Hasan Yasar -- Actionable SBOM via DevSecOps
Hasan Yasar believes that everyone shares the responsibility of creating a secure environment, and this can only be achieved by working collaboratively.
Listen to the episode310 episodes, going back to 2016.
Hasan Yasar believes that everyone shares the responsibility of creating a secure environment, and this can only be achieved by working collaboratively.
Listen to the episodeVarun Badhwar is a three-time founder, a luminary in the cyber security industry, and a clear communicator.
Listen to the episodeSix candidates for the 2023 OWASP Board of Directors debate the choices that shape the foundation and its community.
Listen to the episodeItzik Alvas, Co-founder and CEO of Entro, is an expert on secrets security. Itzik joins Chris and Robert to discuss the significance of understanding and…
Listen to the episodeHarshil Parikh is a seasoned security leader with experience building security and compliance functions from the ground up.
Listen to the episodeJeff Willams of Contrast Security joins Chris and Robert on the Application Security Podcast to discuss runtime security, emphasizing the significance of…
Listen to the episodeDevelopment, operations, and security teams generate oceans of data yet still struggle to answer basic questions about what code is running, who owns it, and which findings matter.
Listen to the episodeMaril Vernon is passionate about Purple teaming and joins Robert and Chris to discuss the intricacies of purple teaming in cybersecurity.
Listen to the episodeDan Küykendall visits The Application Security Podcast to discuss his series "Why All AppSec Products Suck" and explain why software companies should…
Listen to the episodeKevin Johnson is the CEO of Secure Ideas. He began his career as a developer but turned toward security when he discovered that the interface for an intrusion detection system, Snort, was out of date.
Listen to the episodeTony Quadros, the AppSec Lumberjack, shares the unique career path that led him to find his passion in Application Security.
Listen to the episodeCloud security is on an evolutionary path, with newer platforms embracing secure-by-default settings.
Listen to the episode"Visualizing the Software Supply Chain" is a project which aims to kick off a discussion about the scope and breadth of the software supply chain.
Listen to the episodeApplication security teams rarely have enough specialists to embed one expert with every development team.
Listen to the episodeKim Wuyts discusses her work in privacy threat modeling with LINDDUN, a framework inspired by Microsoft's STRIDE for security threat modeling.
Listen to the episodeSoftware supply chain -- how deep does the problem go? François is here to help us realize how deep the rabbit hole of the supply chain is and enlighten us with strategies to get out of the hole.
Listen to the episodeHow do we do security in the world of AI and LLMs? A great place to start is with an OWASP project tasked with creating a standardized guideline for…
Listen to the episodeWhat is the state of application security? JB Aviat answered that question by creating the state of application security report based on data from Datadog…
Listen to the episodeWhat is zero trust, and how does it impact the world of applications and application security?
Listen to the episodeJeevan Singh, the director of product security at Twilio, discusses the future of application security engineers.
Listen to the episodeHave you ever considered using an SBOM to inform your threat modeling? Tony Turner has. Tony joins us to discuss SBOMs, threat modeling, and the importance of Cyber Informed Engineering.
Listen to the episodeChristian Frichot, an AppSec hacker, security leader, and developer of hcltm. He discusses the DevOps threat modeling tool he dreamed up and built.
Listen to the episodeZohar Shachar joins us to discuss the bug bounty process from both sides. Zohar has spent time as a bug bounty hunter and shares wisdom on avoiding bug bounty-causing issues for your AppSec posture.
Listen to the episodeSarah-Jane Madden is the Chief Information Security Officer of Sensing Technology Group. - part of Fortive.
Listen to the episode