Listening guide
New to application security? Start here
This guide is for developers and people new to application security. Chris Romeo and Robert Hurlbut host The Application Security Podcast, where practitioners explain how software security works in real teams. Listen in this order to build a foundation, understand testing and dependencies, and then explore security culture, possible career paths, and the risks of AI applications.
Listen in this order
1. Andrew Van Der Stock -- The New OWASP Top Ten
Andrew van der Stock · July 23, 2024 · 52 min
Why this one: Andrew explains how OWASP gathers data and builds its Top 10. Start here to understand the role of this awareness list before treating it as a testing checklist.
2. Chris and Robert -- The Activities of the Secure Development Lifecycle
Chris Romeo and Robert Hurlbut · September 20, 2016 · 44 min
Why this one: Chris and Robert walk through requirements, coding standards, review, testing, and response. Hear how security activities fit into development and how different roles share the work.
3. Pete Chestna -- SAST, DAST, and IAST. Oh My!
Pete Chestna · February 16, 2018 · 35 min
Why this one: Pete explains static, dynamic, interactive, and composition analysis in the context of a security program. Learn what each approach can reveal and why tools need to fit developer workflows.
4. Erez Yalon — The OWASP API Security Project
Erez Yalon · January 3, 2020 · 37 min
Why this one: Erez walks through the original 2019 API Security Top 10. The examples explain object-level authorization, data exposure, and other assumptions that make APIs different from traditional web applications.
5. Chris Hughes -- Software Transparency
Chris Hughes · January 20, 2024 · 39 min
Why this one: Chris Hughes explains software transparency and software bills of materials. Connect the dependencies inside an application to the wider software supply chain.
6. Your AppSec Bottleneck Is a People Problem
Lisi Hocke · September 7, 2026 · 48 min
Why this one: Lisi Hocke explains what makes a security champions program work from a participant’s perspective. Learn why psychological safety, cognitive load, influence, and community matter.
7. Tracy Maleeff -- Natural Paranoia as a Career Path? A Transition to Security
Tracy Maleeff · December 6, 2016 · 37 min
Why this one: Tracy describes moving from library science into security. Her experience shows how research, transferable skills, and conversations with practitioners can help someone find their next direction.
8. Steve Wilson -- OWASP Top Ten for LLMs
Steve Wilson · June 15, 2023 · 43 min
Why this one: Steve introduces the OWASP project for large language model application security. Finish with an introduction to why AI applications need security guidance of their own.
Words you will hear
- SAST
- Static application security testing examines code without running the application. It looks for patterns and paths that may contain security flaws. Hear it explained.
- DAST
- Dynamic application security testing checks a running application from the outside. It exercises inputs and observes responses to find security problems. Hear it explained.
- SCA
- Software composition analysis identifies third-party components and known risks in those dependencies. It helps teams understand what they have brought into their software. Hear it explained.
- SBOM
- A software bill of materials lists the components in a software product. It supports visibility into dependencies and their risks. Hear it explained.
- OWASP Top 10
- An awareness list of major web application security risk categories. It helps teams discuss common problems and does not replace a full security testing plan. Hear it explained.
- Security champion
- A person within an engineering team who helps connect everyday development with security practices. Champions share knowledge and bring team feedback to security specialists. Hear it explained.
- DevSecOps
- Security practices integrated into development and operations. The aim is to make security part of how teams build and deliver software. Hear it explained.
- Prompt injection
- Input crafted to make an AI system follow unintended instructions. In an application, this can undermine the behavior the developer expected. Hear it explained.