The Application Security Podcast
The Application Security Podcast is a practitioner-led show for anyone building or securing modern software—and now AI-powered applications. Hosts Chris Romeo and Robert Hurlbut talk with the people shaping application security about AI and LLM security, threat modeling, secure development, OWASP, cloud, DevSecOps, security champions, and building programs that help engineering teams move faster and safer. With more than 300 episodes, the show turns real-world experience into practical guidance for developers, architects, AppSec professionals, and security leaders.
The Application Security Podcast
Mark Curphey -- The future of OWASP
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Mark Curphey is one of the creators of OWASP from the very early days. Mark worked in the background over the few decades of OWASP but has recently taken more to the spotlight. After running, he was elected and joined the OWASP Board of Directors. Hello, fine listeners from all over planet Earth. This is Chris Romeo, and I just wanted to let you know that you're in for a treat with this week's episode. This week we're joined by Mark Kerfe, and you may or may not have known, but Mark was involved in the creation of OWASP from the very early days. Now, Mark has been working in the background helping things happen over the few decades of OWASP, but he has recently run for and been elected to the OWASP Board of Directors.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
We help enterprises reduce vulnerabilities through application security education for developers and everyone in the SDLC.
→ Learn more about Security Journey
Connect with Mark Curphey:
→ Jeff Williams on LinkedIn
→ OWASP
Mentioned in this episode:
→ OWASP
→ OWASP Top Ten
→ WebGoat
→ OWASP Juice Shop
→ ZAP
→ OpenSSF
→ Alpha-Omega
→ Sigstore
→ CycloneDX
→ OWASP ModSecurity Core Rule Set
→ Royal Holloway Information Security
→ Ward Cunningham
→ Linux Foundation
→ Mark Curphey
→ OWASP Top Ten
→ OpenSSL
→ Jeff Williams on LinkedIn
→ Christian Folini
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Meet Mark Curphey: The future of OWASP
03:58 You're getting to university, you're in this kind of information security-focused
12:26 Would you say then was the first project
15:33 It definitely is fun to watch kind of where it's gotten
22:02 I think about, you know, kind of taking a different strategy
25:35 Yeah. No, that definitely makes sense. So, you know, when I
31:24 Cool. Let's transition and talk a little bit about the larger
35:06 There's a lot more moving pieces to it. So, When we
38:59 Yeah, that is a great goal for all of us to
People on this episode
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
The Security Table
Izar Tarandach, Matt Coles, and Chris Romeo