Skip to content
PodcastsBusinessThe Application Security Podcast

The Application Security Podcast

Chris Romeo and Robert Hurlbut
The Application Security Podcast
Latest episode

308 episodes

  • The Application Security Podcast

    Your AppSec Bottleneck Is a People Problem

    07/09/2026 | 48 mins.
    Most security champions programs don't fail on tooling — they fail on people. Lisi Hocke spent three years as a champion before moving fully into product security, which means she has argued both sides of this from inside the trenches. Drawing on the talk she and Mireia Cano gave at OWASP Global AppSec EU 2026, Lisi walks us through the four things that actually make these programs work: psychological safety first, then cognitive load, then influence when you hold no formal authority, then a champions community so the whole thing doesn't stall the week security goes on vacation. We also get into cutting security wait times, winning organizational support, what AI does and doesn't change here, and why she will tell you never to record the champions meeting.
    This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.
    About Corgea
    Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.
    → Learn more about Corgea
    Connect with Lisi Hocke:
    → Lisi Hocke on LinkedIn
    → A Tester's Journey — Lisi's blog
    Mentioned in this episode:
    → Slides: Security Champions — Lessons from Opposite Trenches (with Mireia Cano)
    → OWASP Juice Shop
    Follow the Application Security Podcast:
    ➜ Home: appsecpodcast.com
    ➜ X: @AppSecPodcast
    ➜ LinkedIn: The Application Security Podcast
    ➜ YouTube: @ApplicationSecurityPodcast
    ➜ Instagram: @appsecpodcast
    ➜ Facebook: Application Security Podcast
    Chapters:
    00:00 Cold open — what psychological safety actually means
    00:56 Meet Lisi Hocke
    02:25 Lisi's security origin story
    05:42 "That place was taken" — becoming a champion anyway
    07:39 Moving into a full-time product security role
    08:39 Meeting Björn Kimminich, the Juice Shop project lead
    09:23 Why role play instead of a normal conference talk
    12:27 Security and development, disconnected
    14:19 The first full-time security role
    15:14 Making people wait is the real damage
    17:10 Cutting the backlog and the turnaround time
    19:31 What Lisi got dead wrong
    20:08 What testing and quality work taught her
    21:31 The four things that make champions programs work
    22:07 One: fostering psychological safety
    24:50 Champions without their manager's blessing
    28:45 Two: managing cognitive load
    29:46 Three kinds of load, and which one to cut
    31:21 Three: power sources when you have no formal authority
    33:03 Four: build a champions community
    34:38 Keeping security people from burning out
    36:37 How AI changes who you recruit and what you need
    39:32 Should AI change champions programs at all?
    40:33 Psychological safety when a bot joins the meeting
    42:25 Don't record the champions meetings
    43:26 Programs that outlive the person who started them
    45:59 Key takeaway and homework
    47:21 Closing thoughts
    Follow the Application Security Podcast:
    ➜ Home: appsecpodcast.com
    ➜ X: @AppSecPodcast
    ➜ LinkedIn: The Application Security Podcast
    ➜ YouTube: @ApplicationSecurityPodcast
    ➜ Instagram: @appsecpodcast
    ➜ Facebook: Application Security Podcast
  • The Application Security Podcast

    AI Pen Testing Killed Traditional DAST

    31/08/2026 | 43 mins.
    Is traditional DAST finally dead? James Berthoty came back to settle the argument that his last episode started. James is the founder and analyst behind Latio, and he argues that AI pentesting is a genuinely different animal — payloads generated with context about your actual application, agents that chase findings the way a human tester would, and results a scanner was never going to produce. We get into what it costs once tokens enter the picture, who pays for them, whether a pentest on every pull request is realistic, and what stops an autonomous tester from going further than it should. Then we look further out: the future of bug bounties, what happens when cloud and model providers absorb today's security tooling, and who is accountable when an agent deletes your production database.
    This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.
    About Corgea
    Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.
    → Learn more about Corgea
    Connect with James Berthoty:
    → James Berthoty on LinkedIn
    → Latio
    → Latio Pulse
    Mentioned in this episode:
    → Latio's free reports
    → James on the podcast the first time: Is DAST Dead? And the future of API security
    Follow the Application Security Podcast:
    ➜ Home: appsecpodcast.com
    ➜ X: @AppSecPodcast
    ➜ LinkedIn: The Application Security Podcast
    ➜ YouTube: @ApplicationSecurityPodcast
    ➜ Instagram: @appsecpodcast
    ➜ Facebook: Application Security Podcast
    Chapters:
    00:00 Cold open — the results speak for themselves
    01:01 Meet James Berthoty and the "Is DAST dead?" fallout
    01:31 Chickens, eggs, and getting away from screens
    03:46 Why we're revisiting the DAST question
    04:14 A working definition of AI pentesting
    05:47 Contextual payloads and application awareness
    06:47 Determinism, repeatability, and what buyers actually want
    07:46 Can you run an AI pentest on every code change?
    09:43 What it really costs
    10:40 Incumbents vs. AI-native vendors
    13:27 Who pays for the tokens?
    14:29 Bundling, platforms, and competitive pressure
    16:25 AI across the whole development workflow
    18:22 Agents that run all the way to deployment
    19:21 A pentest on every pull request
    21:52 What stops a pentest from going too far?
    23:10 Permission scoping and guardrails
    26:07 Where the findings actually land
    28:02 The future of bug bounties
    30:50 Why pentests command more budget than DAST
    31:45 Could the cloud providers absorb security tooling?
    34:38 What model providers could build instead
    36:36 The same story on the code scanning side
    39:24 Accountability when the tool misses something
    40:22 Shared responsibility when an agent deletes production
    41:23 The verdict on DAST
    42:19 Where to find Latio's free reports
    43:15 Closing thoughts
    Follow the Application Security Podcast:
    ➜ Home: appsecpodcast.com
    ➜ X: @AppSecPodcast
    ➜ LinkedIn: The Application Security Podcast
    ➜ YouTube: @ApplicationSecurityPodcast
    ➜ Instagram: @appsecpodcast
    ➜ Facebook: Application Security Podcast
  • The Application Security Podcast

    AI Security: OWASP Meets Global Standards

    26/08/2026 | 47 mins.
    AI security has no shortage of standards — the problem is turning them into something a team can actually use. Rob van der Veer has spent 34 years in AI and security, founded the OWASP AI Exchange, and created MOSAIC, the agreement that brought eight standards bodies together with SANS to stop the fragmentation. Rob explains what responsible AI really means, what the EU AI Act actually asks of you, and why most AppSec teams are still missing the point on AI-generated code. We also get into agentic red teaming, what happens when agents quietly exceed their scope, and whether AI finally levels the playing field between attackers and defenders. If you build software with AI in it — or with AI — this one is worth your time.
    This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.
    About Corgea
    Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.
    → Learn more about Corgea
    Connect with Rob van der Veer:
    → Rob van der Veer on LinkedIn
    → OWASP AI Exchange
    → MOSAIC
    Mentioned in this episode:
    → OpenCRE
    → Luna and the Magic AI Paintbrush
    Follow the Application Security Podcast:
    ➜ Home: appsecpodcast.com
    ➜ X: @AppSecPodcast
    ➜ LinkedIn: The Application Security Podcast
    ➜ YouTube: @ApplicationSecurityPodcast
    ➜ Instagram: @appsecpodcast
    ➜ Facebook: Application Security Podcast
    Chapters:
    00:00 Cold open — don't be surprised when the AI breaks out of the cage
    01:15 Meet Rob van der Veer: music, cycling, and the Hoodoo 500
    05:24 Defining responsible AI
    07:41 Fairness, protected attributes, and transparency
    09:34 The EU AI Act and what regulation actually asks of you
    11:27 How AI changes every part of software development
    13:23 Where responsibility lands
    15:20 You're not defending your own data center
    17:19 What traditional AppSec teams consistently miss about AI
    18:18 Finding vulnerabilities in AI-generated code
    19:19 Too many standards — and using AI to write them
    20:51 MOSAIC: eight standards bodies, one agreement
    22:09 One machine-readable taxonomy with OpenCRE
    23:06 Can AI level the field between attackers and defenders?
    25:59 When AI security becomes security theater
    26:56 What agentic red teaming actually looks like
    29:44 When agents exceed their scope
    32:43 Luna and the Magic AI Paintbrush
    33:40 Do we sandbox the agents?
    34:40 Guardrails without killing creativity
    36:39 Skill atrophy when AI is your only way forward
    40:04 "How do we hit this quarter?" and the pressure to ship
    43:16 Everyone is selling agentic security
    45:07 Key takeaways and where to start with the AI Exchange
    47:12 Closing thoughts
    Follow the Application Security Podcast:
    ➜ Home: appsecpodcast.com
    ➜ X: @AppSecPodcast
    ➜ LinkedIn: The Application Security Podcast
    ➜ YouTube: @ApplicationSecurityPodcast
    ➜ Instagram: @appsecpodcast
    ➜ Facebook: Application Security Podcast
  • The Application Security Podcast

    The Future of Open-Source Threat Modeling

    17/08/2026 | 40 mins.
    You don't have to let AI do the thinking for you. In this episode, Vikram Narayan shares why the smartest teams use AI as an accelerant — not a replacement — and why human judgment still matters most in threat modeling. Vikram created Precogly, an open-source threat modeling platform now running as an OWASP project, and he walks us through what it took to build a free tool on par with commercial vendors. We dig into the tension among speed, compliance, and real risk; whether the Threat Modeling Manifesto needs amending for AI; and what it means to "fight the AI" so critical thinking stays sharp. If you care about AppSec, AI, and the future of threat modeling, this conversation will give you a lot to think about.
    This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.
    About Corgea
    Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.
    → Learn more about Corgea
    Connect with Vikram Narayan:
    → Vikram Narayan on LinkedIn
    → Precogly — open-source threat modeling (OWASP project)
    Mentioned in this episode:
    → Threat Modeling Manifesto
    → ThreatModCon
    Follow the Application Security Podcast:
    ➜ Home: appsecpodcast.com
    ➜ X: @AppSecPodcast
    ➜ LinkedIn: The Application Security Podcast
    ➜ YouTube: @ApplicationSecurityPodcast
    ➜ Instagram: @appsecpodcast
    ➜ Facebook: Application Security Podcast
    Chapters:
    00:00 Cold open — the threat model that "feels wrong"
    01:22 Welcome and introductions
    02:17 Vikram's security origin story
    05:43 From machine learning research into LLMs
    06:42 Hospital chatbots, hallucination, and knowing when to escalate
    07:51 ThreatModCon and the case for an open-source threat modeling tool
    09:35 IoT, emergence, and the traffic-light problem
    11:17 The OWASP Vienna talk and the Threat Modeling Manifesto
    12:26 Why "AI, just do the threat model" falls apart
    15:14 What AI is actually good at in threat modeling
    18:07 Human discomfort vs. the machine's confident answer
    20:29 Inside Precogly: accelerant, not replacement
    20:58 Library packs and the skills layer
    24:50 Where AI kicks in — and where it shouldn't
    27:48 Should the Threat Modeling Manifesto be amended for AI?
    30:28 Where Chris and Robert land
    31:36 Wi-Fi sensing, privacy, and modeling what you can't see
    33:15 If you can't explain it, can you trust it?
    35:11 Beyond checklists — design-level questions
    35:59 Fight the AI — Vikram's key takeaway
    39:10 Closing thoughts
    Follow the Application Security Podcast:
    ➜ Home: appsecpodcast.com
    ➜ X: @AppSecPodcast
    ➜ LinkedIn: The Application Security Podcast
    ➜ YouTube: @ApplicationSecurityPodcast
    ➜ Instagram: @appsecpodcast
    ➜ Facebook: Application Security Podcast
  • The Application Security Podcast

    Isaac Evans - AppSec in the Age of AI

    28/07/2026 | 49 mins.
    AI is moving AppSec's control point out of CI and directly into the coding agent—but what happens when the model writing the code is also expected to secure it? Semgrep co-founder and CEO Isaac Evans explains why deep background analysis and real-time agent plugins may replace universal rule sets with organization-specific security controls. He and Chris explore how security engineering roles will change, why independent verification still matters, and where business-logic flaws may become the next major battleground. The conversation also covers vibe coding at enterprise scale, the limits of reasoning about model behavior, open source in an agent-built world, and why Isaac sees more opportunity than threat even as AI creates a fresh wave of vulnerabilities and cleanup work.
    Connect with Isaac Evans:
    → Isaac Evans on LinkedIn
    → Semgrep
    Mentioned in this episode:
    → Semgrep
    → DeepSeek
    → Cursor
    → OpenAI Codex
    → Claude Code
    → Boston Dynamics
    → DARPA Robotics Challenge
    → Reflections on Trusting Trust
    → uutils/coreutils
    → Rust
    Follow the Application Security Podcast:
    ➜ Home
    ➜ X
    ➜ LinkedIn
    ➜ YouTube
    ➜ Instagram
    ➜ Facebook
    Chapters:
    00:00 Meet Isaac Evans
    01:11 From cryptography to the DARPA Robotics Challenge
    03:43 Founding Semgrep
    04:05 How AI is reshaping AppSec
    06:15 Attackers, defenders, and model choice
    08:02 Regenerating code until it clears the security bar
    10:30 Organization-specific rules beat universal rules
    14:18 The changing role of the security engineer
    17:53 Career advice for security practitioners
    19:47 Will foundation models absorb security vendors?
    24:18 Getting secure changes across an enterprise
    26:40 Trusting Trust becomes the easy problem
    27:41 How much should we trust agent-generated code?
    29:38 Independent verification and competing models
    34:50 Business logic flaws after SQL injection
    36:56 Protecting the new wave of citizen developers
    39:40 Vibe coding and disposable software
    42:05 Open source in an agent-built world
    44:10 Can the exponential pace continue?
    44:41 Key takeaways and calls to action
    Follow the Application Security Podcast:
    ➜ Home: appsecpodcast.com
    ➜ X: @AppSecPodcast
    ➜ LinkedIn: The Application Security Podcast
    ➜ YouTube: @ApplicationSecurityPodcast
    ➜ Instagram: @appsecpodcast
    ➜ Facebook: Application Security Podcast
More Business podcasts
About The Application Security Podcast
The Application Security Podcast is a practitioner-led show for anyone building or securing modern software—and now AI-powered applications. Hosts Chris Romeo and Robert Hurlbut talk with the people shaping application security about AI and LLM security, threat modeling, secure development, OWASP, cloud, DevSecOps, security champions, and building programs that help engineering teams move faster and safer. With more than 300 episodes, the show turns real-world experience into practical guidance for developers, architects, AppSec professionals, and security leaders.
Podcast website

Listen to The Application Security Podcast, Better With Money and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features