Isaac Evans - AppSec in the Age of AI
In this episode, we sit down with Isaac Evans, co-founder and CEO of Semgrep, to talk about how AI is reshaping application security faster than almost anyone expected.
Listen to the episodeTopic
Writing software that resists attack: secure defaults, guardrails, paved roads, code review, and training that developers will sit through.
In this episode, we sit down with Isaac Evans, co-founder and CEO of Semgrep, to talk about how AI is reshaping application security faster than almost anyone expected.
Listen to the episodeAI isn’t just helping developers anymore; it’s writing the code, and that changes everything.
Listen to the episodeSarah Jane Madden joins us to discuss the evolving role of AI in software development.
Listen to the episodeSecurity expert Tanya Janca discusses her new book "Alice and Bob Learn Secure Coding" and shares insights on making security accessible to developers.
Listen to the episodeMehran Koushkebaghi, a seasoned engineering expert, delves into the intricacies of systemic security.
Listen to the episodeTanya Janka, also known as SheHacksPurple, discusses secure guardrails, the difference between guardrails and paved roads, and how to implement both in application security.
Listen to the episodeTanya Janca, also known as SheHacksPurple, joins the Application Security Podcast again to discuss secure coding, threat modeling, education, and other topics in the AppSec world.
Listen to the episodeHarshil Parikh is a seasoned security leader with experience building security and compliance functions from the ground up.
Listen to the episodeKim Wuyts discusses her work in privacy threat modeling with LINDDUN, a framework inspired by Microsoft's STRIDE for security threat modeling.
Listen to the episodeRobyn Lundin started working in tech after a coding boot camp as a developer for a small startup.
Listen to the episodeIn this episode of the Application Security Podcast, Chris Romeo walks through the origin story of Security Journey and shares some experiences taking a security startup from bootstrap to acquisition.
Listen to the episodeKen Toler is a principal consultant at Kudelski Security and is passionate about building and optimizing application security programs that stick through strong adoption and ease of use.
Listen to the episodeDima Kotik is an Application Security Engineer at Security Journey and has been programming in Python for years.
Listen to the episodeAaron Rinehart is expanding the possibilities of chaos engineering to cybersecurity.
Listen to the episodeVandana Verma is the President of Infosec girls and Infosec Kids, a board of directors member for OWASP, and a leader for BSides Dehli. She joins us to introduce the OWASP Spotlight Series.
Listen to the episodeJim Routh has built software security programs at some of the biggest brands in the world.
Listen to the episodeNeil Matatall is a product security engineer at GitHub. He focuses on designing and engineering user experiences solutions related to authentication and account recovery.
Listen to the episodeElie Saad is an application security engineer, leading three different OWASP projects.
Listen to the episodeMark Merkow works at WageWorks in Tempe, Arizona, leading application security architecture and engineering efforts in the office of the CISO.
Listen to the episodeSteve Lipner is a pioneer in cybersecurity, approaching 50 years’ experience. He retired in 2015 from Microsoft where he was the creator and long-time…
Listen to the episodeTommy Ross serves as Senior Director, Policy with BSA | The Software Alliance. In this role, he works with BSA members to develop and advance global policy…
Listen to the episodeNiels Tanis joins to talk about Razor and ASP.Net Core versus General. You can find Niels on Twitter @nielstanis
Listen to the episodeStephen de Vries joins to discuss Threat Modeling and the unique approach that he takes by using tooling. We also discuss application security and startups.
Listen to the episodeSean Wright joins Chris to discuss the changes Google made to handle the HTTP Protocol. They also dive into TLS and some other pieces of crypto that relate to #AppSec.
Listen to the episodeSecurity champions are the hands and feet of any well-equipped product security team.
Listen to the episodeChris and Robert talk to Jim Manico and Katy Anton about the OWASP Proactive Controls project. We have discussed this before, and they are looking for feedback on the upcoming update.
Listen to the episodeWe talk about the future of the OWASP Top 10. We do this by meeting the new project leadership team, understanding the process for how they do governance…
Listen to the episodeWe bring you a recorded version of Chris’s security conference talk from 2016 for this episode.
Listen to the episodeIn this episode, Robert interviews Chris about the security community. Chris talks about his experiences doing security community at a large organization for 5+ years.
Listen to the episodeRobert and I are joined today by Matt Clapham. Matt “makes products more secure” I mean, hey, his Twitter handle is @ProdSec.
Listen to the episodeOn this episode of the Application Security PodCast, we continue our journey through the foundations of application security. We explore the activities of the secure development life cycle.
Listen to the episodeIn the inaugural episode of the Application Security PodCast, Robert and I introduce ourselves to the audience, explain our journeys into the security…
Listen to the episode