The Application Security Podcast
The Application Security Podcast is a practitioner-led show for anyone building or securing modern software—and now AI-powered applications. Hosts Chris Romeo and Robert Hurlbut talk with the people shaping application security about AI and LLM security, threat modeling, secure development, OWASP, cloud, DevSecOps, security champions, and building programs that help engineering teams move faster and safer. With more than 300 episodes, the show turns real-world experience into practical guidance for developers, architects, AppSec professionals, and security leaders.
The Application Security Podcast
Latest Episodes
AI Pen Testing Killed Traditional DAST
Is traditional DAST finally dead? James Berthoty explains how AI pentesting is changing the dynamics of security testing through contextual payloads, autonomous agents, and application-aware vulnerability discovery. We also explore token cos...
AI Security: OWASP Meets Global Standards
AI security has no shortage of standards—but how do we turn them into practical guidance? Rob van der Veer explains how OWASP, the AI Exchange, and MOSAIC are coordinating global AI security efforts. We also explore responsible AI, agentic r...
The Future of Open-Source Threat Modeling
This episode is sponsored by Corgea.Design it. Build it. Ship it. Corgea secures it.Learn more:
Isaac Evans - AppSec in the Age of AI
In this episode, we sit down with Isaac Evans, co-founder and CEO of Semgrep, to talk about how AI is reshaping application security faster than almost anyone expected. Isaac walks us through why CI is losing its place as the central securit...
José Carlos Chávez - When Museums Get Hacked: OWASP Top 10 Lessons from Heists
In this episode, we sit down with Jose Carlos Chavez from Okta to break down the OWASP Top 10 for 2025 and what actually changed since 2021. We trace Jose's path from software engineering and observability into security, dig into why broken ...
Contributors
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
The Security Table
Izar Tarandach, Matt Coles, and Chris Romeo