The Application Security Podcast
The Application Security Podcast is a practitioner-led show for anyone building or securing modern software—and now AI-powered applications. Hosts Chris Romeo and Robert Hurlbut talk with the people shaping application security about AI and LLM security, threat modeling, secure development, OWASP, cloud, DevSecOps, security champions, and building programs that help engineering teams move faster and safer. With more than 300 episodes, the show turns real-world experience into practical guidance for developers, architects, AppSec professionals, and security leaders.
The Application Security Podcast
Milan Williams -- AppSec Metrics
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Milan Williams discusses the importance of application security metrics and how to make them both meaningful and actionable. She explains that metrics are crucial for tracking progress in what can often feel like an overwhelming security landscape, and they're valuable for career advancement and securing resources. We discuss metrics categories and several specific metrics that are good to track. Milan shares important principles on the importance of making metrics actionable through storytelling and relating security impacts to real-world consequences for users. Milan Williams is a senior product manager at Semgrep, where she helps security engineers and developers work together to ship secure software. She recently graduated from Harvard University with degrees in computer science and physics.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
We provide application security training for not just your developers, but for all roles in your SDLC.
→ Learn more about Security Journey
Connect with Milan Williams:
→ Quiet Influence
→ Semgrep
Mentioned in this episode:
→ Quiet Influence
→ Semgrep
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Meet Milan Williams: AppSec Metrics
02:58 I like that idea. So, all right, Robert, where are we
04:45 Do you think people associate metrics with boring
07:13 Yeah. It's all about OKRs, objectives and key results. And I
10:33 If you've got that perspective, because it's one of those things
12:00 For the metrics framework, could you walk us through that a
15:19 Then, is there, are there additional metrics in the framework
16:48 Before we go to any of the remaining categories, metrics, so
22:55 Yeah. So, I took a turn there in the middle. We
25:54 If it's simple and it's easily, easy to calculate, whichever thing
27:05 Because that's the one that it's easy to create metrics, but
30:41 All right, Lon, we have 3 questions to ask about in
32:23 Very cool. And the final question is around book recommendations. What's
34:19 Very cool. So, Milan, what do you want to leave our
Follow the Application Security Podcast:
➜ Home: appsecpodcast.com
➜ X: @AppSecPodcast
➜ LinkedIn: The Application Security Podcast
➜ YouTube: @ApplicationSecurityPodcast
➜ Instagram: @appsecpodcast
➜ Facebook: Application Security Podcast
People on this episode
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
The Security Table
Izar Tarandach, Matt Coles, and Chris Romeo