Skip to content
Artwork for The Application Security Podcast
The Application Security Podcast · June 16 · 48 min

Michael Burch - AI-Enabled Citizen Developers

When every employee can generate working software, who owns the risk? Michael Burch, VP of AI Enablement and Acceleration at Security Journey, explains how AI is turning nondevelopers into citizen developers faster than enterprises can build guardrails around them. He and the hosts examine rollouts that hand GitHub and Claude Code to hundreds of employees, the danger of measuring adoption instead of business value, and why prompt libraries alone do not meet people where they work. Michael argues for sandboxed workflows, automated security controls, clear limits, and AI champion programs that quietly carry security practices into every team. The discussion closes on evaluating generated code, token-cost incentives, and the need to define a measurable outcome before buying licenses or opening production access. Connect with Michael Burch: → Michael Burch on LinkedIn → Security Journey Mentioned in this episode: → SecureMyVibe → Manicode Security → The Security Champions Podcast → OWASP Low-Code/No-Code Top 10 → Claude Code Follow the Application Security Podcast: ➜ Home ➜ X ➜ LinkedIn ➜ YouTube ➜ Instagram ➜ Facebook Chapters: 00:00 Meet Michael Burch 02:12 From Army Ranger to AppSec education 05:40 What is an AI-era citizen developer? 06:52 When low-code guardrails disappear 08:49 Giving GitHub to 200 nondevelopers 12:16 The rollout is already underway 13:23 What happens outside the pipeline 17:20 Training gaps and adoption without outcomes 20:03 Measuring ROI instead of usage 22:28 Why prompt libraries are not enough 25:28 Sandboxing citizen developers 28:36 Are organizations waiting for a breach? 29:56 Turn security champions into AI champions 32:00 How AppSec teams need to change 34:58 Guardrails, expectations, and saying no 38:41 Can developers evaluate generated code? 42:40 Token pricing and platform lock-in 44:36 When token usage becomes the wrong incentive 46:17 A practical plan for citizen development 48:28 Closing thoughts Follow the Application Security Podcast: ➜ Home: appsecpodcast.com ➜ X: @AppSecPodcast ➜ LinkedIn: The Application Security Podcast ➜ YouTube: @ApplicationSecurityPodcast ➜ Instagram: @appsecpodcast ➜ Facebook: Application Security Podcast

0:00-48:58

transcript

No transcript — this publisher did not publish one.

show notes

When every employee can generate working software, who owns the risk? Michael Burch, VP of AI Enablement and Acceleration at Security Journey, explains how AI is turning nondevelopers into citizen developers faster than enterprises can build guardrails around them. He and the hosts examine rollouts that hand GitHub and Claude Code to hundreds of employees, the danger of measuring adoption instead of business value, and why prompt libraries alone do not meet people where they work. Michael argues for sandboxed workflows, automated security controls, clear limits, and AI champion programs that quietly carry security practices into every team. The discussion closes on evaluating generated code, token-cost incentives, and the need to define a measurable outcome before buying licenses or opening production access.

Connect with Michael Burch:
Michael Burch on LinkedIn
Security Journey

Mentioned in this episode:
SecureMyVibe
Manicode Security
The Security Champions Podcast
OWASP Low-Code/No-Code Top 10
Claude Code

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Meet Michael Burch
02:12 From Army Ranger to AppSec education
05:40 What is an AI-era citizen developer?
06:52 When low-code guardrails disappear
08:49 Giving GitHub to 200 nondevelopers
12:16 The rollout is already underway
13:23 What happens outside the pipeline
17:20 Training gaps and adoption without outcomes
20:03 Measuring ROI instead of usage
22:28 Why prompt libraries are not enough
25:28 Sandboxing citizen developers
28:36 Are organizations waiting for a breach?
29:56 Turn security champions into AI champions
32:00 How AppSec teams need to change
34:58 Guardrails, expectations, and saying no
38:41 Can developers evaluate generated code?
42:40 Token pricing and platform lock-in
44:36 When token usage becomes the wrong incentive
46:17 A practical plan for citizen development
48:28 Closing thoughts

Follow the Application Security Podcast:

➜ Home: appsecpodcast.com
➜ X: @AppSecPodcast
➜ LinkedIn: The Application Security Podcast
➜ YouTube: @ApplicationSecurityPodcast
➜ Instagram: @appsecpodcast
➜ Facebook: Application Security Podcast

links13