The Application Security Podcast
The Application Security Podcast is a practitioner-led show for anyone building or securing modern software—and now AI-powered applications. Hosts Chris Romeo and Robert Hurlbut talk with the people shaping application security about AI and LLM security, threat modeling, secure development, OWASP, cloud, DevSecOps, security champions, and building programs that help engineering teams move faster and safer. With more than 300 episodes, the show turns real-world experience into practical guidance for developers, architects, AppSec professionals, and security leaders.
The Application Security Podcast
Brad Geesaman - Redefining AppSec with AI: Shrinking Toil, Expanding Impact - How LLMs are able to reduce toil in triage-heavy AppSec workflows
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
AppSec teams are drowning in repetitive triage while the work that requires judgment keeps piling up. Brad Geesaman, Principal Security Engineer at Ghost Security, explains how large language models can shrink that toil without handing security decisions to an unreliable black box. He walks through using LLMs for classification, evidence gathering, and contextual analysis, with humans retaining final authority. Brad and Chris examine prompt engineering, trust, market disruption, and the limits of incumbent tools built around producing ever-larger finding queues. They also explore AI-assisted remediation, code drift, and the changing day-to-day work of AppSec engineers. The result is a pragmatic model for gaining leverage from AI while preserving the expertise, accountability, and skepticism that effective security still demands.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
We provide application security training for not just your developers, but for all roles in your SDLC.
→ Learn more about Security Journey
Connect with Brad Geesaman:
→ Brad Geesaman on LinkedIn
→ Ghost Security Reaper
Mentioned in this episode:
→ Ghost Security
→ Reaper
→ Security Compass
→ OWASP ZAP
→ Burp Suite Professional
→ SQL Slammer
→ Code Red
→ Nimda
→ Exodus Communications
→ NetWitness
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Meet Brad Geesaman
03:01 What toil means in AppSec
05:20 Why triage drains security teams
06:13 Where AI can create leverage
09:29 Does an LLM need custom training?
11:51 Prompt engineering for useful results
13:33 Humans remain at the center
15:23 Trusting probabilistic systems
19:30 A seismic shift in AppSec tooling
20:18 Escaping the pile of findings
24:00 How incumbent vendors are responding
25:46 Why platform shifts leave openings
28:31 The AppSec engineer's changing day
33:04 Moving from triage to code changes
35:36 AI-generated code and application drift
38:49 What Brad hopes comes next
41:51 Closing thoughts
Follow the Application Security Podcast:
➜ Home: appsecpodcast.com
➜ X: @AppSecPodcast
➜ LinkedIn: The Application Security Podcast
➜ YouTube: @ApplicationSecurityPodcast
➜ Instagram: @appsecpodcast
➜ Facebook: Application Security Podcast
People on this episode
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
The Security Table
Izar Tarandach, Matt Coles, and Chris Romeo