The Application Security Podcast

Farshad Abasi -- Three Models for Deploying AppSec Resources

Chris Romeo

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 9:18

Application security teams rarely have enough specialists to embed one expert with every development team. Farshad Abasi joins Chris for a focused comparison of three staffing models he used while building enterprise AppSec programs: expert-led support, a federated risk-based model, and a security champion or deputy model. Farshad explains why dedicated experts struggle to scale, how application tiering concentrates attention on the systems that matter most, and how champions can take ownership of routine security work with coaching and escalation from AppSec. The episode offers a practical progression for organizations trying to expand coverage without pretending scarce specialists can attend every stand-up and review every user story.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Farshad Abasi:
Farshad Abasi on LinkedIn
Forward Security

Mentioned in this episode:
OWASP Security Champions Guide
Forward Security

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Three models for deploying AppSec resources
01:21 Farshad Abasi’s path from development to security
03:28 The expert-led AppSec model
05:45 A federated, risk-based model
07:31 The security champion or deputy model
08:41 Choosing a model that can scale

People on this episode

Podcasts we love

Check out these other fine podcasts recommended by us, not an algorithm.

The Security Table Artwork

The Security Table

Izar Tarandach, Matt Coles, and Chris Romeo