The Application Security Podcast
The Application Security Podcast is a practitioner-led show for anyone building or securing modern software—and now AI-powered applications. Hosts Chris Romeo and Robert Hurlbut talk with the people shaping application security about AI and LLM security, threat modeling, secure development, OWASP, cloud, DevSecOps, security champions, and building programs that help engineering teams move faster and safer. With more than 300 episodes, the show turns real-world experience into practical guidance for developers, architects, AppSec professionals, and security leaders.
The Application Security Podcast
Tanya Janca -- A Secure SDLC from a Developer's Perspective
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Security expert Tanya Janca discusses her new book "Alice and Bob Learn Secure Coding" and shares insights on making security accessible to developers. In this engaging conversation, she explores how security professionals can better Tanya Jenka, aka She Hacks Purple, is the bestselling author of Alice and Bob Learn Secure Coding, Alice and Bob Learn Application Security, and Cards Against AppSec. Over her 28-year IT career, she's won countless awards, including the OWASP Lifetime Distinguished Member and Hacker of the Year. She has spoken all over the planet and is a prolific blogger. Tanya has trained thousands of software developers and IT security pros via her online academies, We Hack Purple and Semigroup Academy, and her live training programs.
Today's episode is brought to you by Security Journey.
About Security Journey
Our education platform teaches valuable secure coding skills based on real-world vulnerabilities and threats, including OWASP Top 10.
→ Learn more about Security Journey
Connect with Tanya Janca:
→ Ranakhalil1
→ Alice & Bob Learn Secure Coding
Mentioned in this episode:
→ Alice & Bob Learn Secure Coding
→ Confidence Staveley
→ Ranakhalil1
→ Laurabellmain
→ Adam Shostack
→ Liran Tal
→ OWASP Application Security Verification Standard (ASVS)
→ Tanya Janca (SheHacksPurple)
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Meet Tanya Janca: A Secure SDLC from a Developer's Perspective
02:28 Glad, glad to have you here. So we have an intro
06:50 This is definitely a needed piece of literature. I can, Robert
09:26 Really
11:23 Wow. Wow. So Robert, why don't you take us into that
23:26 I'm curious to see who comes to those talks. Is it
24:33 That's a— that's a view of the— the way what we're
28:10 See
30:46 It makes me, just made me think of something that I
35:05 About other areas
43:49 Put it on a t-shirt. That's good stuff. Well, that's, that's
46:03 Yeah, definitely. Definitely. Well, Tanya, how about a key takeaway for
Follow the Application Security Podcast:
➜ Home: appsecpodcast.com
➜ X: @AppSecPodcast
➜ LinkedIn: The Application Security Podcast
➜ YouTube: @ApplicationSecurityPodcast
➜ Instagram: @appsecpodcast
➜ Facebook: Application Security Podcast
People on this episode
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
The Security Table
Izar Tarandach, Matt Coles, and Chris Romeo