Skip to content
AppSec PodcastThe Application Security Podcast — home

Listening guide

New to application security? Start here

This guide is for developers and people new to application security. Chris Romeo and Robert Hurlbut host The Application Security Podcast, where practitioners explain how software security works in real teams. Listen in this order to build a foundation, understand testing and dependencies, and then explore security culture, possible career paths, and the risks of AI applications.

Listen in this order

  1. 1. Andrew Van Der Stock -- The New OWASP Top Ten

    Andrew van der Stock · July 23, 2024 · 52 min

    Why this one: Andrew explains how OWASP gathers data and builds its Top 10. Start here to understand the role of this awareness list before treating it as a testing checklist.

    Read the transcript

  2. 2. Chris and Robert -- The Activities of the Secure Development Lifecycle

    Chris Romeo and Robert Hurlbut · September 20, 2016 · 44 min

    Why this one: Chris and Robert walk through requirements, coding standards, review, testing, and response. Hear how security activities fit into development and how different roles share the work.

    Read the transcript

  3. 3. Pete Chestna -- SAST, DAST, and IAST. Oh My!

    Pete Chestna · February 16, 2018 · 35 min

    Why this one: Pete explains static, dynamic, interactive, and composition analysis in the context of a security program. Learn what each approach can reveal and why tools need to fit developer workflows.

    Read the transcript

  4. 4. Erez Yalon — The OWASP API Security Project

    Erez Yalon · January 3, 2020 · 37 min

    Why this one: Erez walks through the original 2019 API Security Top 10. The examples explain object-level authorization, data exposure, and other assumptions that make APIs different from traditional web applications.

    Read the transcript

  5. 5. Chris Hughes -- Software Transparency

    Chris Hughes · January 20, 2024 · 39 min

    Why this one: Chris Hughes explains software transparency and software bills of materials. Connect the dependencies inside an application to the wider software supply chain.

    Read the transcript

  6. 6. Your AppSec Bottleneck Is a People Problem

    Lisi Hocke · September 7, 2026 · 48 min

    Why this one: Lisi Hocke explains what makes a security champions program work from a participant’s perspective. Learn why psychological safety, cognitive load, influence, and community matter.

    Read the transcript

  7. 7. Tracy Maleeff -- Natural Paranoia as a Career Path? A Transition to Security

    Tracy Maleeff · December 6, 2016 · 37 min

    Why this one: Tracy describes moving from library science into security. Her experience shows how research, transferable skills, and conversations with practitioners can help someone find their next direction.

    Read the transcript

  8. 8. Steve Wilson -- OWASP Top Ten for LLMs

    Steve Wilson · June 15, 2023 · 43 min

    Why this one: Steve introduces the OWASP project for large language model application security. Finish with an introduction to why AI applications need security guidance of their own.

    Read the transcript

Words you will hear

SAST
Static application security testing examines code without running the application. It looks for patterns and paths that may contain security flaws. Hear it explained.
DAST
Dynamic application security testing checks a running application from the outside. It exercises inputs and observes responses to find security problems. Hear it explained.
SCA
Software composition analysis identifies third-party components and known risks in those dependencies. It helps teams understand what they have brought into their software. Hear it explained.
SBOM
A software bill of materials lists the components in a software product. It supports visibility into dependencies and their risks. Hear it explained.
OWASP Top 10
An awareness list of major web application security risk categories. It helps teams discuss common problems and does not replace a full security testing plan. Hear it explained.
Security champion
A person within an engineering team who helps connect everyday development with security practices. Champions share knowledge and bring team feedback to security specialists. Hear it explained.
DevSecOps
Security practices integrated into development and operations. The aim is to make security part of how teams build and deliver software. Hear it explained.
Prompt injection
Input crafted to make an AI system follow unintended instructions. In an application, this can undermine the behavior the developer expected. Hear it explained.

Where to go next