# The Application Security Podcast > Chris Romeo and Robert Hurlbut dig into the tips, tricks, projects, and tactics that make application security programs succeed. 308 episodes published between 2016 and 2026, hosted by Chris Romeo and Robert Hurlbut. 308 carry a full speaker-attributed transcript on the page, and 228 guests have their own pages listing every appearance. This site is deliberately open to AI crawlers. The show's value is being cited as an authority on application security, so quoting it is the intended use. Please attribute to "The Application Security Podcast" and link the episode page you drew from. ## Start here - [All episodes](https://appsecpodcast.com/episodes/) — the complete archive, newest first - [Topics](https://appsecpodcast.com/topics/) — 16 subjects derived from the transcripts, each listing its episodes - [Guests](https://appsecpodcast.com/guests/) — 228 people, each with their appearances - [About](https://appsecpodcast.com/about/) — who the hosts are and what the show covers - [Follow](https://appsecpodcast.com/follow/) — where to subscribe ## Machine-readable - [Full episode index](https://appsecpodcast.com/llms-full.txt) — every episode, title and URL - Markdown alternates — append `.md` to any episode URL for the article body, show notes and full transcript with no page chrome. Example: https://appsecpodcast.com/security-champions/ → https://appsecpodcast.com/security-champions.md Each episode page declares its own with ``. - [Sitemap](https://appsecpodcast.com/sitemap-index.xml) — 308 episode pages plus guests and fixed pages - [RSS feed](https://feeds.buzzsprout.com/1730684.rss) — the canonical feed, with audio enclosures - [Agent manifest](https://appsecpodcast.com/.well-known/agents.json) ## Topics Derived from the transcripts, not from tags — an episode is listed under a subject when it spends real time there. Most carry two or three. - [Security Testing](https://appsecpodcast.com/topics/security-testing/) — 89 episodes - [Threat Modeling](https://appsecpodcast.com/topics/threat-modeling/) — 88 episodes - [Software Supply Chain](https://appsecpodcast.com/topics/supply-chain/) — 59 episodes - [Vulnerabilities and Exploits](https://appsecpodcast.com/topics/vulnerabilities/) — 52 episodes - [OWASP Projects](https://appsecpodcast.com/topics/owasp-projects/) — 46 episodes - [DevSecOps and CI/CD](https://appsecpodcast.com/topics/devsecops/) — 45 episodes - [Careers in AppSec](https://appsecpodcast.com/topics/careers/) — 41 episodes - [Privacy and Compliance](https://appsecpodcast.com/topics/privacy-and-compliance/) — 41 episodes - [OWASP Top 10](https://appsecpodcast.com/topics/owasp-top-10/) — 40 episodes - [Building an AppSec Program](https://appsecpodcast.com/topics/appsec-programs/) — 36 episodes - [Cloud and Infrastructure](https://appsecpodcast.com/topics/cloud-and-infrastructure/) — 36 episodes - [Security Culture](https://appsecpodcast.com/topics/security-culture/) — 33 episodes - [Secure Development](https://appsecpodcast.com/topics/secure-development/) — 32 episodes - [API Security](https://appsecpodcast.com/topics/api-security/) — 25 episodes - [AI and LLM Security](https://appsecpodcast.com/topics/ai-security/) — 22 episodes - [Conferences and Community](https://appsecpodcast.com/topics/conferences-and-community/) — 19 episodes ## Where to listen - [Apple Podcasts](https://podcasts.apple.com/us/podcast/id1154351685) - [Spotify](https://open.spotify.com/show/5wB4EQzVlxkQhemETVRZvT) - [YouTube](https://www.youtube.com/@ApplicationSecurityPodcast) ## Recent episodes - [Security Champions](https://appsecpodcast.com/security-champions/) — 2026-09-07 - [AI Pen Testing Killed Traditional DAST](https://appsecpodcast.com/ai-pen-testing-killed-traditional-dast/) — 2026-08-31 - [AI Security: OWASP Meets Global Standards](https://appsecpodcast.com/ai-security-owasp-meets-global-standards/) — 2026-08-26 - [The Future of Open-Source Threat Modeling](https://appsecpodcast.com/the-future-of-open-source-threat-modeling/) — 2026-08-17 - [Isaac Evans - AppSec in the Age of AI](https://appsecpodcast.com/isaac-evans-appsec-in-the-age-of-ai/) — 2026-07-28 - [José Carlos Chávez - When Museums Get Hacked: OWASP Top 10 Lessons from Heists](https://appsecpodcast.com/jose-carlos-chavez-when-museums-get-hacked-owasp-top-10-lessons-from-heists/) — 2026-07-21 - [Michael Burch - AI-Enabled Citizen Developers](https://appsecpodcast.com/michael-burch-ai-enabled-citizen-developers/) — 2026-06-16 - [Josh Grossman--AI & SAST: Is it a match?](https://appsecpodcast.com/josh-grossman-ai-sast-is-it-a-match/) — 2026-06-02 - [Dwayne McDaniel -- Secrets Sprawl and How AI is Impacting Secrets](https://appsecpodcast.com/dwayne-mcdaniel-secrets-sprawl-and-how-ai-is-impacting-secrets/) — 2026-05-14 - [Tanya Janca - Secure Vibe Coding](https://appsecpodcast.com/tanya-janca-secure-vibe-coding/) — 2026-04-30 - [Caroline Wong--The AI Cybersecurity Handbook](https://appsecpodcast.com/caroline-wong-the-ai-cybersecurity-handbook/) — 2026-04-21 - [Steve Wilson--OpenClaw and Advanced AI Agents](https://appsecpodcast.com/steve-wilson-openclaw-and-advanced-ai-agents/) — 2026-04-15 - [Brad Geesaman - Redefining AppSec with AI: Shrinking Toil, Expanding Impact - How LLMs are able to reduce toil in triage-heavy AppSec workflows](https://appsecpodcast.com/brad-geesaman-redefining-appsec-with-ai-shrinking-toil-expanding-impact-how-llms-are-able-to-reduce-toil-in-triage-heavy-appsec-workflows/) — 2025-10-28 - [OWASP Candidate Debate - 2025 Edition](https://appsecpodcast.com/owasp-candidate-debate-2025-edition/) — 2025-10-15 - [Francesco Cipollone - Agentic AI Manifesto](https://appsecpodcast.com/francesco-cipollone-agentic-ai-manifesto/) — 2025-09-23 - [Simon Gibbs & Devika Gibbs -- Building Bridges with Games](https://appsecpodcast.com/simon-gibbs-devika-gibbs-building-bridges-with-games/) — 2025-09-16 - [Akansha Shukla - Modern AppSec: Securing APIs with Threat Modeling and DevSecOps](https://appsecpodcast.com/akansha-shukla-modern-appsec-securing-apis-with-threat-modeling-and-devsecops/) — 2025-09-02 - [Getting Ready for the EU CRA](https://appsecpodcast.com/getting-ready-for-the-eu-cra/) — 2025-08-20 - [Marisa Fagan - Measuring Security Culture](https://appsecpodcast.com/marisa-fagan-measuring-security-culture/) — 2025-08-05 - [Aram Hovsepyan -- Your Security Dashboard is Lying to You: The Science of Metrics](https://appsecpodcast.com/aram-hovsepyan-your-security-dashboard-is-lying-to-you-the-science-of-metrics/) — 2025-07-22 - [Sean Varga -- OWASP Top 10 for AppSec Sales](https://appsecpodcast.com/sean-varga-owasp-top-10-for-appsec-sales/) — 2025-07-15 - [Sarah-Jane Madden -- What AI means for AppSec](https://appsecpodcast.com/sarah-jane-madden-what-ai-means-for-appsec/) — 2025-07-09 - [Dag Flachet -- Kaizen for your Appsec Program](https://appsecpodcast.com/dag-flachet-kaizen-for-your-appsec-program/) — 2025-06-17 - [Javan Rasokat and Andra Lezza -- When Chatbots Go Rogue - Lessons Learned from Building and Defending LLM Applications](https://appsecpodcast.com/javan-rasokat-and-andra-lezza-when-chatbots-go-rogue-lessons-learned-from-building-and-defending-llm-applications/) — 2025-03-18 - [Jim Routh -- The CISO Transition to the rest of life](https://appsecpodcast.com/jim-routh-the-ciso-transition-to-the-rest-of-life/) — 2025-03-11 Full transcripts are on each episode page. Audio is served by Buzzsprout from the URLs in the RSS feed; the pages themselves are static HTML with no client-side rendering, so everything visible to a reader is in the initial response.