The Elephant in AppSec
The Elephant in AppSec
Time to discuss AppSec issues no one talks about.
Author
The Elephant in AppSec
Category
Podcast website
Latest episode
May 20, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Risk, Product Management, and Supply Chain Security: Is There a Connection? ⎜Jesus Cuadrado 04.12.2024 49:25
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room. Today, I’m thrilled to welcome Jesus Cuadrado to the show! Jesus is the Chief Product Officer at Xygeni, an ASPM platform focused on improving software supply chain security. With over a decade of experience in product management, he’s now leading the charge in creating user-frie...
How hard is it to make DevSecOps work in a Hybrid Cloud? ⎜Michael Tayo 02.12.2024 49:29
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room. Today, I’m thrilled to welcome Michael Tayo to the show! As the Information Security Lead at EDX Markets, Michael advises C-suite leaders and drives strategies to protect critical infrastructure in institutional crypto markets. With prior roles in Financial Services and Tempus AI...
Is It Possible to Maximize the Effectiveness of Security Champions? ⎜ Magdalena Modric 25.11.2024 46:21
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room. Today, I’m thrilled to welcome Magdalena Modric to the show! Magdalena is an AppSec Program Strategist at Secure Code Warrior, where she’s been empowering developers in the German-speaking market to build secure applications since 2018. Beyond her professional expertise, Magdalen...
Hacker Turned Policy Builder: What They Don’t Want You to Know 15.11.2024 55:32
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room. Today, I’m thrilled to welcome Patrick Mathieu to the podcast! Patrick is currently a Senior Manager of Product Security at DoorDash, but his impact on the cybersecurity world spans years. Fifteen years ago, he founded Hackfest.ca , Canada's largest bilingual infosec conference...
Why Is Transforming Company Culture for Product Security So Challenging? ⎜ Ariel Shin 30.10.2024 47:47
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room. Today, I’m super excited to have Ariel Shin on the podcast! Ariel started as a pentester, moved into appsec, and now she’s a Security Engineering Manager at Datadog. Before that, she led the Product Security team at Twilio, where she led an effort to democratize vulnerability man...
The API Governance Problem: Why Your API Security Is at Risk (And How to Fix It) ⎜Akansha Shukla 23.10.2024 42:38
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room. Today, I’m excited to welcome Akansha Shukla, a cybersecurity expert with over 10 years of experience, currently specializing in API security at ABN AMRO, one of the largest banks in the Netherlands. Akansha has a strong background in application security, DevSecOps, threat model...
AI Chatbots: Security Disaster or Can We Build Them Securely? ⎜Ante Gojsalic & Benjamin Dulieu 15.10.2024 49:56
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room. Today, I have two incredible guests with me: Ante Gojsalic and Benjamin Dulieu. Ben is a Chief Information Security Officer at Duck Creek Technologies, an Insurance SaaS provider supporting the end-to-end insurance process for many of the world’s largest carriers. A former U.S. M...
Open Source vs. Commercial Software: The Ultimate Showdown⎜Kyle Kelly 10.10.2024 48:54
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room. Today, my guest is Kyle Kelly, Tech Lead for Supply Chain Security Research at Semgrep and the founder of the CramHacks weekly newsletter. You can subscribe here 👉 cramhacks.com With a background in consulting and research, he specializes in supply chain security, using his expe...
Privacy vs. Application Security: Can They Truly Coexist? | Kim Wuyts 01.10.2024 45:48
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room. Today, my guest is Kim Wuyts, a leading privacy engineering expert with over 15 years of experience in security and privacy. Before joining PwC Belgium as Manager of Cyber & Privacy, Kim was a senior researcher at KU Leuven, where she led the development and extension of LIND...
From PhD to AppSec: How to Bridge the Gap Between Research & Security Tools | Diego Sempreboni 24.09.2024 42:25
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room. Today, I’m joined by Diego Sempreboni, a Senior Application Security Engineer at Pleo. Diego earned his PhD in Computer Science, specializing in security, at King’s College London. After realizing his passion lay in solving real-world problems, he transitioned from academia to pr...
AppSec for Startups: Critical or Overlooked? | Rob Picard 20.09.2024 49:50
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room. Today, my guest is Rob Picard. Rob started his career as a pentester and went on to become an early security hire at both Robinhood and Vanta, where he helped establish scalable security programs. He is now leading Observa, a security consulting firm focused on helping startups b...
What are the risks associated with open source? | Kaiwen Jiang 12.09.2024 39:35
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room. Today, my guest is Kaiwen Jiang, an Application Security Engineer at a financial services company in the UK. Her primary areas of focus are . She was previously a cybersecurity consultant at Deloitte. Kaiwen also runs a blog, AppSec Kiki, where she shares her knowledge with the c...
Season 2 The Elephant in AppSec Podcast Trailer 06.09.2024 1:25
Get ready for more bold opinions starting next week! 🔥
AI Security - How hard is it to develop secure AI? ⎪Rob van der Veer 07.07.2024 49:51
Today, we have an amazing guest, Rob van der Veer, joining us. Rob is an AI pioneer with 32 years of experience, specializing in engineering, security, and privacy. Currently, he is a Senior Principal Expert at the Software Improvement Group (SIG), where he leads global thought leadership, advisory, and innovation in AI and software security. Rob is the lead author of the ISO/IEC 5338 standard on...
We Don’t Let the Bad Guys Win: Is It Possible with All Third-Party Apps in Oil & Gas? ⎜Catharina "DD" Budiharto 20.06.2024 48:59
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room. Today, we have an amazing guest, Catharina "DD" Budiharto, joining us. DD has extensive experience in cybersecurity, having worked for several years with multiple Oil and Gas companies. She also served as the chairperson for the American Petroleum Institute (API) IT S...
Why “shift-left” isn’t good enough ⎪Chris Romeo 07.06.2024 55:45
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room. Today, we have an amazing guest, Chris Romeo, joining us. Chris has 26 years of experience in cybersecurity, having worked for 11 years at CISCO, founded his own security education company, Security Journey, and now Devici, an AI-infused collaborative threat modeling tool. Chris...
What are the Non-Human Identity challenges? ⎪Andrew Wilder and Amir Shaked 23.05.2024 44:05
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room. We have two incredible guests with us: Andrew Wilder and Amir Shaked. Andrew is the Retained Chief Security Officer at Community Veterinary Partners and the former Regional CISO for Nestle, where he spent 18 years shaping cybersecurity across the Americas, Asia, and Europe. Amir...
API Security: Are Vendors Just Blowing Smoke? ⎪David Homoney 21.05.2024 57:40
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room. Today, we have an amazing guest, David Homoney, join us. David is the newly appointed Sales Engineer at Apiiro. Before stepping into this role, he made significant contributions as a Technical Solutions Architect II for Application, API, and Workload Security at World Wide Techno...
The Truth About Software Supply Chain Risks ⎪Cassie Crossley 10.05.2024 47:33
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room. Today, we’re excited to have an amazing guest, Cassie Crossley, join us. Cassie is the Vice President, Supply Chain Security in the global Cybersecurity & Product Security Office at Schneider Electric. Starting from a development background, she moved through different roles...
How secure are your digital wallets? ⎪Max Imbiel (Bitpanda) 29.04.2024 52:26
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room. Today we’re excited to have an amazing guest, Max Imbiel, join us. Max is the driving force behind “Ahead Security,” an agency specializing in vCISO activities, and currently serves as the CISO at BitPanda, an online crypto trading platform. Max’s career began in IT and software...
How security research can earn you $20m in tokens ⎪Swan Beaujard 29.04.2024 29:39
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room. Today we’re excited to have an amazing guest, Swan Beaujard, join us. Swan is a security software engineer at Escape, specializing in Dynamic Application Security Testing. He is a core contributor to a lot of open-source projects related to GraphQL security and is passionate abo...
Securing cloud native applications: how hard is it? ⎪Mihir Shah 12.04.2024 56:54
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room. Today we’re excited to have an amazing guest, Mihir Shah, join us. Mihir Shah is a Senior Staff Application Security Engineer at ForgeRock, specializing in architecting secure cloud-based Identity & Access Management services hosted using Kubernetes and Google Cloud Platfor...
Are custom security tests a product security superpower? ⎜Keshav Malik (LinkedIn) 01.04.2024 23:42
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room. Today we’re excited to have an amazing guest, Keshav Malik, join us. Keshav is a Senior Product Security Engineer at LinkedIn. With experience in information security and a passion for automation, Keshav brings a unique blend of expertise to the table. Keshav is also a dedicated...
The art and science of product security ⎥Jacob Salassi (Snowflake) 21.03.2024 49:53
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room. Today we’re excited to have an amazing guest, Jacob Salassi, join us. Jacob is the Director of Product Security and Regulatory Expansion at Snowflake, where he has played a pivotal role in guiding the company through its pre- and post-IPO phases. With over 15 years of experience,...
Security Consultant vs. In-House Engineer: The Showdown⎜Ric Campo 05.03.2024 40:33
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room. Today we’re excited to have an amazing guest, Ric Campo, join us. Ric started his cybersecurity journey in the Royal Australian Air Force. With a decade of dedicated experience as an Application Security Engineer and Penetration Tester, he currently serves as a Principal Security...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.