The Application Security Podcast
The Application Security Podcast is a practitioner-led show for anyone building or securing modern software—and now AI-powered applications. Hosts Chris Romeo and Robert Hurlbut talk with the people shaping application security about AI and LLM security, threat modeling, secure development, OWASP, cloud, DevSecOps, security champions, and building programs that help engineering teams move faster and safer. With more than 300 episodes, the show turns real-world experience into practical guidance for developers, architects, AppSec professionals, and security leaders.
Episodes
308 episodes
Your AppSec Bottleneck Is a People Problem
Most security champions programs don't fail on tooling — they fail on people. Lisi Hocke spent three years as a champion before moving fully into product security, which means she has argued both sides of this from inside the trenches. Drawing ...
AI Pen Testing Killed Traditional DAST
Is traditional DAST finally dead? James Berthoty came back to settle the argument that his last episode started. James is the founder and analyst behind Latio, and he argues that AI pentesting is a genuinely different animal — payloads generate...
AI Security: OWASP Meets Global Standards
AI security has no shortage of standards — the problem is turning them into something a team can actually use. Rob van der Veer has spent 34 years in AI and security, founded the OWASP AI Exchange, and created MOSAIC, the agreement that brought...
The Future of Open-Source Threat Modeling
You don't have to let AI do the thinking for you. In this episode, Vikram Narayan shares why the smartest teams use AI as an accelerant — not a replacement — and why human judgment still matters most in threat modeling. Vikram created Precogly,...
Isaac Evans - AppSec in the Age of AI
AI is moving AppSec's control point out of CI and directly into the coding agent—but what happens when the model writing the code is also expected to secure it? Semgrep co-founder and CEO Isaac Evans explains why deep background analysis and re...
José Carlos Chávez - When Museums Get Hacked: OWASP Top 10 Lessons from Heists
Why do broken access control and injection still dominate the OWASP Top 10 despite years of mature tooling? Okta's José Carlos Chávez joins Chris to explain what changed in the 2025 list—and what stubbornly did not. Drawing on his path from sof...
Michael Burch - AI-Enabled Citizen Developers
When every employee can generate working software, who owns the risk? Michael Burch, VP of AI Enablement and Acceleration at Security Journey, explains how AI is turning nondevelopers into citizen developers faster than enterprises can build gu...
Josh Grossman--AI & SAST: Is it a match?
Traditional SAST is deterministic but shallow; AI can reason about context but may answer differently every time. Can the two approaches make each other better? Bounce Security CTO Josh Grossman explains why he built AGHAST, an open-source fram...
Dwayne McDaniel -- Secrets Sprawl and How AI is Impacting Secrets
GitGuardian found 29 million hard-coded secrets in public GitHub commits in one year—a 34% increase and its largest jump yet. Why is a supposedly simple problem getting worse? Principal Developer Advocate Dwayne McDaniel explains what the 2026 ...
Tanya Janca - Secure Vibe Coding
If AI writes all the code and the developer barely reads it, where does AppSec fit? Tanya Janca returns to define vibe coding and explain why models trained on insecure public code do not understand secure design by default. She and the hosts b...
Caroline Wong--The AI Cybersecurity Handbook
AI is multiplying the amount of software organizations produce, but security teams are not multiplying with it. Caroline Wong, author of The AI Cybersecurity Handbook and Chief Strategy Officer at Axari, explains how AppSec must change when age...
Steve Wilson--OpenClaw and Advanced AI Agents
OpenClaw makes always-on personal AI agents feel inevitable—and exposes how poorly prepared most organizations are for their autonomy. Steve Wilson, Chief AI and Product Officer at Exabeam and founder of the OWASP GenAI Security Project, return...
Brad Geesaman - Redefining AppSec with AI: Shrinking Toil, Expanding Impact - How LLMs are able to reduce toil in triage-heavy AppSec workflows
AppSec teams are drowning in repetitive triage while the work that requires judgment keeps piling up. Brad Geesaman, Principal Security Engineer at Ghost Security, explains how large language models can shrink that toil without handing security...
OWASP Candidate Debate - 2025 Edition
What should OWASP become, and which leaders have a credible plan to get it there? In this special 2025 Board of Directors candidate debate, nine candidates present their qualifications and answer the same questions about OWASP's future. The dis...
Francesco Cipollone - Agentic AI Manifesto
Most products labeled as AI agents are little more than chatbots with tools. Francesco Cipollone, founder and CEO of Phoenix Security, explains what makes an agent genuinely agentic and why his team uses multiple specialized models instead of o...
Simon Gibbs & Devika Gibbs -- Building Bridges with Games
Security education often struggles because the people in the room are being talked at instead of invited to participate. Simon and Devika Gibbs, the duo behind CyberSec Games, explain how tabletop games can turn abstract security concepts into ...
Akansha Shukla - Modern AppSec: Securing APIs with Threat Modeling and DevSecOps
APIs power modern applications, yet many AppSec programs still cannot reliably inventory them, model their threats, or enforce authorization. Akansha Shukla draws on more than a decade in application security and DevSecOps to explain why API se...
Getting Ready for the EU CRA
The EU Cyber Resilience Act turns product security from a best practice into a market-access requirement, and its effects extend well beyond Europe. Application Security Architect and OWASP SAMM core team member Nariman Aga-Tagiyev explains wha...
Marisa Fagan - Measuring Security Culture
Security champions programs rarely fail because the idea is bad; they fail because organizations launch without management support, meaningful incentives, or a plan to prove value. Marisa Fagan, Head of Product at Katilyst and a veteran securit...
Aram Hovsepyan -- Your Security Dashboard is Lying to You: The Science of Metrics
A dashboard full of green indicators can still describe an insecure organization. Aram Hovsepyan, founder and CEO of Codific and an OWASP SAMM contributor, explains why vulnerability totals and unexamined CVSS scores often measure activity inst...
Sean Varga -- OWASP Top 10 for AppSec Sales
We’re discussing the intersections of application security (AppSec) and sales strategy with our guest, Sean Varga. Sean shares the unique challenges and best practices in AppSec sales, like the importance of empathy, understanding customer need...
Sarah-Jane Madden -- What AI means for AppSec
Sarah-Jane Madden joins Chris and Robert to ask what AI actually changes in software development—and what foundational practices still matter. Drawing on her OWASP Global AppSec EU keynote, she challenges the idea that AI makes the SDLC obsolet...
Dag Flachet -- Kaizen for your Appsec Program
Dag Flachet joins us to discuss the concept of Kaizen and its application in improving application security. Dag shares his journey into the world of security, emphasizing the importance of iterative, small-step improvements. The conversation d...
Javan Rasokat and Andra Lezza -- When Chatbots Go Rogue - Lessons Learned from Building and Defending LLM Applications
What happens when teams add large language models to real applications and discover that familiar AppSec controls are no longer enough? Andra Lezza and Javan Rasokat share lessons from building, breaking, and defending LLM-enabled systems at Sa...
Jim Routh -- The CISO Transition to the rest of life
Former CISO Jim Routh discusses his perspective on retirement and career fulfillment in cybersecurity. Rather than viewing retirement as simply stopping work, Routh describes his three-filter approach: working only with people he respects and a...