leading an AI initiative or just trying to figure out where to start, this episode is a practical look at what real adoption looks like inside organizations today. FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @AppSecPodcast ➜LinkedIn: The Application Security Podcast ➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

  • S13 · E5
    June 2 · 40 min

    Josh Grossman--AI & SAST: Is it a match?

    AI coding tools are accelerating development fast, but they’re also exposing the limits of traditional AppSec tooling. Josh Grossman, CTO of Bounce Security and longtime AppSec consultant, joins the podcast to break down AGHAST, his new open-source security tool that combines static analysis with AI to uncover business logic flaws and authorization issues that traditional scanners miss. FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @AppSecPodcast ➜LinkedIn: The Application Security Podcast ➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

  • S13 · E4
    May 14 · 45 min

    Dwayne McDaniel -- Secrets Sprawl and How AI is Impacting Secrets

    GitGuardian found 29 million hard-coded secrets leaked in public GitHub commits in a single year, a 34% jump and the biggest spike they've ever recorded. Dwayne McDaniel joins to break down why AI coding tools, MCP servers, and a false sense of security in private repos are making the problem worse, and what it'll actually take to fix it. Check out the report here - https://www.gitguardian.com/files/the-state-of-secrets-sprawl-report-2026. Dwayne McDaniel is a Principal Developer Advocate who has been on a mission to "help people figure stuff out" for over a decade. At GitGuardian, he specializes in secrets security and non-human identity governance across cloud and DevOps environments. FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @AppSecPodcast ➜LinkedIn: The Application Security Podcast ➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

  • S13 · E3
    April 30 · 47 min

    Tanya Janca - Secure Vibe Coding

    AI isn’t just helping developers anymore; it’s writing the code, and that changes everything. In this episode, Tanya Janca breaks down “vibe coding,” the hidden security risks behind it, and how teams need to rethink AppSec from the ground up. If you’re building with AI, this is the wake-up call you can’t afford to miss. Tanya Janca, AKA SheHacksPurple, is an author, founder, trainer, speaker, software developer, but most of all, a nerd obsessed with security. She speaks and teaches secure coding worldwide and through her podcast, DevSec Station. Check it out here: https://www.youtube.com/@DevSecStation FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @AppSecPodcast ➜LinkedIn: The Application Security Podcast ➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

  • S13 · E2
    April 21 · 44 min

    Caroline Wong--The AI Cybersecurity Handbook

    Caroline Wong, author of The AI Cybersecurity Handbook and Chief Strategy Officer at Axari, is back! Caroline shares how AI is rapidly changing AppSec, driving massive increases in code, accelerating risk, and challenging traditional security practices. The conversation covers AI-generated code, trust and explainability, and how security teams must adapt to keep up. FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @AppSecPodcast ➜LinkedIn: The Application Security Podcast ➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

  • S13 · E1
    April 15 · 49 min

    Steve Wilson--OpenClaw and Advanced AI Agents

    In this episode of the Application Security Podcast, Chris Romeo and Robert Hurlbut welcome back Steve Wilson, a global leader in AI security and Chief AI and Product Officer at Exabeam, as well as founder of the OWASP Gen AI Security Project. Steve shares how his AI assistant was “hacked” using a simple phishing attack, highlighting a major shift in security—AI agents behave more like humans than traditional software. The conversation explores how this changes the threat model, why AppSec is struggling to keep up, and how organizations should approach the practical security of AI systems. They also cover the risks of autonomous agents, the expanding blast radius of failures, and what AppSec professionals can do now to adapt. FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @AppSecPodcast ➜LinkedIn: The Application Security Podcast ➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

  • S12 · E20
    Oct 28, 2025 · 42 min

    Brad Geesaman - Redefining AppSec with AI: Shrinking Toil, Expanding Impact - How LLMs are able to reduce toil in triage-heavy AppSec workflows

    Brad Geesaman, Principal Security Engineer at Ghost, joins the podcast today to explore how AI and large language models are transforming the world of application security. The discussion starts with the concept of "toil"—the repetitive, exhausting work that drains AppSec teams as they struggle to keep up with mountains of security findings and alerts. Brad shares his insights on how LLMs can provide meaningful leverage by handling the heavy lifting of triage, classification, and evidence gathering, while keeping humans firmly in the loop for final decisions. They also discuss the seismic shift happening in the AppSec market, with AI-native approaches potentially disrupting traditional security tooling. Listen along to hear more about the future of secure coding and how artificial intelligence might finally give security teams the helicopter view they need to fight fires effectively. FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @AppSecPodcast ➜LinkedIn: The Application Security Podcast ➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

  • S12 · E19
    Oct 15, 2025 · 1 hr 8 min

    OWASP Candidate Debate - 2025 Edition

    In this special episode of the Application Security Podcast we meet nine of the OWASP Board of Directors candidates. Each candidate discusses their unique qualifications, experiences, and vision for OWASP's future. Topics include enhancing OWASP's impact, improving outreach and education, securing funding, and engaging local chapters. Don't miss this insightful debate as these candidates share their strategies to help secure a brighter future for OWASP. FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @AppSecPodcast ➜LinkedIn: The Application Security Podcast ➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

  • S12 · E18
    Sep 23, 2025 · 33 min

    Francesco Cipollone - Agentic AI Manifesto

    Francesco Cipollone, the CEO of Phoenix Security, shares his extensive experience in AI and security, discussing the crucial difference between true AI agents and glorified chatbots. Learn why Phoenix Security utilizes six different LLMs instead of a single super agent. Understand the sobering economics behind AI implementation and the importance of adopting AI responsibly. Get practical advice on integrating AI agents to enhance, not replace, human capabilities, while touching on the Agentic AI Manifesto's key principles. This conversation is perfect for anyone navigating the AI landscape both cautiously and optimistically. FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @AppSecPodcast ➜LinkedIn: The Application Security Podcast ➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

  • S12 · E17
    Sep 16, 2025 · 36 min

    Simon Gibbs & Devika Gibbs -- Building Bridges with Games

    Simon and Devika Gibbs, the innovative minds behind Cybersec Games, join us on the episode today. Discover how the Gibbs duo are revolutionizing the way we teach and learn security concepts through interactive gaming. Learn about their journey from developing stationary for agile teams to delving into the world of threat modeling games like Elevation of Privilege. We talk about the power of gamification in cybersecurity education, and get the inside scoop on their Cybersecurity Game Challenge, which invites creative minds to bring their game ideas to life. FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @AppSecPodcast ➜LinkedIn: The Application Security Podcast ➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

  • S12 · E16
    Sep 2, 2025 · 35 min

    Akansha Shukla - Modern AppSec: Securing APIs with Threat Modeling and DevSecOps

    Our guest today is Akansha Shukla, an information security professional with over 10 years of experience in application security, DevSecOps, and API security. We’re discussing why API security remains one of the least mature areas of AppSec today and exploring the challenges developers face when securing APIs. Akansha shares her insights on incorporating APIs into threat modeling exercises, the ongoing struggles with API discovery and inventory management, and the authorization challenges highlighted in the OWASP API Security Top 10. The conversation also touches on whether "shift left" is truly dead and why we still haven't solved basic security problems like input validation despite having the frameworks to address them. FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @AppSecPodcast ➜LinkedIn: The Application Security Podcast ➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

  • S12 · E15
    Aug 20, 2025 · 40 min

    Getting Ready for the EU CRA

    The European Union's Cyber Resilience Act is set to revolutionize how we approach product security worldwide. In this episode, we sit down with application security expert Nariman Aga-Tagiyev to break down everything you need to know about this legislation. Nariman has over 20 years of software development experience and today he’s sharing his expertise with us. Learn what the EU CRA is and why it matters for global software companies, key compliance requirements, and how OWASP SAMM can help you. FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @AppSecPodcast ➜LinkedIn: The Application Security Podcast ➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

  • S12 · E13
    Aug 5, 2025 · 50 min

    Marisa Fagan - Measuring Security Culture

    Marisa Fagan, Head of Product at Katilyst and veteran security culture expert joins us today to share practical strategies for building and scaling security champions programs that actually work, from designing effective pilots to avoiding common pitfalls that can derail your initiatives. Learn how to motivate developers using the SAPs model (Status, Access, Power, Stuff), why getting management buy-in is crucial before launching, and discover the metrics that truly demonstrate security culture success. Marisa reveals why most programs fail, shares her blueprint for creating sustainable security culture initiatives, and discusses the evolution beyond security champions to include privacy and accessibility programs. Resources Mentioned: • Security Champion Success Guide: https://securitychampionsuccessguide.org/ • OWASP Security Champions Guide: securitychampions.owasp.org • People-Centric Security book by Lance Hayden FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @AppSecPodcast ➜LinkedIn: The Application Security Podcast ➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

  • S12 · E12
    Jul 22, 2025 · 40 min

    Aram Hovsepyan -- Your Security Dashboard is Lying to You: The Science of Metrics

    Aram Hovsepyan joins the podcast today to chat about the misconceptions behind common security metrics. Aram tells us how total vulnerability counts and CVSS scores can be misleading and he introduces us to the Goal Question Metric framework, this framework is a better approach to building truly effective security dashboards. Learn about the critical qualities of good metrics and how to ensure that your metrics accurately reflect your organization's security posture and readiness. Also, discover overlooked metrics that could offer deeper insights into your application security. FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @AppSecPodcast ➜LinkedIn: The Application Security Podcast ➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

  • S12 · E11
    Jul 15, 2025 · 47 min

    Sean Varga -- OWASP Top 10 for AppSec Sales

    We’re discussing the intersections of application security (AppSec) and sales strategy with our guest, Sean Varga. Sean shares the unique challenges and best practices in AppSec sales, like the importance of empathy, understanding customer needs, and community participation. Learn about the OWASP top 10 for AppSec Sales and discover how to achieve success by aligning with customer goals, maintaining detailed living documents, and fostering strong partnerships. FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @AppSecPodcast ➜LinkedIn: The Application Security Podcast ➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

  • S12 · E10
    Jul 9, 2025 · 37 min

    Sarah-Jane Madden -- What AI means for AppSec

    Sarah Jane Madden joins us to discuss the evolving role of AI in software development. We reflect on the changes and challenges posed by AI, including the potential for over-reliance and the misconception that traditional software engineering practices like the SDLC are obsolete. The conversation explores the nuances of AI-generated code, emphasizing the importance of maintaining foundational engineering skills and a critical understanding of the tools used. Madden shares insights from her keynote at OWASP Barcelona and stresses the need for responsible and thoughtful integration of AI in development workflows. Key takeaways include leveraging AI for efficiency while avoiding complacency and ensuring a deep, ongoing engagement with code and quality practices. Previous Episode with Sarah-Jane Madden: Threat Modeling to Established Teams FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @AppSecPodcast ➜LinkedIn: The Application Security Podcast ➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Showing 1–20 of 20 episodes