--- title: "Chris Romeo -- The Security Journey Story" url: https://appsecpodcast.com/chris-romeo-the-security-journey-story/ date: 2022-06-02 duration_seconds: 1633 guests: ["Chris Romeo"] topics: ["Threat Modeling", "Secure Development"] audio: https://www.buzzsprout.com/1730684/episodes/10726680-chris-romeo-the-security-journey-story.mp3 video: https://www.youtube.com/watch?v=e6ctYQMVKG8 transcript: true --- # Chris Romeo -- The Security Journey Story *June 2, 2022 · 27 min* with [Chris Romeo](https://appsecpodcast.com/guests/chris-romeo/) on [Threat Modeling](https://appsecpodcast.com/topics/threat-modeling/), [Secure Development](https://appsecpodcast.com/topics/secure-development/) [Audio](https://www.buzzsprout.com/1730684/episodes/10726680-chris-romeo-the-security-journey-story.mp3) · [Video](https://www.youtube.com/watch?v=e6ctYQMVKG8) ## Show notes In this episode of the Application Security Podcast, Chris Romeo walks through the origin story of Security Journey and shares some experiences taking a security startup from bootstrap to acquisition. Chris talks about how and why he started the company, what defining factors made Security Journey successful and why they're being acquired now. He ends by giving an overview of what to expect from Security Journey moving forward. We hope you enjoy this conversation with…Chris Romeo. You're about to listen to AppSec Podcast. When you're done with this, be sure to check out our other show, High Five. Hey, welcome folks to another episode of the Application Security Podcast. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey You're about to listen to AppSec Podcast. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Chris Romeo: → [Chris Romeo on LinkedIn](https://www.linkedin.com/in/planetlevel/) → [Press Release: HackEDU Acquires Security Journey](https://www.accesswire.com/702562/HackEDU-Acquires-Security-Journey-to-Provide-the-Most-Comprehensive-Application-Security-Training-Offering-Helping-Development-Teams-Deliver-Secure-Code-and-Protect-Data) Mentioned in this episode: → [Press Release: HackEDU Acquires Security Journey](https://www.accesswire.com/702562/HackEDU-Acquires-Security-Journey-to-Provide-the-Most-Comprehensive-Application-Security-Training-Offering-Helping-Development-Teams-Deliver-Secure-Code-and-Protect-Data) → [Joe's Blog Post](https://www.hackedu.com/blog/hackedu-acquires-security-journey-to-create-industry-leading-application-security-offering) → [Hackedu Acquires Security Journey](https://www.securityjourney.com/post/hackedu-acquires-security-journey) → [Cisco Security Ninja](https://blogs.cisco.com/security/our-commitment-to-cybersecurity-education-and-training) → [Threat Modeling Manifesto](https://www.threatmodelingmanifesto.org/) Chapters: 00:00 Meet Chris Romeo: The Security Journey Story 02:03 In those early days, yeah, I remember meeting and talking about 10:43 So, I start telling the story of what we had accomplished 14:38 I barely had $10 when I started this thing. But what 16:01 Yeah, that's a great history. A lot of things going on 19:39 Yeah, she was in those modules in the early days when 23:26 Excellent. And so, going forward, what do you see for the ## Transcript *5,332 words · assemblyai* **0:01 Chris Romeo:** You're about to listen to AppSec Podcast. When you're done with this, be sure to check out our other show, High Five. **0:08 Robert Hurlbut:** Hey, welcome folks to another episode of the Application Security Podcast. My name is Robert Hurlbut, and I'm joined here by my co-host Chris Romeo. Hey Chris. **0:19 Chris Romeo:** Hey Robert, Chris Romeo, CEO of Security Journey for the time being. **0:23 Robert Hurlbut:** Yes, and that's actually the special episode that we have today that we're going to talk about Security Journey. And I know that history has been interesting because it sort of coincided a bit with Application Security Podcast over the years. I remember very early on and, and getting opportunity to work with Chris on the podcast, but also opportunity just to see some of the early days of Security Journey. So we're going to be talking about that story and some exciting news that was recently brought to our attention. **1:00 Chris Romeo:** Yeah, I was thinking, Robert, about when we started. So, you and I met at the Converge conference in Detroit, and I think the year was— it couldn't have been 2015. **1:12 Robert Hurlbut:** It was 2016. **1:13 Chris Romeo:** 2016, yeah, because I was still at Cisco in 2015. So, it was 2016. I remember sitting there, and we were sitting in the back, and I think we even joked about it while we were sitting there at the conference, having just met each other, like, hey, we should do a podcast on application security. And then, like, 2 weeks later, we're just like, all right, let's go ahead and just start recording. recording something. And, you know, that's when Security Journey was in its infancy as well, was in that same time period. And so, you know, Security Journey has always been behind the Application Security Podcast. But, you know, and heck, people thought you worked at Security Journey for how many years in a row here, even though you've never worked here. **1:46 Robert Hurlbut:** No. **1:47 Chris Romeo:** But you've been a big supporter. So, you and I have been able to partner together on this podcast. But Security Journey has always been behind the scenes of the podcast, helping to, you know, cover the cost, defray the cost and everything, because, you know, podcasts aren't free. You know, they're almost free, but they're not completely free. **2:02 Robert Hurlbut:** Well, in those early days, yeah, I remember meeting and talking about this and trying to figure out, hey, what can we do? And getting started. I remember the early interviews back and forth. What are we doing? What are we working on? Where do we come from? And then starting to reach out. But also, so tell us a little bit about Security Journey and how did that get started? What was the— where'd that come from and the origin story? We always talk about the origin story of a number of our guests, but tell us about the origin story of Security Journey. **2:41 Chris Romeo:** Yeah, happy to share where Security Journey's come from. And part of the reason I wanted to share this story with our audience is, I know there are a lot of people out there that are thinking, hey, I want to start my own company someday. And so, I want to share this story to let people know there's more than one way to start a company. You don't necessarily have to go out to Silicon Valley and have someone write you a giant check and now we can go think up an idea. We approached Security Journey from a different perspective, more from the bootstrap side. But let me kind of take you back through a little bit of a history lesson about Security Journey. I love to tell this story, too, because— **3:15 Robert Hurlbut:** Yeah. **3:16 Chris Romeo:** You know, I guess it's my story. It's intertwined in how— where the company came from. But I've been involved in the world of security. I just passed my 25-year mark. So, I don't know. Does that mean I got to retire? Do I get a watch? I'm just— I'm waiting for the— Maybe a watch. Somebody send me a watch, please. It can be, you know, a $2.99 watch from Amazon, but I feel like I need a watch for my 25 years of hardship in the world of cybersecurity. So, you know, in my background, I've had a lot of different cybersecurity-related roles from, you know, trusted product evaluator from the government perspective, did incident response, traveling security consultant. I've had a chance to do a lot of different things. And, you know, coming out of kind of the first big job I ever had in my career, I had the opportunity to go and work at Cisco Systems. And so, when I think about Cisco, I'm so grateful to that company because it's really where I grew up in understanding how to approach security at scale. And build a program that would, you know, really reach a lot of different people. It's not— it's one thing to build a program that works for 20 developers. It's a whole other thing when you're thinking about 25,000 developers that are scattered all over the earth. And so in my time at Cisco, I had a chance to be part of Cisco's government product evaluation for a few years, and then I transitioned over to Cisco's secure development lifecycle team. And so, that team was focused on internal security. How do we help Cisco build more secure products using a, you know, secure development lifecycle? And I had a chance to roll out threat modeling and learn how to teach that from the side of kind of working directly with developers. And I had a chance to go to a conference. It was the Microsoft Secure Development Lifecycle Conference. And this is— I don't even know what year was this, maybe 2010, 20— I don't know, somewhere way back. back, 2010, 2011, somewhere in there. And I'm sitting there and I'm listening to Brad Arkin, who was the chief security officer of Adobe at the time. And Brad's doing this talk where he's describing this Adobe Security Ninja program that they had built using a belt-based approach, just like martial arts, of different levels of knowledge and letting people make a progression through them. And I'm sitting there and I'm sitting next to my boss at the time, from Cisco. And, you know, I'm somebody who studied martial arts for a lot of my life. And I'm like, I'm just, I'm digging this whole idea. I'm like, this is the coolest thing I've ever seen in my life. So, I kind of elbowed my boss who I was sitting next to and I said, Steve, you know, do you think we could do this at Cisco? And Steve's— I remember this moment like it was yesterday. He said, yes, you can. That was his direct answer. And so, I had permission at that point to go and build something at Cisco that modeled what Adobe had done. And so, but when I got back to work after that, I thought, huh, okay, I'm Cisco, you know, I work at Cisco. I can probably pay somebody to do this. We can just write a check. We have lots of money. We can write a check. We can bring in somebody from the outside to do this. And so I started looking across the industry and there just wasn't anything there that I was going to write my name on. And the reason for that is Cisco to this day is still a very engineering-positive kind of environment where engineering does drive a lot of decisions and a lot of things. And in those days, there was really no concept of mandatory, of telling people, hey, you have to do this training. And so I knew if I bought something that I really wasn't behind and then I asked the engineers to do it, they were just going to either not do it, maybe they'd throw me out of the building. You know, there could be a lot of different challenges that I'd be facing there. And so I made the decision to say, okay, let's build something, a program ourselves. And that's where the Cisco Security Ninja was born. And the idea behind the Cisco Security Ninja, looked at Adobe's program and said, what can we take from this that will help us as a baseline? What can we add that will be more Cisco's culture? And so we went down this road. I had a couple of people that were working with me just in slices of their time. They had full-time jobs during the day. They were just donating a little bit of their time to make this happen. And so we started building content. We get into a studio in Austin, Texas that we made out of a conference room. We literally put curtains up over It was the funniest story. We're trying to record our first ever Cisco Security Ninja video module. There's literally a guy mowing the lawn behind the window. So, we have to keep stopping because the lawnmower is going through and you can hear it in the background. But really, one of the things that I discovered in that moment is we sat down to record that content. We had slides in front of us and we had teleprompters. We had written out scripts. And so, I started to with another guest, we started to read off the teleprompters to each other. And after about 3 minutes, I'm like, okay, stop. All right, stop the cameras. And the producer's looking at me like, what's wrong? Everything's going great. I'm like, I'm bored and I'm sitting here recording this content. If I'm going to ask somebody to sit in their seat, a developer somewhere on earth, and consume this content and I'm bored making it, they're going to be bored out of their mind listening to me talk. So, I said, okay, push the teleprompters away, show us the slides, and we're just going to talk. We're just going to have a conversation back and forth as people that love security, that are passionate about it. We hit record, off we went. We're joking around a little bit. We're having fun. We're talking about these principles in security. We're using the slides to keep us from really going off the rails and, you know, talking for 10 hours about something like authentication. Like, we had to have a little bit of a guardrail there to keep us going. So, we go through this process at Cisco. We build this initial level, the Cisco Security White Belt. We go to the internal security conference. We kick this thing off. My director at the time, he says, okay, you've invested some time in this. What are you going to consider success for this? How many people are going to become White Belts? I said, if we get 250 people to go through this and earn their White Belt, we'll consider that a success. We launched. 3 months later, the 10,000th person earned their white belt inside of Cisco. This thing just caught— it was like wildfire inside the company. People were talking about it, and it wasn't mandatory. There was nobody that was saying, oh, we have to do this. It wasn't mandatory training. It was people were grabbing onto it. They were seeing the content and saying, hey, there's something valuable here. We're learning good lessons. But there was just a real movement inside the company. So, over the next couple of years, We added the Cisco Green Belt and built out a bunch of different topics there. We added Brown and Black Belt where people could do activities to prove that they had learned the knowledge and could then apply it into, you know, what they were doing in their job. And so then I had the chance to go out to RSA for the first time and to stand up and tell the Cisco Security Ninja story. And so I'm standing there for a whole other aside here, but This was my first big speaking event. Nobody mentioned how big the room was or the number of people that were going to be in the room. And so, I'm literally thinking, this is going to be a conference room, probably have 25 people around. It'll be a nice intimate conversation. I walk into this room and it's a banquet hall with 300 seats in it. And so, I get up there and I literally— I wish I could find the videos probably somewhere. I swear I stumbled through the first 60 seconds of it. And then, I started to tell the story and then I kind of got in the groove, but I probably had 200 people in the room. **10:41 Robert Hurlbut:** Wow. **10:42 Chris Romeo:** And so, I start telling the story of what we had accomplished at Cisco and I get to the end of this talk and there's a line of people going out the door. And so, I'm like, this is my first big conference. I'm like, I'm not really sure what's happening here. I don't know what's— so, I kind of go start talking to the first person. Half the people are asking me the question of, so, a tactical question like, why did you do it this way? What was the impact of this? And the other half were saying, where do I send my check? One person literally said, Is there a Cisco salesperson here that I can write my order with? And I laughed because I thought they were kidding. They were serious. They just wanted to buy this idea right on the spot. And so, Cisco was focused on a lot of other things and metal boxes and cloud services and all those types of things. And there really wasn't any way to move the Cisco Security Ninja to be something that could be offered to the rest of the world. And so, I left Cisco to start Security Journey and to take these same ideas that I'd had success with in training tens of thousands of developers inside of Cisco. I left all the stuff that I made there behind. But I came and said, hey, let me start and build a fresh version of this that can then be deployed for other different companies to take these same ideas. And so, we use the same principles of security conversation using belts. It's not like I invented belts at Cisco. It's not like Adobe invented belts. or Six Sigma. Martial arts invented belts long, long before any of us were walking on this earth. So, that's a concept that people can understand and get behind. And so, over the years, from a bootstrap perspective, I did consulting in the early days. I was helping folks build AppSec programs, build secure development lifecycles, doing all of that and taking the money that came from that and saying, We're going to funnel this into the product. And now, Robert, you got to come and be a part of our Security Journeys initial white belt. We built a studio space in the lobby of a video studio in downtown Raleigh. You got to come and be a part of that and be part of that first group of fun people that we had that came in to be on camera with us. So, you know, you're a little part of Security Journeys history. **12:52 Robert Hurlbut:** Yeah, no, I was just thinking about that. I remember that approach where we sat there And same thing, you showed slides and we just simply talked about it. And as opposed to reading something from a slide, we had conversations about application security and how they applied. And those slides helped us keep on track, but it was nice. It was just opportunity for folks who had a love and a passion for application security to talk about those topics. And it was fun, a lot of fun. I think I was on 2 sets. I remember going there twice and helping you out in the early days, but a lot of fun. I really enjoyed that. **13:30 Chris Romeo:** Yeah, going into that format. And so, after we built that white belt out, then we started working on our yellow belt. And here's a little bit of Security Journey history that most people are never going to know, but the studio, our first studio was on the 3rd floor of my house. So, we built a wood structure that had like, you know, old barn wood behind us, had a really nice look to it. We had a couple different cameras. We had a little bit of a, you know, we had some, a little bit of production value, but not a whole lot. And we were, you know, recording right from the 3rd floor of my house. And I just, it was so funny because one of my neighbors had a really loud truck. When he would go by, we'd always have to stop recording and I'd be like shaking my fist at this man driving by with his, you know, giant truck and, you know, making all kinds of noise. But, you know, that's kind of where our roots are from though, you know, and all of that to say like, Yeah. You can start a company that's bootstrapped. You don't have to have some giant amount of capital that says, hey, for me to start a company, I need $10 million. You don't need $10 million. **14:36 Robert Hurlbut:** I didn't have— **14:38 Chris Romeo:** I barely had $10 when I started this thing. But what you need is a good idea. You need, you need something that you stand behind, you think is going to, is going to work and is going to solve a customer's problem. And it doesn't hurt if you have some type of experience in that where you've seen the problem be solved. And so, one of the things that helped me in the early days of Security Journey as we were explaining kind of what this programmatic approach does and how you use the belts is I'd already done this before. So, it wasn't something where some people were like, oh, this sounds like a great theory, but we don't know if it's going to work. I could say, it's worked already. Now, I'm bringing the same idea to you that I've already used in other places and trained tens of thousands of individual people. And so, you know, all that to say, bootstrapping is possible in the world of startups. And so, you know, over the next number of years, we built out more content. We're up to, you know, 250+ individual modules now covering any topic you can imagine. I mean, we're focused on blockchain for this particular quarter just because we've done all the languages from a secure coding perspective. And now we're like, ah, people want to understand the security ramifications of blockchain. So, let's give some modules that talk about how blockchain security works. What are some of the threats? You know, those types of things along the way. So, I guess this was supposed to be an in-a-nutshell version of the Security Journey origin story, but I had a lot of history to share. **16:01 Robert Hurlbut:** Yeah, that's a great history. A lot of things going on in the last 6 years. And so, another reason why we're talking about Security Journey today is the recent news of the company being acquired. But before we dive into that, what were some of the— if you could share some of the defining factors that made Security Journey successful in these last 6 years? Yeah. **16:30 Chris Romeo:** So, I think, you know, one of the big defining factors for our approach is that I consider myself to be an application security practitioner first. You know, I was a CEO of the company for, you know, 6+ years, But first, at the end of the day, I like solving AppSec problems. I mean, you and I got to work on the Threat Modeling Manifesto together amongst with all of our other friends. There's too many on that list to name, but they're awesome people. Go look it up, Threat Modeling Manifesto. That's what I like to do. And so, I've taken that approach, and that's what our general approach is as a company as well is, you know, yes, we are application security trainers, application security educators. We want to help people learn the most important things about AppSec. But at the end of the day, we're passionate about AppSec, too. We're not just trying to sell somebody, hey, just buy our training, and then, you know, we don't really live and breathe it, but just take this training and your developers— like, developers can smell that like a mile away if people don't know what they're actually talking about. And so, that's really one of the defining factors of Security Journey is that I love AppSec. I love building AppSec programs, building SDLs, teaching threat modeling, teaching all these different principles. And so, this isn't for me just something I looked at and said, that's an interesting market that I think we could dominate. Like, this is my life. I love to do it. I love to talk about it. And so, I think that's really one of the big defining features. And then, the other thing is just, you know, being bootstrapped. It's just a different, you know, I call that a defining feature. I mean, Deb, Robert, who you know, my wife, The CFO, has been the CFO of Security Journey. And, you know, I owe our success greatly to her in this process because at the end of the day, I'm not a finance person. I'm not pouring over a spreadsheet looking at this. And I've told her a number of times and the rest of the team here, like, if it had been up to me and it was tied to my ability to manage financial transactions and things, we would have been sunk. back in 2016. We might have made it to 2017, probably not, because I like to solve AppSec problems and I get excited about that, but I don't get excited about, you know, general ledgers and moving numbers, and she does. And so, her— Deb being a co-founder with me of Security Journey was just a really powerful thing because, you know, she did— she enjoyed doing all those things, figuring out the financial systems, how do we invoice, how do we bill, all of those things you need to have to be a successful business. But if it would have been on me, I would have been in trouble. And so, that's one of the other defining, you know, find the right co-founder, the right co-founder who can really balance what you're doing as a company. And that's how you really get to success. Get people to really focus on what they're passionate about and they can help to drive wherever you want to go with the company. **19:17 Robert Hurlbut:** Oh, yeah, definitely. And I absolutely had the pleasure of meeting Deb early on and I remember all the work in the videos and everything, and she's right there all the time. And yeah, so absolutely agree with you. And kudos to Deb for all the work that she's done somewhat behind the scenes, but sometimes also in the front as well. **19:38 Chris Romeo:** Yeah, she was in those modules in the early days when, you know, once again, you're a bootstrap company. It's like everybody who, you know, is part of the company has to be on camera. I mean, Justin Redberg, who led sales for us for a long time, You know, he was the, he was the host on a lot of those early modules. And so, you know, he'd be going in to do a demo for somebody and it'd be, they'd be like, hey, wait, isn't that you on the— so we were so small, he'd be doing a demo and his picture would be up in the product and they'd be like, wait, is that you? And he'd be like, yeah, well, you know, kind of famous. You know, I'm, I'm in the, I'm in the videos as well. So yes, for some people it might have felt a little small time. For us, you know, bootstrapped, we leaned into, to the resources we had available and that's what we had to do to be successful. **20:21 Robert Hurlbut:** That's right. So let's now shift to the acquisition. Tell us about that and why be acquired now? **20:31 Chris Romeo:** Yeah, so Security Journey was acquired by HackEDU a couple of weeks ago, and it's a process that we've been going through since January. So, you know, whenever you see an acquisition, to all my startup friends out there who might be thinking about selling a company in the future, you see that acquisition and you're like, Oh, wow, that must have happened really quickly. No, it didn't happen. It took months and months behind the scenes of lawyers and accountants and due diligence processes and all of these things to really prove who you are as a company, what you've done. You know what you've done as a founder, but you have to go through this process that proves that everybody can look at your books and your financials. And once again, Deb saved the day here for me in that she had really clean books that there were no discrepancies in when you're looking through them. It is what it is. We're transparent in how we approach it. But yeah, so for us, this is the right time and it was the right time for Security Journey to join forces with HackEDU. And a lot of it comes down to we have 2 different philosophies coming together here, but 2 different philosophies that are so complementary. if you put them together. And so Security Journey has focused on that video-based content. You know, how do we pack the most important AppSec lessons into a short period of time for, you know, a particular coding language, whether it's Python or Ruby or Java or JavaScript or C#, C++, whatever? How do we pack the most important things a developer needs to know so that then they can go apply them? And we've done some things with experimentation where we, you know, we let the developer do some hands-on coding, but our real focus has been The platform, the programmatic approach, and then having the best content catalog on earth. Well, Hacky2u focused in on the hands-on pieces of what they call the sandbox and focusing on the experimentation and letting developers learn by experiencing and finding a vulnerability in a web application in, you know, one of 9 languages and then fixing that same vulnerability. And so for me, when this opportunity came in front of us, I was looking at it going, Wow, we've got the best content, they've got the best experiments, we have the programmatic approach. You put these 2 things together and now you've got a super training product that nobody in the industry is going to be able to match with what we're able to do from that content depth, that experimentation depth, putting together 2 awesome teams that were both achieving very highly in our own spaces. And so, that's really what was exciting for me and said, this is the right time to do this because You're bringing 2 entities together that are best of breed in their own space, putting them together into one, which is really going to help us to go to market and say, hey, we've got the best platform, program, content, and experiments that you can get in this marketplace. **23:26 Robert Hurlbut:** Excellent. And so, going forward, what do you see for the combined company in terms of— for customers, for our listeners, for viewers? What do we have to look forward to? **23:41 Chris Romeo:** I think putting these 2 companies together, I think you're going to see us being able to add more and more content together for more topics, more different— as new coding languages come out, we're going to be able to really create content for those things really fast so that people will have content for cutting-edge programming languages. You think about Go and what the the rise to popularity Go's had over the last couple of years. We added our Go content about 6 to 9 months ago from now, but we were still a little bit behind from where we wanted to be. You think about the OWASP Top 10. When the new OWASP Top 10 comes out, I want to be able to have the freshest content that's covering that, getting it to developers as quickly as possible. So, for the future, that's what we're going to be able to do from a content perspective is really invest more in having even better and more up-to-date content than we do today. And then taking that experimentation engine that HackEDU has and leaning into that, you know, they're doing things like creating DevSecOps experiments. So it's not just code-based stuff. It's, hey, let's, let's set up a build pipeline in this sandbox and let you integrate a SaaS tool and then work through a challenge to find some problems that the SaaS tool finds. Then you can fix them and you can run it again and prove that you got it to work. So, it's more than even just code. And so, I think, you know, with what we can do in this sandboxed environment, we're going to be able to do much more into the future with different types of experiments that give that real hands-on experience so that when a developer is facing a challenge, they won't be dealing with it the first time in their own environment. They'll be like, oh, I did something. I integrated a SaaS tool, you know, in the training platform that I use. I know how to do that. Developers are smart people. They'll figure out the 10% that's not in the experiment. they'll figure that out and integrate it into their own environment anyway. So, that's really what I'm excited about for the future is just being able to put these 2 things together and then, you know, just continue to pump out the best content, whether that's video, whether that's experiment, that anybody's seen in the industry. **25:48 Robert Hurlbut:** Oh, really exciting news. It's really been great to talk with you about this, Chris. I know I wished you congratulations when I heard the news. Obviously, as we talked about, I've never been an employee of the company, but I've always been excited to see what's going on with Security Journey, being in the early days and see what's been happening and very excited for you and your team. And, you know, thanks again. Glad we could talk about this today and share your journey with others and experiences. **26:21 Chris Romeo:** Yeah, thanks, Robert. And just so the listeners know, we're not going anywhere. The Application Security Podcast lives on. We've got a long list of people to interview and get those those details out to our audience here. And so, we will continue forward with lots of exciting interviews in the coming months with lots of people you've probably never heard of in the world of AppSec, but we're going to bring them to your attention. So, thanks, Robert. Thanks for interviewing me through this process. Thanks for listening to the Application Security Podcast. You'll find the show on Twitter @AppSecPodcast and on the web at www.securityjourney.com/resources/podcast. You can also find Chris on Twitter @edgeroute and Robert @roberthurlbut. Remember, with application security, there are many paths, but only one destination. --- Source: https://appsecpodcast.com/chris-romeo-the-security-journey-story/