Tromzo
Future of Application Security
The Future of Application Security is a podcast for ambitious leaders who want to build a modern and effective AppSec program. Doing application security right is really hard and we want to help other experts build the future of AppSec by curating the best industry insights, tips and resources. What’s the most important security metric to measure in 2024? It’s Mean Time to Remediate (MTTR).Download our new MTTR guide: https://lnkd.in/evjcf4Vt
Be sure to visit the podcast's website and support the creator: futureofapplicationsecurity.podbean.com
Author
Tromzo
Category
Podcast website
Latest episode
May 22, 2024
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
EP 60 - Appian’s Abdullah Munawar on Enhancing Product Security Amid Evolving Development Trends 22.05.2024 21:05
In this episode of the Future of Application Security podcast, Harshil speaks with Abdullah Munawar , Director of Product Security at Appian . Abdullah shares valuable insights into his journey from security assessments and consulting to leading product security efforts, discussing the evolving challenges and strategies for building effective security programs in modern development environments. ...
EP 59 - Nat Mokry on Advancing Application Security in the Gaming Industry 24.04.2024 26:55
In our latest episode of the Future of Application Security podcast, Nat Mokry , VP of Application & Product Security at Xbox (formerly of Activision Blizzard at the time of recording), shares valuable insights into the world of application security, from the mission of defending player trust to emphasizing the importance of technical skills in cybersecurity. Nat provides guidance on building...
EP 58 — Asana's Felix Matenaar on Building Resilient Security Practices for the Future 10.04.2024 32:45
In this episode of the Future of Application Security podcast, Harshil interviews Felix Matenaar , Head of Product Security at Asana . Felix shares insights into his journey from Germany to Silicon Valley, where he transitioned from mobile security to leading Asana's product security efforts. The conversation highlights Felix's experience in creating security frameworks that eliminate vulnerabilit...
EP 57 — Clari's Steve Lukose on Using SLAs as Benchmarks for Businesses 27.03.2024 27:05
In this episode of the Future of Application Security, Harshil speaks with Steve Lukose , Vice President of Security at Clari , about how security is becoming a business enabler rather than just an organization. Steve explains why SLAs will become one of the benchmarks for security experts to use, but that it won’t necessarily be for all aspects of security. Still, they’ll be a great tool to help...
EP 56 — Aruneesh Salhotra on Why Security is Everyone’s Job 28.02.2024 24:49
In this episode of the Future of Application Security, Harshil speaks with Aruneesh Salhotra , CEO and Fractional CISO, SNM Consulting Inc. They discuss the unique challenges and opportunities of application security in the financial sector, including how the "necessary evil" of regulations is increasing accountability around security efforts. They also talk about the need for more vigilant softwa...
EP 55 — BlackBerry's Christine Gadsby on What's Driving Software Supplier Transparency and Accountability 14.02.2024 26:21
In this episode of the Future of Application Security, Harshil speaks with Christine Gadsby , VP, Product Security at BlackBerry , a software company specializing in cybersecurity. They discuss the new initiatives driving software transparency, like SBOMs and VEX, and how adoption will not only come from regulations but from companies holding their software suppliers more accountable. They also ta...
EP 54 — LPL Financial's Chad Girouard on Improving Application Security Through Better Tools and Relationships 31.01.2024 23:43
In this episode of the Future of Application Security, Harshil speaks with Chad Girouard , AVP Application Security at LPL Financial , a provider of investment and business solutions. They discuss how security teams can better engage with developers, and how they can encourage secure coding through scanning tools and security champion programs. They also talk about how to manage the "results delug...
EP 53 — ReversingLabs's Dave Ferguson on Securing Your Software Supply Chains 17.01.2024 24:24
In this episode of the Future of Application Security, Harshil speaks with Dave Ferguson , Director of Technical Product Management, Software Supply Chain Security at ReversingLabs , which offers software supply chain security analysis platform. They discuss the rising need for software supply chain security as a result of the complexities around how software is built today. They also talk about w...
EP 52 — Gen’s Curtis Koenig on Speaking the Language of Why Security Matters 13.12.2023 27:28
In this episode of the Future of Application Security, Harshil speaks with Curtis Koenig , Head of Application Security at Gen , a multinational software company that provides cybersecurity software and services. They discuss why it's key to be able to articulate why security matters and how it impacts business goals, and what Curtis has learned about how different industries approach risk. They a...
EP 51 — Ping Identity’s Arthur Loris on How to Tell Better Stories About Your Product Security Success 29.11.2023 27:10
In this episode of the Future of Application Security, Harshil speaks with Arthur Loris , Senior Manager, Product Security at Ping Identity , a company that provides self-hosted identity access management (IAM) solutions. They discuss what product security constitutes at Ping Identity, the biggest challenge to great product security, and how security teams need more strategic, tactical plans to ac...
EP 50 — DryRun Security’s James Wickett on Aligning Incentives and Speaking the Same Language with Developers and Security 15.11.2023 31:08
In this special episode of the Future of Application Security, recorded at the Developers & Security are Friends Day , Eric speaks with James Wickett , co-founder and CEO of DryRun Security , a company that provides security products for developers. They discuss the misaligned incentives between developers and security and how teams can learn how to speak the same language to increase value. T...
EP 49 — Semgrep’s Colleen Dai on Building Security Strategies and Relationships with Other Teams 02.11.2023 20:14
In this special episode of the Future of Application Security, recorded at the Developers & Security are Friends Day , Eric speaks with Colleen Dai , Senior Security Researcher at Semgrep , an open source static analysis tool. They discuss strategies security teams can take to reduce false positives, use secure defaults to eliminate bug classes, and reduce complexity in security decision-makin...
EP 48 — Chaotic Good’s Johnathan Kuskos on Testing for Functionality, Priorities, and Better Incident Response 26.10.2023 31:10
In this special episode of the Future of Application Security, recorded at the Developers & Security are Friends Day , Eric speaks with Johnathan Kuskos , Founder of Chaotic Good Information Security , a boutique professional services company. They discuss what it's like to be a pen tester, some of the unusual things found during testing, and how the 15 Minutes Rule helps you not waste time du...
EP 47 — Manicode Security’s Jim Manico on Addressing OWASP Top Ten Issues Through Better Security and Developer Partnerships 18.10.2023 26:38
In this special episode of the Future of Application Security, recorded at the Developers & Security are Friends Day , Eric speaks with Jim Manico , Founder and CEO of Manicode Security , a secure coding education firm. They discuss the various challenges around certain items on the OWASP Top Ten list, including server side request forgery and access control, and how security and developers ca...
EP 46 — TuSimple’s Madjid Nakhjiri on the Evolving Need for Automotive Cybersecurity 20.09.2023 24:03
In this episode of the Future of Application Security, Harshil speaks with Madjid Nakhjiri , Head of Product Security and Lead Security Architect at TuSimple , a global autonomous driving technology company. They discuss the current landscape of automotive security today, why the industry is expanding its safety initiatives to cyber security initiatives, and the standards rising up to ensure that...
EP 45 — Toast’s David Kosorok on Leading Application Security with Collaboration, Empathy, and Good Data 14.09.2023 33:55
In this episode of the Future of Application Security, Harshil speaks with David Kosorok , Director of AppSec at Toast , a restaurant point of sale and management system. They discuss how to build an application security program from the ground up by prioritizing initiatives, establishing security champions, and bringing in great people — and why gathering and analyzing good data is the foundation...
EP 44 — Workrise’s Tim Kelly on How to Build a Data-Driven Application Security Program 28.08.2023 24:06
In this episode of the Future of Application Security, Harshil speaks with Tim Kelly , Director, Security Engineering at Workrise , a technology company with a platform that supports the energy workforce. They discuss the importance of collecting, storing, and analyzing data in order to enhance application security efforts, and how to go about building a data program that does that. They also disc...
EP 43 — Avalara’s Derek Samford on Building a Security Culture with Data, Collaboration, Education, and Empathy 16.08.2023 35:56
In this episode of the Future of Application Security, Harshil speaks with Derek Samford , Senior Director of Product Security at Avalara , a company that builds cloud-based tax compliance solutions. They discuss Derek's approach to product security, including how his team uses data to drive visibility, how feedback loops can build maturity, and how they create application grade cards that inform...
EP 42 — Snowflake’s Jacob Salassi on the Science of Product Security 02.08.2023 38:00
In this episode of the Future of Application Security, Harshil speaks with Jacob Salassi , Director, Product Security at Snowflake , a cloud computing and data management company. They discuss how Snowflake approaches product security — from what they expect engineers and developers to do, to their risk-based reporting — and why Jacob takes a scientific approach to it. They also discuss how Jacob'...
EP 41 — SAP’s Helen Oakley on Protecting Human Well-Being by Securing Software Supply Chains 26.07.2023 26:07
In this episode of the Future of Application Security, Harshil speaks with Helen Oakley , Lead Architect for Software Supply Chain Security at SAP , which develops enterprise software for business operations. They discuss the need for software supply chain security, especially considering how much of software is open source today, and what the current state of adoption is across industries. They a...
EP 40 — Steve Springett on Solving Software Supply Chain Security and SBOM Challenges 19.07.2023 33:58
In this episode of the Future of Application Security, Harshil speaks with Steve Springett. They discuss the broad definition of what software supply chain security is, the implementation of SBOMs after the White House's Executive Order, and how organizations can effectively adopt, operationalize, and use SBOMs. They also discuss the biggest drivers for better software supply chain security, why...
EP 39 — A Modernized and Scalable Approach to Product Security with Origami Risk’s Prajakta Badhe 12.07.2023 28:20
In this episode of the Future of Application Security, Harshil speaks with Prajakta Badhe , Head of Product Security at Origami Risk , which provides risk software to the insurance industry. They discuss how product security is different from application security, the ways in which Prajakta evaluates a product’s risk, and why she always gives context as to why a vulnerability needs remediation. Th...
EP 38 — Avalara’s Anthony Ungerman on the Imperative for Security-Minded Organizations 06.07.2023 29:34
In this episode of the Future of Application Security, Harshil speaks with Anthony Ungerman , VP Product Security at Avalara , a tax software company. They discuss what product security encompasses beyond application security, how the security team at Avalara works with engineers, and how they articulate business value to increase security implementation. They also discuss security automation, app...
EP 37 — Choosing AppSec Priorities: Software Supply Chain, Code-to-Cloud Business Context and Metrics 28.06.2023 55:51
Tanya Janca , Founder of We Hack Purple , and Eric Sheridan, Chief Innovation Officer at Tromzo, join us for a special episode of the Future of Application Security Podcast. This episode was originally recorded as a LinkedIn Live on June 25, 2023. Tanya and Eric discuss how understanding the context in which applications operate is crucial for effective AppSec prioritization. You don't want to mi...
EP 36 — Highspot’s Joe Basirico on How to Build Security by Buildng Trust 21.06.2023 30:58
In this episode of the Future of Application Security, Harshil speaks with Joe Basirico , Senior Director of Product Security at Highspot , a sales enablement platform. They discuss how product security's evolution has increased its focus on relationships and trust-building, why security is like fixing a leaky faucet, and how to prioritize for more efficiency and impact. They also discuss where pr...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.