
Michael Burch - AI-Enabled Citizen Developers
transcript
show notes
When every employee can generate working software, who owns the risk? Michael Burch, VP of AI Enablement and Acceleration at Security Journey, explains how AI is turning nondevelopers into citizen developers faster than enterprises can build guardrails around them. He and the hosts examine rollouts that hand GitHub and Claude Code to hundreds of employees, the danger of measuring adoption instead of business value, and why prompt libraries alone do not meet people where they work. Michael argues for sandboxed workflows, automated security controls, clear limits, and AI champion programs that quietly carry security practices into every team. The discussion closes on evaluating generated code, token-cost incentives, and the need to define a measurable outcome before buying licenses or opening production access.
Connect with Michael Burch:
→ Michael Burch on LinkedIn
→ Security Journey
Mentioned in this episode:
→ SecureMyVibe
→ Manicode Security
→ The Security Champions Podcast
→ OWASP Low-Code/No-Code Top 10
→ Claude Code
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Meet Michael Burch
02:12 From Army Ranger to AppSec education
05:40 What is an AI-era citizen developer?
06:52 When low-code guardrails disappear
08:49 Giving GitHub to 200 nondevelopers
12:16 The rollout is already underway
13:23 What happens outside the pipeline
17:20 Training gaps and adoption without outcomes
20:03 Measuring ROI instead of usage
22:28 Why prompt libraries are not enough
25:28 Sandboxing citizen developers
28:36 Are organizations waiting for a breach?
29:56 Turn security champions into AI champions
32:00 How AppSec teams need to change
34:58 Guardrails, expectations, and saying no
38:41 Can developers evaluate generated code?
42:40 Token pricing and platform lock-in
44:36 When token usage becomes the wrong incentive
46:17 A practical plan for citizen development
48:28 Closing thoughts
Follow the Application Security Podcast:
➜ Home: appsecpodcast.com
➜ X: @AppSecPodcast
➜ LinkedIn: The Application Security Podcast
➜ YouTube: @ApplicationSecurityPodcast
➜ Instagram: @appsecpodcast
➜ Facebook: Application Security Podcast