OWASP Candidate Debate - 2025 Edition
In this special episode of the Application Security Podcast we meet nine of the OWASP Board of Directors candidates.
Listen to the episodeTopic
The tools and standards that come out of OWASP — ZAP, ASVS, SAMM, Juice Shop, the Cheat Sheets, and the people who build them.
In this special episode of the Application Security Podcast we meet nine of the OWASP Board of Directors candidates.
Listen to the episodeSteve Springett, an expert in secure software development and a key figure in several OWASP projects is back. Steve unpacks CycloneDX and the value proposition of various BOMs.
Listen to the episodeMark Curphey and Simon Bennetts, join Chris on the podcast to discuss the challenges of funding and sustaining major open source security projects like ZAP.
Listen to the episodeBjorn Kimminich, the driving force behind the OWASP Juice Shop project, joins Chris and Robert to discuss all things Juice Shop.
Listen to the episodeThe Application Security Podcast presents the OWASP Board of Directors Debate for the 2023 elections. This is a unique and engaging discussion among six candidates vying for a position on the board.
Listen to the episodeMark Curphey and John Viega join Chris and Robert to explain the details of Chalk, Crash Override's new tool.
Listen to the episodeKevin Johnson is the CEO of Secure Ideas. He began his career as a developer but turned toward security when he discovered that the interface for an intrusion detection system, Snort, was out of date.
Listen to the episodeMark Curphey is one of the creators of OWASP from the very early days. Mark worked in the background over the few decades of OWASP but has recently taken more to the spotlight.
Listen to the episodeTiago Mendo is a co-founder and CTO of Probely. He has extensive experience in pentesting applications, training, and providing all-around security consultancy.
Listen to the episodeDominique Righetto is an AppSec enthusiast and OWASP projects contributor. Dominique joins us to discuss the OWASP Secure Headers project.
Listen to the episodePatrick is a Senior Product Security Engineer in the Application Security team at ServiceNow. He is also Co-Leader of the OWASP CycloneDX project.
Listen to the episodeSimon Bennetts is the OWASP Zed Attack Proxy (ZAP) Project Leader and a Distinguished Engineer at StackHawk, a company that uses ZAP to help users fix…
Listen to the episodeTimo Pagel has been in the IT industry for over fifteen years. After a system administrator and web developer career, he advises customers as a DevSecOps consultant and trainer.
Listen to the episodeVandana Verma is the President of Infosec girls and Infosec Kids, a board of directors member for OWASP, and a leader for BSides Dehli. She joins us to introduce the OWASP Spotlight Series.
Listen to the episodeJC Herz is the COO of Ion Channel, a software logistics and supply chain assurance platform for critical infrastructure.
Listen to the episodeElie Saad is an application security engineer, leading three different OWASP projects.
Listen to the episodeJannik Hollenbach is a Security Automation Engineer at iteratec GmbH, working on and with open source security testing tools to continuously detect security…
Listen to the episodeSebastien Deleersnyder is co-founder, CEO of Toreon, and Bart De Win is a director within PwC Belgium. They work together to co-lead both the OWASP Belgium Chapter and the OWASP SAMM project.
Listen to the episodeJeremy Long is a principal engineer specializing in securing the SDLC. Jeremy is the founder and project lead for the OWASP dependency-check project; a…
Listen to the episodeThreat modeling, secrets, mentoring, self-care, program building, and much more. Clips from Georgia Weidman, Simon Bennetts, Izar Tarandach, Omer Levi…
Listen to the episodeSteve Springett is a technologist, husband, father, entrepreneur, and tequila aficionado. He is the creator of the OWASP @DependencyTrack and @CycloneDX_Spec.
Listen to the episodeThe question is for Steve Springett, in regards to Software Composition Analysis / Software Supply Chain and OWASP Dependency Track.
Listen to the episodeBjörn Kimminich is the project leader for OWASP JuiceShop. This is his second visit to the podcast, and we discuss new features in JuiceShop, including XSS…
Listen to the episodeBjörn Kimminich is the project leader for OWASP JuiceShop. He created JuiceShop out of necessity, after reviewing all the available vulnerable web apps years ago, and not finding what he needed.
Listen to the episodeNancy Gariché and Tanya Janca are two of the project leaders for the OWASP DevSlop Project. As we learn more about DevSlop, we realize that it is much more than a project: it's a movement.
Listen to the episodeSimon Bennetts is the project leader for OWASP ZAP. Simon joined Robert at CodeMash to talk about the origin of ZAP, the new heads up display, and ZAP API.
Listen to the episodeMatt Konda joins Chris and Robert to talk about what Glue is. You can find Matt on Twitter @mkonda OWASP Glue
Listen to the episodeChris talks with Jeff Williams about the History of OWASP and where it came from. You can find Jeff on Twitter @planetlevel
Listen to the episodeBjorn Kimminich joins to talk about JuiceShop. He dives into what JuiceShop is and some of its use cases. You can find Bjorn on Twitter @bkimminich
Listen to the episodeChris is at AppSec USA and is joined by Swaroop to talk about iGoat. They discuss how iGoat relates to WebGoat and how they can be used for pen testing.
Listen to the episodeChris talks with Erlend Oftedal about the Norway Chapter of OWASP and continues on to what retire.js is and how it works.
Listen to the episodeWe're joined by Matt Tesauro, a co-lead for the AppSec Pipeline Project. He explains how they began building this project and some ways for you to start using this in your organization.
Listen to the episodeStephen de Vries joins to discuss Threat Modeling and the unique approach that he takes by using tooling. We also discuss application security and startups.
Listen to the episodeChristian Folini joins Chris at AppSec EU for this episode about ModSecurity and the Core Rule Set project from OWASP.
Listen to the episodeThe conclusion of Season 3, all the best highlights, and some great advice from our guests on what you need to build an #AppSec Program.
Listen to the episodeMartin Knobloch joins Chris and Robert to discuss all things OWASP. They dive into the history of OWASP and some of the plans for the future. You can find Martin on Twitter @knoblochmartin.
Listen to the episodeJohn Melton joins to discuss the #OWASP AppSensor project. He talks about how AppSensor works and how it can be used in your application.
Listen to the episodeSteve Springett joins the show to talk about Dependency Check and Dependency Track. He also discusses how they can help prevent you from using components with known vulnerabilities.
Listen to the episodeJim Manico joins us to discuss some of the changes with the OWASP Cheat Sheets and their plans for that project's future.
Listen to the episodeTin Zaw, an advocate for ModSecurity, joins Robert and Chris. He dives into its background, the use of rules, and the many advantages.
Listen to the episodeChris and Robert talk to Jim Manico and Katy Anton about the OWASP Proactive Controls project. We have discussed this before, and they are looking for feedback on the upcoming update.
Listen to the episodeWe talk about the future of the OWASP Top 10. We do this by meeting the new project leadership team, understanding the process for how they do governance…
Listen to the episodeTanya and Nicole join Chris and Robert. They talk about what APIs are, how they are used, and some of the threats involved with them.
Listen to the episodeDave Ferguson discusses the OWASP Top 10 Proactive Controls in this episode with Chris.
Listen to the episodeWe’re here today with Jim Manico, a project lead with OWASP. We dive deep into some of the projects on his plate.
Listen to the episodeIn this episode, we speak with Mike Goodwin, the founder of the OWASP Threat Dragon.
Listen to the episode