The Elephant in AppSec
The Elephant in AppSec
Time to discuss AppSec issues no one talks about.
Autor
The Elephant in AppSec
Kategorie
Podcast-Website
Neueste Folge
20. Mai 2026
Wo hören?
Podcasts in der App Replaio Radio Bald verfügbarPodcasts kommen bald in die App. Installiere sie jetzt und erlebe als Erster einen ganz neuen Blick auf Podcasts
Folgen
Why Security Loses Influence in High-Growth Companies (And What to Do About It) with Kavia Venkatesh 20.05.2026 31:48
Today, I'm joined by Kavia Venkatesh, Director of Product Security at a large healthcare organization. She didn't take the traditional path into cybersecurity — she came from biotech. But that outsider lens turned out to be her edge. With over 10 years of experience leading cybersecurity strategy for hyper-scale ecosystems, she's built many security programs from the ground up, navigat...
The Lethal Trifecta or why your AI agent knows too much - Jason Fernandes 11.05.2026 33:03
Today, I’m joined by Jason Fernandes, VP of security and privacy at Mercari, the Japanese-born global marketplace now spanning e-commerce, FinTech, and crypto. It is this rare combination that puts him at the intersection of some of the strictest regulatory environments in tech. He oversees everything from product and platform security to threat detection, privacy, and, since last year, AI securi...
25 years of the same problem in Application Security - Sam Stepanyan 22.04.2026 37:36
Today, I’m joined by Sam Stepanyan, an OWASP Global Board member and an OWASP London Chapter Leader. Sam is an Independent Application Security Consultant and Security Architect with over 20 years of experience in the IT industry. Sam has worked for various financial services institutions in the City of London specialising in Application Security consulting, Secure Software Development Lifecycle...
Should security belong in every AI strategy meeting? with Amol Deshpande 29.12.2025 47:14
Today, I’m joined by Amol Deshpande, a seasoned security engineer currently at Stripe, where he focuses on building secure systems at massive scale. With a background spanning product security and penetration testing at companies like Salesforce, Splunk, and Early Warning, Amol brings deep hands-on experience in securing complex, real-world platforms. He’s also been a HackMIT judge and a long-time...
What Mindset Shift Developers Need to Break Into Security? with Aleksandra Kornecka 24.12.2025 38:42
Today, I’m joined by Aleksandra Kornecka, a security engineer with a global mindset. She recently transitioned from Senior AppSec Engineer to Cloud Infrastructure Security Engineer, and has a background in software testing and cognitive science — a combination that gives her a unique take on both the technical and human sides of security. As a member of the OWASP Security Champions Guide and the p...
Is the AI–API interaction the biggest security blind spot? with Gowtham Sundar 20.12.2025 31:29
Today, I’m joined by Gowtham Sundar, a Senior Lead Engineer - 3A Security (AI and API included as you can guess) at SPH Media and a seasoned AppSec leader with over a decade of experience across enterprise security, penetration testing, and secure product development. In this episode, Gowtham brings a real practitioner’s point of view on what it actually takes to secure AI systems. We dive into wh...
What best drives the adoption of secure software practices? with Enrique Larios Vargas 11.12.2025 38:10
Today, I’m joined by Enrique Larios Vargas, a Security and Learning Specialist at Adyen. Enrique has over eight years of experience designing impactful learning and enablement programs across fintech, engineering, and security. He’s also been a university lecturer in software engineering in Peru, the Netherlands, and Canada. Bringing together technical expertise and behavioral science, Enrique is...
Why AppSec Needs More Than Just a Checkbox ⎢ Marcos Vinicius Cassel 03.12.2025 42:32
Today, I’m joined by Marcos Vinicius Cassel, Application Security Manager at PowerSchool. With over a decade of experience in the information security space, as a CISSP, ISO 27001 Lead Auditor, and a passionate technologist, Marcos has led security initiatives across multiple industries. He also previously led the OWASP Porto Alegre Chapter, and fun fact: we first met while volunteering together...
The Supply Chain Crisis We Created: How AI, Extensions, and Dependencies Became the New Attack Surface with Aamiruddin Syed 26.11.2025 40:32
Today, I’m joined by Aamiruddin Syed, Senior Product Security Engineer at AGCO Corporation. Aamiruddin is the author of “Supply Chain Software Security book focusing on AI, IoT, and AppSec” and a recognized advocate for secure development. He’s a frequent speaker at major conferences, including RSA, DEFCON, and Black Hat. Fun facts: he was once ranked in the top 1% of all TryHackMe penetration tes...
Why AppSec Is breaking: Vibe Coding, DevSecOps backlogs & the new OWASP Top 10 (with Tanya Janca) 13.11.2025 51:09
Today, I’m joined once again by Tanya Janca for her second appearance on the podcast. Her first episode was a hit, so we figured: why not record another? And the timing couldn’t be better, as Tanya has just embarked on a brand-new chapter in her career this year. In our first conversation, I highlighted many of Tanya’s accomplishments, and she’s only added to the list since then. Most notably, she...
Secure by Design: Who’s Really Responsible? with Abhijeth Dugginapeddi 04.11.2025 43:24
Today on the show, I’m joined by Abhijeth Dugginapeddi, Director of Offensive Security at Palo Alto Networks. Before this, he built and led product and cloud security at BigCommerce, and worked on application security at Commonwealth Bank and Adobe. Abhijeth is deeply passionate about giving back to the community. He’s taught advanced web application security at UNSW, mentored through multiple out...
The Pressure of Security Leadership: What SLAs Actually Work? with Terry O'Daniel 19.10.2025 44:14
Today, I’m excited to be joined by Terry O’Daniel, former global head of security at Amplitude, Instacart, and Netflix, and a trusted advisor in the security space. Terry thrives in high-growth environments and loves tackling complex challenges. With a strong background in engineering and security, he builds teams that focus on solving security problems at scale through automation and instrumentat...
Can We Make AI Agents Smarter Than Security Teams? with Anshuman Bhartiya 25.09.2025 32:42
Today, I’m excited to welcome Anshuman Bhartiya, an AppSec tech lead at Lyft. Before that, he worked as a security engineer at companies like Thirty Madison, Intuit, and Atlassian. Anshuman is also a fellow podcaster and co-host of the Boring AppSec podcast, alongside one of my previous guests, Sandesh Mysore Anand. Recently, he’s been experimenting extensively with building AI agents for both off...
Why DevSecOps isn't enough without deep cloud context with Anjali Singh Shukla 24.09.2025 32:36
Today I’m joined by Anjali Singh Shukla, Senior Security Engineer Cloud at Flipkart. She bridges the worlds of Cloud Security and DevSecOps, having led audits and defense strategies across AWS, Azure, and GCP, with a strong focus on Kubernetes and container security. Beyond building secure pipelines, Anjali designs training programs and speaks at global conferences like Black Hat and OWASP. Most r...
Decoding a Healthy Security Program: What Does "Healthy" Even Mean? with Maxwell Zhou 18.09.2025 40:54
Today, I’m joined by Maxwell Zhou, the Founding Partner of PolarStar Cybersecurity Group, a cybersecurity firm focused on helping fintech organizations strengthen their product security. Throughout his career at Greenlight, Visa, and T-Mobile, Maxwell has specialized in penetration testing, vulnerability assessments, and secure coding practices. He’s particularly excited about building world-class...
Why SAP Security Can be a Hidden Weakness for Enterprises with Oumaima Baira 12.09.2025 36:57
Today, I’m joined by Oumaima Baira, Directrice of Enterprise Security at Deloitte. With nearly a decade of experience, she’s helped organizations strengthen their defenses — from DevSecOps and SAP application security to enterprise-wide security strategy. She began her career in cloud engineering before moving into cyber consulting, and quickly rose through Deloitte’s leadership ranks, blending de...
Latin America’s AppSec Culture: What’s Lost (and Found) in Translation? 05.09.2025 37:27
Today, I’m joined by Max Alejandro Gómez-Sánchez Vergaray, Defensive Cybersecurity Manager at Banco de Crédito BCP. With a background in software engineering, Max transitioned into AppSec and has become a leading voice in promoting DevSecOps awareness and building robust AppSec programs using SAMM across Latin America and beyond. He actively contributes to OWASP projects like Cornucopia and regula...
OWASP SAMM vs BSIMM: Which Maturity Model Reigns Supreme? 27.08.2025 46:26
Today, I'm joined by Nariman Aga-Tagiyev, a seasoned cybersecurity architect and threat modeling coach, bringing over two decades of experience in the software development industry. As the founder of SecureHabits, he’s on a mission to help software manufacturers mature their secure software development lifecycle. Nariman is a familiar face at OWASP Netherlands Chapter events and an active con...
Security Culture: When Are We Really Creating Change? with Marisa Fagan 21.08.2025 35:13
Today, I'm joined by Marisa Fagan , a lifelong community builder and security culture enthusiast. As the Head of Product at Katilyst, Marisa leads the development of security champion programs that empower Security Champions to drive cultural change. Previously, she served as Head of Trust Culture & Training at Atlassian and has managed security programs at Synopsys, Salesforce, and Meta....
Security Wins Only When Institutionalized – Here’s Why!⎜Kevan Bard 15.08.2025 43:59
Today, I'm joined by Kevan Bard, Director of Product Security at Morningstar. With 20 years of experience in information security, Kevan has helped shape security practices across various organizations. He’s passionate about building blue team careers, with a focus on recruiting, mentoring, and staff development. When not busy cultivating kaizen, emotional intelligence, secure coding practices...
Why Your Security Program Might Be Failing Before It Even Starts with Sean Finley 08.08.2025 39:29
Today, I’m joined by Sean Finley, an experienced Information and Application Security leader with deep expertise in AppSec, security operations, vulnerability management, and governance. Sean’s AppSec career started at GEICO, one of the most recognizable names in U.S. insurance. He made the leap from business analyst to the company’s very first AppSec engineer, teaching himself everything along th...
The Future of Pentesting: Can AI Replace Human Expertise? 29.07.2025 30:05
Today I’m joined by Jyoti Raval, a security leader with a diverse background across consulting, product security at Qualys and Harness, and now serving as Director of Cyber Security Engineering at Baker Hughes. Jyoti is a passionate pentester and international speaker. She’s also the author of Phishing Simulation and MPT: Pentest in Action and has discovered multiple CVEs. Beyond her technical exp...
How to Fix the Lack of Clear Guidance in Building Effective Security Programs | Luís Fontes 17.07.2025 35:53
Today's episode features Luís Fontes, who, after five years working with various technologies as a full-stack developer, transitioned to the AppSec world. Luís worked as an AppSec engineer at major companies like Checkmarx and then moved to IOVLabs (RSK) and the cryptocurrency space. Nowadays, Luís works at Xapo, a crypto bank, and is an expert in both product security and blockchain security....
AI Security: Do You Need a Dedicated Vendor? | Insights with James Berthoty 10.07.2025 45:43
Welcome to Season 4 of The Elephant in AppSec ! Get ready for a season packed with even spicier takes! Today's episode features none other than James Berthoty, a security engineer turned founder and CEO of Latio. James is always ready to share his unfiltered opinions, and I’ve had the pleasure of chatting with him for last couple of years. Over the past few months, there were a lot of discussi...
Why AppSec isn’t just for tech — Surprising Insights ⎜ Olga Dzięgielewska 17.06.2025 39:23
Today, I’m joined by Olga Dzięgielewska, Senior Manager of InfoSec Application Security at Philip Morris International. With over 10 years of experience in secure code reviews, a PhD in IT Security, and now leading global AppSec teams, Olga specializes in secure development practices, IT assurance, ethical hacking, API security and SAP security, driving security initiatives across multiple interna...
Ähnliche Podcasts
Replaio ist kein Herausgeber von Podcasts; die Namen der Sendungen, Cover und Audioinhalte gehören ihren Autoren und werden über öffentliche RSS-Feeds verbreitet