Will Ratner -- Centralized container scanning
Will Ratner is a software security professional with extensive experience building and implementing security solutions across a myriad of industries…
Listen to the episode310 episodes, going back to 2016.
Will Ratner is a software security professional with extensive experience building and implementing security solutions across a myriad of industries…
Listen to the episodeNeil Matatall is an engineer with a background in security. He has previously worked at GitHub and Twitter and is a co-founder of Loco Moco Product Security Conference.
Listen to the episodeJoern Freydank is a Lead Cyber Security Engineer with more than 20 years of experience. He is currently establishing the Threat Modeling Program at a major insurance company.
Listen to the episodeKen Toler is a principal consultant at Kudelski Security and is passionate about building and optimizing application security programs that stick through strong adoption and ease of use.
Listen to the episodeSecrets management fails in surprisingly ordinary ways: credentials land in code, deployment files, containers, and cloud resources, then quietly become part of the system’s attack surface.
Listen to the episodeAdam is a leading expert on threat modeling, and a consultant, expert witness, author and game designer. He has decades of experience delivering security.
Listen to the episodeOchaun Marshall is an Application Security Consultant. In his roles of secure ideas, he works on on-going development projects utilizing Amazon web services and breaks other people's web applications.
Listen to the episodeInfrastructure as code gives security teams something they have wanted for years: a readable description of the systems surrounding an application.
Listen to the episodeSimon Bennetts is the OWASP Zed Attack Proxy (ZAP) Project Leader and a Distinguished Engineer at StackHawk, a company that uses ZAP to help users fix…
Listen to the episodeTimo Pagel has been in the IT industry for over fifteen years. After a system administrator and web developer career, he advises customers as a DevSecOps consultant and trainer.
Listen to the episodeMazin Ahmed is a security engineer that specializes in AppSec and offensive security.
Listen to the episodeWhy do application security programs stall even after teams buy tools and define processes? James Ransome and Brook S. E.
Listen to the episodeChris and Robert conduct a practitioner peer review of the 2021 OWASP Top 10, examining what changed, what moved, and what the new structure communicates to development teams.
Listen to the episodeAdding encryption is easy; designing a system that protects keys, metadata, and users is much harder.
Listen to the episodeMark Loveless - aka Simple Nomad - is a security researcher and hacker. He's spoken at numerous security and hacker conferences worldwide, including Blackhat, DEF CON, ShmooCon, and RSA.
Listen to the episodeThreat modeling needs to fit the way developers work if it is going to survive a fast delivery cycle.
Listen to the episodeJeroen Willemsen is a Principal Security Architect at Xebia. Jeroen is more or less a jack of all trades with an interest in infrastructure security, risk management, and application security.
Listen to the episodeSoftware security has spent decades alternating between prevention, detection, and response. Kevin Greene joins Chris and Robert to ask what a balanced approach should look like now.
Listen to the episodeJeevan Singh is a Security Engineer Manager at Segment, where he is embedding security into all aspects of the software development process.
Listen to the episodeDima Kotik is an Application Security Engineer at Security Journey and has been programming in Python for years.
Listen to the episodeBefore taking the plunge into information security leadership, Dustin Lehr spent over a decade as a software engineer and architect in a variety of…
Listen to the episodeAaron Rinehart is expanding the possibilities of chaos engineering to cybersecurity.
Listen to the episodeThreat modeling advice often sounds simple until a development team tries to apply it to a real system.
Listen to the episodeCharles is a Senior Security Consultant for Red Siege. He has over 18 years of experience in IT.
Listen to the episode