Tromzo

Future of Application Security

Business EN ↓ 60 episodes

The Future of Application Security is a podcast for ambitious leaders who want to build a modern and effective AppSec program. Doing application security right is really hard and we want to help other experts build the future of AppSec by curating the best industry insights, tips and resources. What’s the most important security metric to measure in 2024? It’s Mean Time to Remediate (MTTR).Download our new MTTR guide: https://lnkd.in/evjcf4Vt

Be sure to visit the podcast's website and support the creator: futureofapplicationsecurity.podbean.com

Author

Tromzo

Category

Business

Latest episode

May 22, 2024

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android almost 10M downloads · 4.8 rating iOS soon

Episodes

EP 35 — Streamlining and Accelerating Your Product Security with iHerb’s Mike de Libero 15.06.2023

In this episode of the Future of Application Security, Harshil speaks with Mike de Libero , Director of Product Security at iHerb , an online health and wellness shop. They discuss the ways in which automation helps lighten the workload and creates more consistency, when you need to hire someone for security automation, and what to look for when scaling visibility. They also discuss how the role o...

EP 34 — The Future of AppSec: People, Processes, and Progress with Coalfire’s Warren Kopp 07.06.2023

In this episode of the Future of Application Security, Harshil speaks with Warren Kopp , Application Security Consultant at Coalfire , a cybersecurity advisor. Together they discuss how better application security involves building relationships with the people behind the processes, and why skills like communication, collaboration, and an understanding of psychology are keys to moving forward secu...

EP 33 — Democratizing Security and Implementing Change with Twilio’s Ariel Shin 01.06.2023

In this episode of the Future of Application Security, Harshil speaks with Ariel Shin , Senior Product Security Engineer at Twilio , a company that provides businesses the tools to connect with customers through automated messaging. Ariel shares the story of how she implemented a democratized, centralized vulnerability management program at Twilio, which included conducting interviews to gauge the...

EP 32 — Leading with Context - Where Institutional Knowledge Cannot Scale 24.05.2023

In the ever-evolving landscape of application security, organizations face the challenge of effectively scaling and growing their AppSec programs. On this episode of the Future of Application Security podcast, Harshil Parikh interviews Ty Sbano , the CISO of Vercel , who brings years of experience and expertise in the field of cybersecurity. During their conversation, Ty and Harshil shared their v...

EP 31 — Cloudflare’s Sri Pulla on Building Collaboration and Synergies for Better Product Security 17.05.2023

In this episode of the Future of Application Security, Harshil speaks with Sri Pulla , Director, Application Security at Cloudflare , a company that wants to "build a better internet" through its cloud platform of network services. They discuss how Cloudflare protects its products, uses risk scoring for prioritization and decision making, and why the engineering team must answer a security questio...

EP 30 — C.H. Robsinson’s Jason Espone on Building Business Resiliency Through Application Security 10.05.2023

In this episode of the Future of Application Security, Harshil speaks with Jason Espone , Global Head — Application Security Engineering | Cybersecurity at C.H. Robinson , the world’s most powerful logistics platform allowing customers to ship goods around the world. They discuss the challenges of addressing tech debt at a 117-year-old company, strategies to manage a vast application portfolio, an...

EP 29 — A Conversation on the State of AppSec with Reddit’s Matt Johansen and Semgrep’s Clint Gibler 03.05.2023

In this special edition of the Future of Application Security podcast, Harshil speaks with Matt Johansen , Principal Security Architect at Reddit , a community and content-sharing site, and Clint Gibler , Head of Security Research at Semgrep , an open source static analysis tool. Together they discuss how the world of AppSec has changed, including the more widespread adoption of a shift-left menta...

EP 28 — Injecting Better Security into Products and Processes with Dremio’s Emre Saglam 19.04.2023

In this episode of the Future of Application Security, Harshil speaks with Emre Saglam , Head of Security and Compliance at Dremio , a data lakehouse that empowers data engineers and analysts with easy-to-use self-service SQL analytics. They discuss the current state of AppSec, including how to improve security by prioritizing business implications, using frameworks, and having tools "closer to th...

EP 27 — Mohit Kalra: How Sprinklr Scales Product Security 12.04.2023

In this episode of the Future of Application Security, Harshil speaks with Mohit Kalra , Vice President of Product Security at Sprinklr , a platform that enables the world's largest enterprises to market, advertise, research, care, and engage consumers. Together, they take a look at the overall management of product security in a SaaS organization that needs to keep a large amount of customer data...

EP 26 — Derek Fisher: How Envestnet Scales Product Security 05.04.2023

In this episode of the Future of Application Security, Harshil speaks with Derek Fisher , the Head of Product Security at Envestnet , a publicly traded financial technology company that connects people's daily financial decisions with their long-term financial goals. Derek is a highly accomplished professional with an exceptional track record in engineering and information security. With his exper...

EP 25 — Navigating the Complex World of Software Supply Chain Security with Schneider Electric’s Cassie Crossley 29.03.2023

In this podcast episode of the Future of Application Security, Harshil speaks to Cassie Crossley , VP of Supply Chain Security at Schneider Electric, a global specialist in energy management and automation, Cassie is responsible for overseeing the cybersecurity strategy and ensuring the security of the company's products and services. With a wealth of experience from her leadership roles at well-k...

EP 24 — Innovating Application Security with Industry Expert Eric Sheridan 28.03.2023

In this special episode of the Future of Application Security, Harshil interviews Eric Sheridan , Tromzo’s recently appointed Chief Innovation Officer. Eric shares his 20-year journey in security, from his teenage encounter with Punters (little apps that would flood the target with AIM messages and knock them offline) to developing innovative security technologies at companies including WhiteHat S...

Ep 23 — Martin Nystrom: How Lumen Scales Product Security 16.03.2023

In this episode, Harshil is joined by Martin Nystrom , Vice President Of Product Security at Lumen .  Lumen is the world’s largest provider of communications, network services, and cloud security solutions. The Lumen platform enables companies to capitalize on emerging technologies and next-gen business applications, offering simplified security solutions that allow their customers to shift their...

Ep 22 — How to Find the Right Balance Between Compliance and Security with KnowBe4’s Senior Director of Product Security, Bradley Petzer 02.03.2023

KnowBe4 is the world's largest integrated Security Awareness Training and Simulated Phishing platform. KnowBe4’s training program is designed to help organizations address their most pressing IT security issues. With proper security awareness training, teams are able to make better security decisions, and help build a strong security culture within their organization.   In this episode, Harshil ch...

EP 21 — Red Hat’s Emmy Eide on How To Build A Strong Software Supply Chain Security Program 15.02.2023

In this episode, Harshil chats with Emmy Eide , Director of Product Security at Red Hat , a leading provider of open source software solutions that enable enterprises to seamlessly work across various platforms and environments. Emmy shares how she came to lead the team handling software supply chain security at Red Hat, and gives us a look into what makes for a good software supply chain security...

EP 20 — Naomi Buckwalter: Closing the Demand Gap in Cybersecurity and Building Diverse Teams 18.01.2023

In this episode, Harshil is joined by Naomi Buckwalter, Director of Product Security at Contrast Security. Contrast Security is an application security platform that helps developers and security teams write secure code and protects business applications against targeted cybersecurity attacks. The Contrast platform is able to effectively identify actual vulnerabilities from false positives, result...

EP 19 — Kevin Paige, CISO: How Supply Chain Company Flexport Scales AppSec 05.01.2023

Technology has been growing by leaps and bounds but most supply chain processes for shipping, storing, and trading goods have remained fragmented. Flexport is the first to connect the entire ecosystem of global trade, empowering buyers, sellers and logistics providers to grow and innovate. Flexport’s platform sets a new standard for global trade by simplifying supply chain management. In this epis...

EP 18 — Daniel Wood, CISO: How Unqork Scales Product Security 14.12.2022

Unqork is a no-code application platform that helps large enterprises rapidly build complex custom software by completely removing the usual development challenges of a traditional code-based approach. In this episode, Harshil chats with Unqork’s Chief Information Security Officer, Daniel Wood , to learn more about how he’s helped build and scale the company’s product security program. Daniel has...

EP 17 — SolarWinds VP of Security Tim Brown: Behind the Scenes of the 2020 SolarWinds Breach 30.11.2022

Those in IT, DevOps, and SecOps are all too familiar with the demands of a complex and dynamic technological landscape. For more than two decades, SolarWinds has helped technology professionals and organizations manage and adapt to an ever-expanding ecosystem of IT applications and infrastructure.  In this episode, Tim Brown , Vice President of Security at SolarWinds, gives us an insider view of t...

EP 16 — Mukund Sarma: How Chime Built a Scalable Product Security Program 09.11.2022

Chime, one of the fastest growing players in the financial technology space, has a mission of providing financial stability for their customers by eliminating many of the issues that come with traditional banking. In today’s episode, Mukund Sarma, Director of Product Security at Chime , shares how he helps his team address the challenges in building security programs, and maintaining a solid and p...

EP 15 — Tejpal Garhwal: How Pegasystems Scales AppSec 26.10.2022

Pegasystems’ Pega Platform is a powerful low-code platform for AI-powered decisioning and workflow automation. The platform makes it easier for enterprises to work smarter, unify experiences, and quickly adapt. As a publicly traded company with a multi-billion dollar market cap,  more than 6,000 employees, and a global customer base, security is critical to the success of the company.  In this epi...

EP 14 — Mark Stanislav: How FullStory Continuously Measures and Improves Its Product Security Maturity 12.10.2022

FullStory’s mission is to equip organizations with the information they need to deliver perfect digital experiences. To deliver on that mission, their platform captures customer experience data based on understanding browser interactions. In order to capture that data, it must have a position on the end user’s browser which requires a high level of customer trust.  To ensure its service is deliver...

Ep 13 — Daniel Harvey: How to Shift from Application Security to Product Security 28.09.2022

The pace of software development has increased dramatically over the past ten years and the traditional approach to application security has struggled to keep up. With modern development going from code to cloud within hours, manual security checks and  code reviews run the risk of slowing down releases and creating more tension between developers and security teams.  To reduce this friction, orga...

EP 12 — Rajat Bhargava: How Stripe Built a Highly Scalable AppSec Program 14.09.2022

Stripe is the most valuable private startup in the United States with a market valuation of more than $95 billion. With more than 2 million customers spread across 46 countries and nearly 10,000 employees, the scale of Stripe is hard to fathom. To retain its position as the market leader, Stripe must continue to rapidly ship new products while at the same time ensuring those products are secure. ...

EP 11 - Anshuman Bhartiya: Lessons From Building Thirty Madison’s Product Security Program 24.08.2022

Thirty Madison is a healthcare technology company that offers direct-to-consumer healthcare and wellness products for people living with chronic conditions. Founded in 2017, the company has raised over $200 million in funding and has more than 400 employees.  As a healthcare company with millions of customers, Thirty Madison has the responsibility of holding their customers' most personal informat...

Listen to the Future of Application Security podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.