Isaac Evans - AppSec in the Age of AI
In this episode, we sit down with Isaac Evans, co-founder and CEO of Semgrep, to talk about how AI is reshaping application security faster than almost anyone expected.
Listen to the episodeTopic
Dependencies, SBOMs, provenance and the long tail of open source that ships inside everything.
In this episode, we sit down with Isaac Evans, co-founder and CEO of Semgrep, to talk about how AI is reshaping application security faster than almost anyone expected.
Listen to the episodeIn this episode, we sit down with Jose Carlos Chavez from Okta to break down the OWASP Top 10 for 2025 and what actually changed since 2021.
Listen to the episodeIn this special episode of the Application Security Podcast we meet nine of the OWASP Board of Directors candidates.
Listen to the episodeThe European Union's Cyber Resilience Act is set to revolutionize how we approach product security worldwide.
Listen to the episodeHenrik Plate joins us to discuss the OWASP Top 10 Open Source Risks, a guide highlighting critical security and operational challenges in using open source dependencies.
Listen to the episodeFrançois Proulx shares his discovery of security vulnerabilities in build pipelines. Francois has found that attackers can exploit this often overlooked side of the software supply chain.
Listen to the episodeSteve Springett, an expert in secure software development and a key figure in several OWASP projects is back. Steve unpacks CycloneDX and the value proposition of various BOMs.
Listen to the episodeMatt Rose, an experienced technical AppSec testing leader discusses his career journey and significant contributions in AppSec.
Listen to the episodeJames Berthoty, a cloud security engineer with a diverse IT background, discusses his journey into application and product security.
Listen to the episodeMark Curphey and Simon Bennetts, join Chris on the podcast to discuss the challenges of funding and sustaining major open source security projects like ZAP.
Listen to the episodeKyle Kelly joins Chris to explore the wild west of software supply chain security.
Listen to the episodeChris Hughes, co-founder of Aquia, joins Chris and Robert on the Application Security Podcast to discuss points from his recent book Software Transparency:…
Listen to the episodeChris John Riley joins Chris and Robert to discuss the Minimum Viable Secure Product. MVSP is a minimalistic security checklist for B2B software and business process outsourcing suppliers.
Listen to the episodeSteve Wilson and Gavin Klondike are part of the core team for the OWASP Top 10 for Large Language Model Applications project.
Listen to the episodeHasan Yasar believes that everyone shares the responsibility of creating a secure environment, and this can only be achieved by working collaboratively.
Listen to the episodeVarun Badhwar is a three-time founder, a luminary in the cyber security industry, and a clear communicator.
Listen to the episodeMark Curphey and John Viega join Chris and Robert to explain the details of Chalk, Crash Override's new tool.
Listen to the episodeKevin Johnson is the CEO of Secure Ideas. He began his career as a developer but turned toward security when he discovered that the interface for an intrusion detection system, Snort, was out of date.
Listen to the episodeCloud security is on an evolutionary path, with newer platforms embracing secure-by-default settings.
Listen to the episode"Visualizing the Software Supply Chain" is a project which aims to kick off a discussion about the scope and breadth of the software supply chain.
Listen to the episodeSoftware supply chain -- how deep does the problem go? François is here to help us realize how deep the rabbit hole of the supply chain is and enlighten us with strategies to get out of the hole.
Listen to the episodeWhat is the state of application security? JB Aviat answered that question, by creating the state of application security report based on data from Datadog…
Listen to the episodeHave you ever considered using an SBOM to inform your threat modeling? Tony Turner has. Tony joins us to discuss SBOMs, threat modeling, and the importance of Cyber Informed Engineering.
Listen to the episodeDerek is the author of “The Application Security Handbook.” He is a university instructor at Temple University, where he teaches software development security to undergraduate and graduate students.
Listen to the episodeMark Curphey is one of the creators of OWASP from the very early days. Mark worked in the background over the few decades of OWASP but has recently taken more to the spotlight.
Listen to the episodeWith nearly 25 years of experience in the cyber-security industry, Guy held various positions in both corporates and startups.
Listen to the episodeBrett Smith is a Software Architect/Engineer/Developer with 20+ years of experience.
Listen to the episodePatrick is a Senior Product Security Engineer in the Application Security team at ServiceNow. He is also Co-Leader of the OWASP CycloneDX project.
Listen to the episodeDaniel Krivelevich is a cybersecurity expert and problem solver, with 15+ years of enterprise security experience with a proven track record working with…
Listen to the episodeAlex Mor is a passionate cybersecurity defender or breaker depending on the time of day, providing expert technical guidance to product teams and building security in their platforms.
Listen to the episodeWill Ratner is a software security professional with extensive experience building and implementing security solutions across a myriad of industries…
Listen to the episodeKen Toler is a principal consultant at Kudelski Security and is passionate about building and optimizing application security programs that stick through strong adoption and ease of use.
Listen to the episodeOchaun Marshall is an Application Security Consultant. In his roles of secure ideas, he works on on-going development projects utilizing Amazon web services and breaks other people's web applications.
Listen to the episodeJeroen Willemsen is a Principal Security Architect at Xebia. Jeroen is more or less a jack of all trades with an interest in infrastructure security, risk management, and application security.
Listen to the episodeKevin Greene is the Director of Security Solutions at Parasoft and has extensive experience and expertise in software security, cyber research and development, and DevOps.
Listen to the episodeVandana Verma is the President of Infosec girls and Infosec Kids, a board of directors member for OWASP, and a leader for BSides Dehli. She joins us to introduce the OWASP Spotlight Series.
Listen to the episodeDr. Anita D’Amico is the CEO of Code Dx, which provides Application Security Orchestration and Correlation solutions to industry and government.
Listen to the episodeLiran Tal is an application security activist and long-time proponent of open-source software.
Listen to the episodeJC Herz is the COO of Ion Channel, a software logistics and supply chain assurance platform for critical infrastructure.
Listen to the episodeFrank Rietta is the CEO of Rietta.com, a Security Focused Web Application Firm. He is a web application security architect, expert witness, author, and speaker.
Listen to the episodeAaron Davis is a founder, dev, and a lead security researcher at MetaMask, a popular Ethereum wallet.
Listen to the episodeDrew Dennison is the CTO & co-founder of r2c, a startup working to profoundly improve software security and reliability to safeguard human progress.
Listen to the episodeJeremy Long is a principal engineer specializing in securing the SDLC. Jeremy is the founder and project lead for the OWASP dependency-check project; a…
Listen to the episodeNiels Tanis has a background in .NET development, pen-testing, and security consultancy. He has experience breaking, defending and building secure applications.
Listen to the episodeMaya is a Product Manager in Security & Privacy at Google, focused on container security. She previously worked on encryption at rest and encryption key management.
Listen to the episodeThreat modeling, secrets, mentoring, self-care, program building, and much more. Clips from Georgia Weidman, Simon Bennetts, Izar Tarandach, Omer Levi…
Listen to the episodeLiran Tal is a Developer Advocate @snyksec and is the author of Essential Node.js Security. He takes #opensource and protecting the #web very seriously.
Listen to the episodeWhy should someone care about open source security?
Listen to the episodeSteve Springett is a technologist, husband, father, entrepreneur, and tequila aficionado. He is the creator of the OWASP @DependencyTrack and @CycloneDX_Spec.
Listen to the episodeThe question is for Steve Springett, in regards to Software Composition Analysis / Software Supply Chain and OWASP Dependency Track.
Listen to the episodeTommy Ross serves as Senior Director, Policy with BSA | The Software Alliance. In this role, he works with BSA members to develop and advance global policy…
Listen to the episodeChris talks with Jeff Williams about the History of OWASP and where it came from. You can find Jeff on Twitter @planetlevel
Listen to the episodeChris talks with Erlend Oftedal about the Norway Chapter of OWASP and continues on to what retire.js is and how it works.
Listen to the episodeThe conclusion of Season 3, all the best highlights, and some great advice from our guests on what you need to build an #AppSec Program.
Listen to the episodeDavid Habusha joins to discuss the OWASP Top 10 A9: Using components with known vulnerabilities. He also dives into the Software Composition Analysis (SCA) market.
Listen to the episodeSteve Springett joins the show to talk about Dependency Check and Dependency Track. He also discusses how they can help prevent you from using components with known vulnerabilities.
Listen to the episodeThis is the final interview from the #AppSecUSA Conference in Orlando, and Brian Andrzejewski joins Chris and Robert. He talks about containers, their usage within #AppSec, and orchestrations.
Listen to the episodeA listener asked for a recommendation for a PodCast or Blog post about Docker security. We looked but couldn’t find one, so we created one.
Listen to the episodeOur topic today is technical debt and how security plays into it. Chris was at Converge Conference 2017 in Detroit, Michigan (which he says is the best…
Listen to the episode