--- title: "Devin Rudnicki -- Expanding AppSec" url: https://appsecpodcast.com/devin-rudnicki-expanding-appsec/ date: 2024-05-14 duration_seconds: 2157 season: 11 episode: 11 guests: ["Devin Rudnicki"] topics: ["Building an AppSec Program", "Security Testing", "Careers in AppSec"] audio: https://www.buzzsprout.com/1730684/episodes/15041414-devin-rudnicki-expanding-appsec.mp3 video: https://www.youtube.com/watch?v=-C20L2LYuvQ transcript: true --- # Devin Rudnicki -- Expanding AppSec *May 14, 2024 · 36 min · Season 11, episode 11* with [Devin Rudnicki](https://appsecpodcast.com/guests/devin-rudnicki/) on [Building an AppSec Program](https://appsecpodcast.com/topics/appsec-programs/), [Security Testing](https://appsecpodcast.com/topics/security-testing/), [Careers in AppSec](https://appsecpodcast.com/topics/careers/) [Audio](https://www.buzzsprout.com/1730684/episodes/15041414-devin-rudnicki-expanding-appsec.mp3) · [Video](https://www.youtube.com/watch?v=-C20L2LYuvQ) ## Show notes Devon Rudnicki, the Chief Information Security Officer at Fitch Group, shares her journey of developing an application security program from scratch and advancing to the CISO role. She emphasizes the importance of collaboration, understanding the organization's business, and using metrics to drive positive change in the security program. Devin Rudnicki, the Chief Information Security Officer at Fitch Group, developed an application security program and advanced to the CISO role after years in security governance. She holds a BS in mathematics from DePaul University and multiple certifications, including CISSP, GSTRT, GSEC, and GCSA. Outside work, she enjoys group fitness, global travel, and mentoring in cybersecurity. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey Security Journey is an enterprise-class solution with lessons that are built on learning science principles to deliver long-term measurable results. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Devin Rudnicki: → [Alice and Bob Learn Application Security](https://www.wiley.com/en-us/Alice+and+Bob+Learn+Application+Security-p-9781119687405) → [RSA Conference](https://www.rsaconference.com/) Mentioned in this episode: → [Alice and Bob Learn Application Security](https://www.wiley.com/en-us/Alice+and+Bob+Learn+Application+Security-p-9781119687405) → [RSA Conference](https://www.rsaconference.com/) → [Black Hat](https://www.blackhat.com/) → [Walter Isaacson](https://www.simonandschuster.com/authors/Walter-Isaacson/697650) Chapters: 00:00 Meet Devin Rudnicki: Expanding AppSec 03:05 Very cool. So the internship, security and governance, does that lead 05:03 Is that What's that approval look like as far as, is 07:28 What's the first thing that you focus on with this program 10:17 You're kind of, you're learning a little bit about the personalities 11:41 Yes, I think that's an important tactical thing that we can 14:54 Yeah. Okay. So when we, if we break the program, then 17:54 Okay. So, that's the vulnerability management side. How about developer education 20:23 In the past, I would say no to that question, and 21:18 That's, you know, you can minimize. But yeah, I mean, pen 24:49 Tracking the work. What metrics and KPIs did you use to 27:05 Yeah, and I had a similar situation in my previous time 30:03 Devin, we have 3 questions that we typically ask in the 32:59 The gene splicing therapy. We'll find it and put it in ## Transcript *6,167 words · assemblyai* **0:01 Chris Romeo:** Devin Rudnicki, the Chief Information Security Officer at Fitch Group, developed an application security program and advanced to the CISO role after years in security governance. She holds a BS in mathematics from DePaul University and multiple certifications, including CISSP, GSTRT, GSEC, and GCSA. Outside work, she enjoys group fitness, global travel, and mentoring in cybersecurity. Devin joins us to explain how to build an AppSec program from scratch, what to do with that new program, how to quickly expand the program and tools, and the metrics and KPIs that you need to demonstrate success. **0:44 Devin Rudnicki:** The Application Security Podcast is brought to you by Security Journey. Security Journey is an enterprise-class solution with lessons that are built on learning science principles to deliver long-term measurable results. Learn more at securityjourney.com. **0:59 Chris Romeo:** Hey folks, welcome to another episode of the Application Security Podcast. This is Chris Romeo, CEO of DaVinci, general partner at Curve Ventures, and also my most honorable, I think, title, co-host of the Application Security Podcast with Robert Hurlbut. Hey, Robert. **1:29 Robert Hurlbut:** Hey, Chris. Yeah, Robert Hurlbut, Principal Application Security Architect and Threat Modeling Lead at Acquia, and excited to be here again for another Application Security Podcast. **1:40 Chris Romeo:** Yeah, we're going to have fun with this one because we're getting to talk to a practitioner who's built a program from the ground up. And these are always the most fascinating stories for me because I always learn something about that I can apply next time I get a chance to either build a program or help somebody build a program. So without further ado, we'd like to introduce Devin Rudnicki. And Devin, we always like to jump right into people's security origin stories, like no time to warm up. It's like dive right in. Tell us that story. **2:09 Devin Rudnicki:** Yeah, well, first of all, thank you so much for having me today. I'm really excited to be here. So my security origin story is really interesting, actually. or maybe not so interesting. So when I was in college, I was a sophomore and I was looking for an internship. And at that point, at that age, I really just wanted to get an internship, to be completely honest. So I was walking around the career fair at my college, and then it just turned out that there was a company there that wanted an IT/security governance intern. So I just really impressed the hiring manager there and was able to get that internship. And that really started my entire journey in security. And I'm so extremely grateful that they decided to take that chance on me because I didn't have the education or the background necessarily coming from a mathematics degree. So then it was just a huge focal point for starting in my security journey. **3:05 Chris Romeo:** Very cool. So the internship, security and governance, does that lead you to the first job? at that company or did you end up landing somewhere else? I know a lot of times internships kind of lead, at least as the employer, you're always trying to get interns to join the company at the end of their college career. How'd that work out for you? **3:28 Devin Rudnicki:** Yeah, so it's interesting. I actually ended up having my first job at EY, Ernst Young, because I actually got to know one of the managers who was working with us at that time and then got recruited into that program, did the internship with EY, and then went on to go full-time in EY. So that was more an IT risk advisor role. **3:49 Chris Romeo:** Okay. So, you probably got a chance to see a lot of different situations, organizations as a consultant than being in just a single organization. So, did you get to kind of sample a number of different places to see how people were doing security? **4:06 Devin Rudnicki:** So, the funny enough story about that though is, yeah, I actually only spent about 7 months in consulting before I got lured right back into industry, actually back at that first company that I interned with. **4:19 Chris Romeo:** Oh, so it came full circle. **4:20 Devin Rudnicki:** So I went into cybersecurity governance. It was a little boomerang action there. **4:24 Chris Romeo:** Okay, nice. **4:25 Robert Hurlbut:** So that works. And cool. So Devin, when building an AppSec program from scratch, just diving in here to our topic today, how did you get the charter to build the program? **4:40 Devin Rudnicki:** Yeah. So it was nice because I came into the organization being hired to do that exact thing. So my manager at the time, the CISO, actually had gone before the board and everything to go ahead and get approval to build out the application security program. So that was kind of nice. I already had that, that approval and, you know, designation from when I first started at the company. **5:02 Chris Romeo:** And what is that What's that approval look like as far as, is it headcount? Is it budget? What's kind of being set up that you're going to be able to go execute on now? **5:16 Devin Rudnicki:** Yes, exactly. So, it was both getting the headcount and the budget for the tools and consulting services to start up the program. So, it was really nice to have both of those things already secured when I started. **5:33 Robert Hurlbut:** Okay. **5:33 Chris Romeo:** And so you were the first AppSec hire then? First person in the door? **5:37 Devin Rudnicki:** Yes, I was the first application security director at the company. So that was nice to be able to just start from scratch. The company already had some AppSec practices in place, which was great to kind of have that first initial awareness around the company. But that really just gave me the free license to build. **5:57 Chris Romeo:** Yeah, that's such a fun experience to have that greenfield. I can do whatever I want within reason because it's a new playground almost. And, you know, sometimes people come into existing companies and there's a program and you have to try to fit your philosophy into it. In this case, you've got to set the philosophy for what the program is going to do. **6:18 Devin Rudnicki:** Yeah, no, that was really nice. And so, actually, at the last company that I'd been at before I took on this role to build the application security program from scratch, I was managing the application security team, so I got to learn a lot of good practices about AppSec and be able to really take what worked and also what didn't work well, you know, to build— actually building the program on my own. **6:43 Chris Romeo:** Yeah, it's always— it seems like we learn so much from what doesn't work. In my career, when I look back, it's like when things are successful, yes, you learn something and everybody's excited, but when things just completely fall apart, You get a perspective. So the next time when you do it, you're like, I can tell you what we're not doing. We're not doing it this way because that caused me a lot of pain and it just didn't work and everybody hated it at the end of the day. So I'm always, I always love to hear what some of those challenges are, but we'll get into that as we get, we get a little further. So you got this, you know, you're AppSec director, you're in this, this new, new opportunity. You've got budget, you've got headcount allocated. **7:26 Robert Hurlbut:** Yeah. **7:27 Chris Romeo:** What's the first thing that you focus on with this program? **7:31 Devin Rudnicki:** So the very first thing that I did, well, actually, there's 2 things really. First off, I built a roadmap that I could use to socialize my vision for the program and communicate with the key stakeholders what would be needed from them. **7:47 Chris Romeo:** Okay. **7:47 Devin Rudnicki:** So that's the second thing is really the collaboration piece. And that's really what I think made the AppSec program build-out so successful, it was taking the time to do a roadshow, essentially, with all the key stakeholders, showing them the roadmap for the program, and then explaining why it's so important and how it would actually benefit each of them. **8:09 Chris Romeo:** So, when you're building this roadmap, what's your guidebook? Like, what are you using to To know what to even put on that roadmap for somebody who's, you know, I always like to think we've got some people listening to this podcast that are going to be trying to do the same thing you're doing. And so that's why I'm always diving deeper because I'm like imagining somebody listening to this going, I could do what Devin did. Oh, Devin had a, she said roadmap. Oh yeah. This is what it looks like. So, so what, where, where did you go to source the pieces of that roadmap? **8:42 Devin Rudnicki:** So to be honest, a lot of it did come from my prior experience, which I know for someone starting out, it might be difficult if you don't have that. But then I think it's also bringing it back to the people, process, and technology pieces, right? So thinking about what do you need from each of those 3 aspects to roll out the program. And then finally, I would say it's— you can find a lot of things by Googling. I'm fully guilty of that. I Google all the time. There's some really great resources out there and some great books. Tanya Janka's application security book was really helpful. for just knowing the key components of what you need for a program. **9:20 Chris Romeo:** Yeah. And then, on the collaboration side, what would you say, what would you tell somebody who's just getting started with this? And maybe they're a little nervous about, I don't really want to talk about, talk to executive leaders. They seem like they are so important inside the company. What would be your advice for that person, like, based on your experience? Like, what would you advise them? How would you advise them? What can they do to be successful in those conversations? **9:50 Devin Rudnicki:** Yeah, so I think the biggest thing is really reading the room or knowing your audience, right? So do some background, figure out what the people do at the company, and what they think about what they might be most concerned with. And then be able to really tailor your conversation to meet not only your needs, obviously, but also their needs. And I think that's, that's the biggest thing, really. Okay. **10:17 Chris Romeo:** So, you're kind of, you're learning a little bit about the personalities then of the people that you're going to be interacting with and some of their background and trying to profile them a little bit as far as what to expect then, right? Just so you're, it just helps you to be prepared, I guess, as you're going into those conversations. **10:36 Devin Rudnicki:** Yeah. Yeah. And I think the other thing too is, like I kind of mentioned before, putting together a little roadshow presentation. with your roadmap and then really rehearsing and practicing that and feeling confident in that is also a really key thing to making your message come across clearly and also, you know, really powerfully, right, to each of those. **10:58 Chris Romeo:** So how many slides are you putting in that roadshow presentation? **11:02 Devin Rudnicki:** I believe I had about 5 or 6. And so the first one was really talking about you need to set the scene, right? You know, what is application security? Why is it so important? I think I also then put in a slide with some statistics from the industry just about application security risk, just to explain why it's so important. **11:27 Chris Romeo:** Okay. **11:27 Devin Rudnicki:** And then I think I went into the actual roadmap with a nice little PowerPoint slide with all the colorful bars and, you know, on a little timeline there. And then talked about the benefits of the program. **11:40 Chris Romeo:** Yes, I think that's an important tactical thing that we can take away right now just from where we are in the story, right? You really, you don't want to go into that conversation with 50 slides because that room doesn't have the attention span of 50 slides. They have the attention span of 5 to 6 slides. And some people might get mad at me for saying that. I don't care. It's the truth. I'm in that category a lot of times now. And like, if you come in with me for 50 slides, I'm gonna be like, I'm sorry, but I'm gonna play on my phone now 'cause I don't have an attention span for that. But 5 slides, 5 to 6 slides where you're, I can obviously see you've got a path, you can keep me engaged in the conversation. Like, I think that's gonna be, that's a key tactic that you use there was to just minimize. And then, so what did the conversation look like? Like, did, were people, was there a lot of, was there a lot of conversation from different leaders in the company kind of supporting you in what you were doing? **12:38 Devin Rudnicki:** Yeah. Yes. Yes. So essentially the conversation would really look like introducing myself, learning about the other person or the other group, right? Because it's important for you to also get that kind of information for later use, right? And help you better understand about how you can potentially help that person in that group in the future. And then it would be getting into more of, here's the vision and the roadmap that I have for the program, you know, why it's so important How did you expand the application security program and tools to the firm? Yeah, so that's, that's a great question. So we actually came up with a standardized approach. We called it the Application Security Onboarding Program. And so that was really devising, working with all the technical teams to come up with a nice template for implementing the tools within our continuous integration, continuous deployment pipelines. as well as then also teaching people the processes right around application security. So while we roll out the tools, we need to also make sure that we have the processes in place to manage the tools and actually do something about the findings that are coming out of those tools. **13:58 Chris Romeo:** So when you, when you were assembling your, your tool suite, did you— was there any type of prioritization? you were using as far as what categories of tools were most important to get implemented first? Or did you just have the ability to say, we're going to put out a holistic suite of tools all at one time? What— how did that work out for you? **14:23 Devin Rudnicki:** Yeah, great question. So we definitely focused on getting a static scanner in place first, along with dynamic scanning, just because those are the, you know, the core tenets, I think, of application security tools. And then later, we did expand the program to include software proper composition analysis scanning tool. Thank everyone, you know, coming out of Log4j that happened now, I guess, a few years ago almost at this point. Really, you know, really the keenness of having the SCA tools. **14:53 Chris Romeo:** Yeah. Okay. So when we, if we break the program, then as you're moving forward and you're continuing to work on the program, You know, we talked about how you had the roadmap that led to the roadshow, to the collaboration. You know, you focused on SAST and DAST initially and then got to SCA. I heard somebody refer to that as SCA recently. And I was like, when did we start saying SCA? Like, that doesn't— I think of SCA music, which is like, I don't know, I don't even know how to describe that. That's the only thing that comes to mind when someone says SCA. **15:34 Devin Rudnicki:** Yeah. **15:36 Chris Romeo:** So, what are the, I guess, what are the kind of other categories then once you get past, in building out your program here, once you get past that initial buy-in from the executive leadership team, you've got some tools that are starting to come into play. If you had to kind of bucketize the other things that your program is doing, what are some of those other buckets look like? **16:02 Devin Rudnicki:** Yeah. So, the other buckets would— well, the next one would definitely be the vulnerability management piece. So, I did have to come up with an entire proposal for that and really lay it out, not only for the technical people, right, but also the product teams and more on the business side of the house, as well as the Scrum Masters. They really had to understand the deep intricacies of all of the workflows within the ticketing system. And really, you know, to know what's expected of them when a new ticket for a vulnerability comes into their backlog, right? So, that's the vulnerability management piece. And then also developer education is another big piece and penetration testing. **16:43 Chris Romeo:** Okay. So, just to unpack these in a little more depth, vulnerability management, is this something that in your philosophy of AppSec programs, is this something that you're pushing to the individual developers? Is it something that you've got staff on your team that are, that are managing that? Like, how does, how does your philosophy play out with the program? **17:09 Devin Rudnicki:** So we really wanted to make sure that as much of the process was automated as possible. Okay, so we did actually invest in a tool to be able to automatically create, manage, and close the tickets based on the, the tool findings. Or sorry, the tool status of each of those findings. So that's really, really helpful. And then also, we had to really focus on making sure that, again, the Scrum Masters knew what was expected. So, you know, during their backlog planning, they need to be taking a look at all of the vulnerabilities that are appearing in that backlog, and then making sure that they're slotted for an upcoming sprint, you know, within accordance of our SLAs for vulnerabilities. **17:54 Chris Romeo:** Okay. So, that's the vulnerability management side. How about developer education? Is this something that you put— did that become like an internal project? That's something that you had resources on your team focused on delivering that? Did you go outside to try to solve that problem? What were some of your strategies there for success? **18:16 Devin Rudnicki:** Yeah. So, we did get the help of a tool. I think you're probably pretty familiar with that security journey tool. **18:24 Chris Romeo:** I've heard of that one before. **18:26 Devin Rudnicki:** Great, great, you know, great tool. **18:27 Chris Romeo:** I did not know that in advance. I did not know that when I asked the question. No, but I'm glad to hear it. Yeah. **18:32 Devin Rudnicki:** Yeah, that was really helpful because I think it's so key for developers to be able to not only get those chats essentially right, the video pieces, but then also the hands-on keyboard training. So that was really key. And we actually had developers do a proofs of concept with different programs and to tell us which ones they really liked the most. And Security Journey definitely won out. **18:58 Chris Romeo:** Nice. Glad to hear it. So, you mentioned developer education, vulnerability management. What was the third one? **19:07 Devin Rudnicki:** Penetration testing. **19:09 Chris Romeo:** Penetration testing. How could I forget? Because I'm such an anti-pen testing person. That's why I couldn't forget. Not anti-pen testing. I think people pen test at the wrong time. They put too much effort onto it. But our audience has heard me rant about that far too too many times, so I'll save— they'll have to go back to a previous episode for that rant. But what's your— what's your philosophy about pen testing? How does that fit into your AppSec program? Once again, are you going outside? Do you have testers on the team? What do you see as the best practice here? **19:38 Devin Rudnicki:** To me, I think it's really helpful to have both. Both have external as well as internal because that enables you to have a variety of individuals looking at the application right at different times. And I think you also have to then adjust your penetration testing program to what the business wants and needs and has the appetite for. Right. I think we've all probably seen on a million security questionnaires, do you annually penetration test your applications? Right. So I think we definitely have, you know, some requirements in those respects. But also it's about trying to get— make sure that you're actually really assessing the security risk of your, of your applications. Right. **20:23 Chris Romeo:** In the past, I would say no to that question, and then I would have to get on a call to talk about the answers, and the security team would be like, how can you not do pen testing? I'm like, well, we built an application that runs in a container that has a minimal number of— the attack surface is minimized to the bare bones of what it needs. We have a runtime application self-protection solution running inside of it, so we've got We're protected from the inside out and there's just nothing there from an interface perspective. We stripped it down. And they'd be like, oh, okay. So I'm like, you can pen test it if you want. There's really not much to find. It's because it's been minimized to the point on purpose. It's been designed in that way. And that gap got me around doing pen testing for a good period of time. But it was an architecture play. And yeah, it was. **21:17 Devin Rudnicki:** It's— **21:18 Chris Romeo:** but that's, you know, you can minimize. But yeah, I mean, pen testing does have its— it does. I mean, I'm not anti-pen testing. the way. I just think we focus on it too much as an industry, like too many university students. And the audience has heard me say this before, but I'll say it again. You ask a university student that's studying cybersecurity, like, what do you want to do when you graduate? Oh, I want to break stuff. I want to break into things. I want to do that. I'm like, you know, we have a lot more need for people to build secure things. Like if you learn how to build secure things, you will never be unemployed for the next 30 to 40 years. That's my prediction because think about all the people we know in the AppSec community. Nobody's out of work. I mean, like everybody's, most of the people are, they move from one company to the next to launch the next program. Like Devin, like what you did in your career, you go to a new place because you want to build something from scratch and see how you can attach all the pieces together and make it work. And so that's where, but yeah, I just want to see more people focus on building. securely as their, their life goal there. **22:21 Devin Rudnicki:** Yeah, no, I think it's so important. And you're totally right. I see that a lot. A lot of individuals really want to move into red team or penetration testing just because it is very attractive right from the outset. I think that the whole concept just really appeals to people, and that's what a lot of people hear on the news. So that's something that they just are really interested in. But I totally agree that it's always going to be the defenders that we need. Yeah. **22:49 Chris Romeo:** And then when you— people don't realize that the life of a pentester is not as glamorous as it sounds from the outside. There is a certain amount of grind that goes into being a good pentester. It's having the knowledge, it's having the skills, which, you know, my knowledge and skills in those areas have drifted away from me decades ago. But it was, it was also a grind sometimes because there are times where you're like, I just can't, there's just doesn't appear to be anything here, but I can't send a report that says your system was better than us at defending. And so you got to keep going, you got to find a way. And, you know, I grew up in the era when security was so bad that you could pen test something. And if you didn't find a way in within an hour or two, You were probably really shaking your head going, these folks are doing something right. Because in those days, there were so many Microsoft vulns and stuff that were exposed in external services, which led to the worm culture of, you know, the late '90s and early 2000s that Robert remembers that too, because he was around at the same time. He's from the same vintage as I was. But, you know, that worm culture, what I mean is Microsoft had vulnerabilities, people wrote worms for them, and they just went through and compromised machine after machine. And then— **24:09 Devin Rudnicki:** Yeah. **24:10 Chris Romeo:** Once the machine was compromised, it would start looking for more machines to compromise. That was the state of security, which made pen testing a whole lot easier in those days. But now it is something that can be more of a grind. It can be a tough assignment because you got to find some way in. And some people are just more built for that. Like, I find I'm not. That's not my— that's not how I'm gifted in being able to focus and do that. I can— I mean, I used to do it when I had to, but it's not Not something that, that I find myself very good at anymore. But that's not why I have the opinion that I do, just by the way. All right, Robert, what else you got here for Devin? **24:49 Robert Hurlbut:** Well, let's talk about tracking the work. What metrics and KPIs did you use to track and show value? And also, how did executive leadership receive that value? **25:04 Devin Rudnicki:** Great question. I think this is a really hot topic and always has been in security, right? How do you show the return on investment? I think that's a really difficult question, honestly, and I've seen a lot of other people grapple with it as well because it also goes back to the whole quantification of cyber risk, right? That whole, that whole debate. But for metrics and KPIs for the application security program, We did try to show the value as far as showing the vulnerability closure rates and showing the trends and vulnerabilities from quarter to quarter or month to month, depending on what level of reporting you were doing. And then we also had some metrics around our security training, developer training, and how many— what percentage of the developers are taking the training and that sort of thing. **25:56 Chris Romeo:** Okay. And then what was the— how did other leaders receive that? Did they believe the metrics and did those metrics cause change? Did you get any pushback from the executive leadership team as far as how they received that data? **26:10 Devin Rudnicki:** Yes, I think it's really interesting because I think that I really am a proponent of using kind of the scorecard method and trying to gamify things. in a sense. So, if you really show the different business leaders across the stack of what their teams' or products' vulnerabilities are, then I think that that can really help drive vulnerability remediation because they don't want to be the product that has all the vulnerabilities compared to the other products. **26:39 Chris Romeo:** And so, do you recommend showing that type of a scorecard? Is that something that everybody in the company can see? **26:49 Devin Rudnicki:** That's a good question. So we actually just really provided them to the different business leads and technical owners. We did not publish them on our company intranet page or anything like that. But I, you know, I wouldn't be opposed to that. I think that's a cool idea. **27:05 Chris Romeo:** Yeah, and I had a similar situation in my previous time at Cisco. We used that strategy of Metrics, pitting executives against each other using metrics as a driver, because nobody wants to be at the bottom of the leaderboard. And if they see themselves at the bottom of the leaderboard, they immediately call their operations director and say, why am I at the bottom of the leaderboard? I don't care what leaderboard it is. I'm not ever at the bottom of it. And then fix it. And then somebody would go and all of a sudden that team would start to rise up the leaderboard because there was that That perception that we're the worst out of all the people, and we didn't publish it like you'd like to your point, Devin. We didn't publish it. It's not something we published where everybody in the company was looking at it, but it was published at certain levels of leadership where the other leaders could see where they stacked against each other, and it did it did cause some positive change. So that was good. Um, so then CISO, so you. Let me just recap for our audience here. You come to this company, you start the AppSec program, you put all these things in place, you build out the team, and then recently you've become the CISO of the same— in the same organization? You've able— or is it a different company? **28:22 Devin Rudnicki:** Yes, the same organization. Okay. **28:25 Chris Romeo:** So you're able to grow the program and then go and kind of continue to grow your career into the CISO chair. As a result of the success that you had driving the AppSec program through. **28:36 Devin Rudnicki:** Yes. Yes. And I really think it all goes back to what I mentioned at the beginning of the podcast. It's all about the collaboration piece. So I think it's really about getting to know your stakeholders and understanding their needs and how can you best meet their needs and the business's needs. And that's, that's really the key. **28:55 Chris Romeo:** So how has your relationship with those other leaders changed now? Since you've kind of risen up to, from somebody who was kind of a level below them in the organizational structure to somebody who's now kind of in that, in the conversations with them, how has that changed the way you approach influencing them and your general security approach? **29:22 Devin Rudnicki:** Yeah, so I've really just tried to take a lot of the things that I learned with building the application security program and all the collaboration there and just tried to drive that forward across the entire CISO organization, just to really help enable better transparency and collaboration amongst ourselves and our stakeholders. **29:42 Chris Romeo:** Okay. Very cool. Well, Robert, I think we've reached that time of the lightning round. This is Robert's time to shine. This is his scene in, or act in the play called the Application Security Podcast. So, Robert, take it away. **30:02 Robert Hurlbut:** Okay, Devin, we have 3 questions that we typically ask in the lightning round. The first one is more of a controversial take. So, what's your most controversial opinion on application security, and why do you hold this view? **30:15 Devin Rudnicki:** I don't have one. **30:17 Robert Hurlbut:** That's pretty controversial. **30:22 Chris Romeo:** Yes, the most controversial answer we've ever had. And so, that will cause conference talks to be written. Did you hear this interview? Devin said there was nothing controversial in AppSec. I will show the world that there is. **30:35 Devin Rudnicki:** Maybe not. Can't wait for those. Excellent. **30:39 Robert Hurlbut:** All right, the next one is, uh, what would it say if you could display a single message on a billboard at the RSA or Black Hat conference? **30:47 Devin Rudnicki:** Collaboration is key. **30:50 Robert Hurlbut:** Love it. **30:52 Chris Romeo:** Oh, I like that. Yeah, that's cool. **30:53 Robert Hurlbut:** And, uh, the final one is, um, what's your top book recommendation and why do you find it valuable? And that could be any book, really. **31:03 Devin Rudnicki:** So I'll actually just choose— there's too many books to count that I've read in my life. So I'll pick one from somewhat recently. I actually read the new biography of Elon Musk recently. And that book was so valuable to me. So being a risk management professional, right, in this role, and then comparing it to what— how Elon Musk thinks about business and thinks about risk-taking was just really eye-opening to me. And he's truly brilliant. I mean, it was awesome to just kind of get more insight into how he thinks about things and how he addresses issues. Not going to say all that's all good necessarily, but I just think that it was an excellent book and I would highly recommend reading it if you haven't already. **31:50 Chris Romeo:** That is a good one. I've read that one as well, and some of his management tactics Are just like the thing that caught me, a number of things in there of his tactics caught me. I thought the book was brilliant. Like the idea that you can just add up to 10% more stuff of like parts into something you build because we're going to end up needing to cut stuff anyway. And so, just over-engineer it and we'll cut it further down the process. That being a mindset of thinking, like nobody thinks like that. Nobody thinks about, I'm just going to throw extra stuff to make it to try to make the solution work and then we'll figure out how to slice other things out further down the road. Yeah, I love that. That was a great book. That's Walter Isaacson, right? The author of that who's also written— I mean, I find everything by Isaacson is just incredible. He did others that I read. The Steve Jobs biography is very good. And then he also did one recently. I can't remember the lady's name. Jennifer, the CRISPR lady. **32:56 Devin Rudnicki:** Jennifer Doudna. **32:58 Chris Romeo:** The gene splicing therapy. We'll find it and put it in the shownotes. But, that was the story of gene splicing and how that all works. I'm not a biology person, so I don't have that depth. But, the way Isaacson explains these things, I could understand the biology behind it at a simple level of what they're doing and whatnot and the story behind how they're curing diseases with this CRISPR machine. It's just fascinating. But yeah, that's a good recommended reading section. And, thank thank you for pointing out that Isaacson book because that's one that I love as well. So, Devin, how about a key takeaway or a call to action? Do you want to give our audience homework? I don't know how, like I said before, I don't know how they'll turn it into you, but what do you want to leave our audience with here? **33:49 Devin Rudnicki:** Yeah. So, I don't think I actually really talked about this enough in the beginning of the podcast or anything, But I really think that you should take the time to go and learn your organization's business. You really need to understand how your organization makes money, and you need to understand what can you do as a security leader to help enable that. **34:13 Chris Romeo:** Yeah, that's, that is really good advice because if you don't understand where the money's coming from, it's tough to make good decisions. And I find when I understand where the money's coming from, it changes my perspective on decisions because risk has to be filtered through the lens of how we make money. Well, if we just invest all of this money in this, if you invest all that money in that, we'll be out of business. So then this doesn't really matter, the whole conversation, right? It's like we can't spend all the money on the security controls because we need to make some profit because we're a company that sells things to— that's how we run a business, right? So yeah, that's really good. Good advice. Well, Devin, thank you so much for sharing your story here, and hopefully it inspires some folks that are out there with the opportunity to do what you did and build their own programs, or maybe they're refreshing a program. Hopefully they can take some of that wisdom and apply it. And also for those folks that have that desire to get to the CISO chair, this can inspire them as well that you can begin your journey in something that's not AppSec. Get into AppSec, build a program, and you can use that to grow your career throughout the organization as they watch you making stuff happen, which I know that's what you did because you didn't get to the CISO chair unless you were making stuff happen. So hopefully that'll inspire some folks out there that think that's a path for them. So thanks for sharing that story with us. **35:40 Devin Rudnicki:** No, thank you so much for having me. And yes, everyone, please go out there and just Just do hard work, right? Communicate, collaborate, and you'll meet great success. **35:51 Chris Romeo:** Very good. --- Source: https://appsecpodcast.com/devin-rudnicki-expanding-appsec/