The Boring AppSec Podcast
The Boring AppSec Podcast
In this podcast, we will talk about our experiences having worked at different companies - from startups to big enterprises, from tech companies to security companies, and from building side projects to building startups. We will talk about the good, the bad, and everything in between. So join us for some fun, some real, and some super hot takes about all things Security in the Boring AppSec Podcast.
Author
The Boring AppSec Podcast
Category
Podcast website
Latest episode
Mar 11, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
S2E2 - Dustin Lehr 13.01.2025 48:52
In Season 2 Episode 2, we interview Dustin Lehr, Co-Founder, Chief Product & Technology Officer at Katilyst. We discuss the significance of security champions in application security. We explore the cultural aspects of implementing security champions programs, the challenges of maintaining engagement, and the importance of leadership support. The conversation delves into measuring the success...
S2E1 - Jimmy Mesta 06.01.2025 54:00
In Season 2 Episode 1, we interview Jimmy Mesta, a seasoned expert in application security and co-founder of RAD Security. We discuss the evolution of Kubernetes, its security challenges, and the importance of understanding the complexities of cloud-native infrastructure. Jimmy shares insights from his journey of starting a company, the role of AI in security, and the nuances of investing in secur...
S1E10 - Future Security Predictions 20.05.2024 50:41
Welcome to the Boring AppSec Podcast! In Episode 10, we discuss some security predictions that we hope to see in the near future. Some of them are: AI agents - different kinds - activity based and/or persona based Security talent is going to get better, hiring is important AI powered security engineers - up leveling junior engineers AI code review assistants - GPT4-o et al Company consolidations h...
S1E09 - Incidents 13.05.2024 37:48
Welcome to the Boring AppSec Podcast! In Episode 9, we discuss incidents. Both Sandesh and I share 2 incidents each and the lessons learnt from them. Tune in! References mentioned in the episode: Log4j - https://www.cisa.gov/news-events/news/apache-log4j-vulnerability-guidance Incident runbook - https://engineering.razorpay.com/how-an-incident-transformed-razorpay-improving-the-5-why-rca-format-37...
S1E08 - Bug Bounties Part 2 22.04.2024 45:45
Welcome to the Boring AppSec Podcast! In Episode 8, we continue discussing bug bounties from where we left off in Episode 3. We discuss how to build mature bug bounty programs, how to start a program, how to convince stake holders to start a program, differences and similarities between vulnerability disclosure programs and bug bounty programs among other things. Tune in! Contacting Anshuman Linke...
S1E07 - Hiring in Security 15.04.2024 54:59
Welcome to the Boring AppSec Podcast! In Episode 7, we discuss how to hire the right security folks on a security engineering team. We go over the interviewing process, what to look out for, how to compose a team, and also share some of our experiences of interviewing including some tips on what a candidate can/should do if they want to get noticed by hiring managers and recruiters. Contacting Ans...
S1E06 - Vulnerability Management 08.04.2024 56:41
Welcome to the Boring AppSec Podcast! In Episode 6, we discuss the art of Vulnerability Management. What it means, what are some of the problems we've seen as practitioners, what are some ways we've considered to make the process of managing vulnerabilities easy. References: We will try and add information about all the references we make here. Please enter rabbit holes at will :) Gitlab&...
S1E05 - Threat Modeling 01.04.2024 1:01:47
Welcome to the Boring AppSec Podcast! In Episode 5, we dig deep into what threat modeling is from a practitioner's perspective. We compare it with design reviews and discuss when/how/why of threat modeling. In the end, we wrap up by talking about how Gen AI could help threat modeling significantly. References: We will try and add information about all the references we make here. Please enter...
S1E04 - Running a lean AppSec team 25.03.2024 1:09:36
Welcome to the Boring AppSec Podcast! In Episode 4, we discuss how lean AppSec teams run and operate. We share our experiences of having worked in engineering heavy organizations where the "engineer : appsec-engineer" ratio is far from ideal and scaling the AppSec team becomes very important to be able to reasonably manage risk. References: We will try and add information about all the r...
S1E03 - Bug Bounties 18.03.2024 1:11:17
Welcome to the Boring AppSec Podcast! In Episode 3, we discuss all things bug bounties. The researcher side as well as the program owner's side. Enter at your own will as we have a lot of hot takes. References: We will try and add information about all the references we make here. Please enter rabbit holes at will :) Bug Bounty Platforms Bugcrowd - https://www.bugcrowd.com/ HackerOne - ht...
S1E02 - First Security Hire 11.03.2024 1:07:31
Welcome to the Boring AppSec Podcast! In Episode 2, we discuss what a first security hire responsibilities are. How do they prioritize? What do they prioritize? References: We will try and add information about all the references we make here. Please enter rabbit holes at will :) Building a product security program Some blogs on getting SOC2 certifications without too much redtape - RunReveal ,...
S1E01 - Asset Inventory 04.03.2024 44:56
Welcome to the Boring AppSec Podcast! In Episode 1, we discuss software inventories. What they are, why we need them, and what are our favorite ways to build them. References: We will try and add information about all the references we make here. Please enter rabbit holes at will :) Cartography - https://github.com/lyft/cartography GenAI + Cartography https://shinobi.security/#how-it-works...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.