Vulnerability Jail and the AI-Era AppSec Engineer
Three years ago, Jeevan Singh mapped out what an application security engineer needed to know. AI has rewritten the job since.
Listen to the episode310 episodes, going back to 2016.
Three years ago, Jeevan Singh mapped out what an application security engineer needed to know. AI has rewritten the job since.
Listen to the episodeMost fault trees get built on gut feeling. Petra Vukmirovic did something rarer: she borrowed the actual math from aviation and nuclear-plant safety engineering and pointed it at AI agents.
Listen to the episodeMost security champions programs don't fail on tooling — they fail on people. Lisi Hocke spent three years as a champion before moving fully into product…
Listen to the episodeIs traditional DAST finally dead? James Berthoty came back to settle the argument that his last episode started.
Listen to the episodeAI security has no shortage of standards — the problem is turning them into something a team can actually use.
Listen to the episodeYou don't have to let AI do the thinking for you. In this episode, Vikram Narayan shares why the smartest teams use AI as an accelerant — not a replacement…
Listen to the episodeAI is moving AppSec's control point out of CI and directly into the coding agent—but what happens when the model writing the code is also expected to secure it?
Listen to the episodeWhy do broken access control and injection still dominate the OWASP Top 10 despite years of mature tooling?
Listen to the episodeWhen every employee can generate working software, who owns the risk? Michael Burch, VP of AI Enablement and Acceleration at Security Journey, explains how…
Listen to the episodeTraditional SAST is deterministic but shallow; AI can reason about context but may answer differently every time. Can the two approaches make each other better?
Listen to the episodeGitGuardian found 29 million hard-coded secrets in public GitHub commits in one year—a 34% increase and its largest jump yet. Why is a supposedly simple problem getting worse?
Listen to the episodeIf AI writes all the code and the developer barely reads it, where does AppSec fit?
Listen to the episodeAI is multiplying the amount of software organizations produce, but security teams are not multiplying with it.
Listen to the episodeOpenClaw makes always-on personal AI agents feel inevitable—and exposes how poorly prepared most organizations are for their autonomy.
Listen to the episodeAppSec teams are drowning in repetitive triage while the work that requires judgment keeps piling up.
Listen to the episodeWhat should OWASP become, and which leaders have a credible plan to get it there? In this special 2025 Board of Directors candidate debate, nine candidates…
Listen to the episodeMost products labeled as AI agents are little more than chatbots with tools. Francesco Cipollone, founder and CEO of Phoenix Security, explains what makes…
Listen to the episodeSecurity education often struggles because the people in the room are being talked at instead of invited to participate.
Listen to the episodeAPIs power modern applications, yet many AppSec programs still cannot reliably inventory them, model their threats, or enforce authorization.
Listen to the episodeThe EU Cyber Resilience Act turns product security from a best practice into a market-access requirement, and its effects extend well beyond Europe.
Listen to the episodeSecurity champions programs rarely fail because the idea is bad; they fail because organizations launch without management support, meaningful incentives, or a plan to prove value.
Listen to the episodeA dashboard full of green indicators can still describe an insecure organization. Aram Hovsepyan, founder and CEO of Codific and an OWASP SAMM contributor,…
Listen to the episodeWe’re discussing the intersections of application security (AppSec) and sales strategy with our guest, Sean Varga.
Listen to the episodeSarah-Jane Madden joins Chris and Robert to ask what AI actually changes in software development—and what foundational practices still matter.
Listen to the episode