Security Compass

Threat Modeling Unleashed

Education EN ↓ 91 episodes

Security Compass, a leading provider of cybersecurity solutions and advisory services, enables organizations to adopt balanced development automation for rapid and secure application development. With their flagship product, SD Elements, the company helps automate significant portions of proactive manual processes for security and compliance that improves time to market for new technology. In addition, they offer advisory services on how organizations can embrace emerging technologies like cloud to strengthen their security posture. Security Compass is the trusted solution provider to leading...

Author

Security Compass

Category

Education

Podcast website

podcast.securitycompass.com

Latest episode

Dec 2, 2025

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Malu Septien Milan - Aligning Security to Business Value 30.08.2021

Today we are joined by Malu Septien Milan, President of Cryptopon, to talk about tying security to business value. We will start by explaining the gap between security and business expectations. This has an impact on how security teams scale as they become increasingly relevant in business operational risk where DevOps is driving “continuous everything”. We will then round off the discussion by tu...

Jack Freund - Aligning Cyber Security Risk With Business Value 23.07.2021

Today we are joined by Jack Freund, Head of Cyber Risk Methodology at VisibleRisk , to talk about cyber security risk and business value. We will start by discussing the gap between cyber security and business value. In bridging these two domains, we eventually need to consider different risk models. We will discuss cyber security risk modeling approaches and challenges. We will then conclude by l...

Leaders in Product Security - John Deskurakis 09.07.2021

Leaders in Product Security: In the eleventh episode of this series, we are joined by John Deskurakis, Chief Product Security Officer, Carrier Global Corporation , to talk about how Carrier tackles some of the unique challenges they face with product security, as well as the critical role of cold storage for COVID-19 vaccinations. During this discussion, he also highlights how "shift left" is ofte...

Leaders in Product Security - Sean Poris 11.06.2021

Leaders in Product Security: In the eleventh episode of this series, we are joined by Sean Poris, Director, Product Security at Verizon Media , to talk about the role of engineering in a service organization. We will discuss the evolving pace of software development, the critical contributions of security champions, and balancing security by design with security assurance.

Paul Breitbarth - Injecting Privacy Regulations into DevOps 04.06.2021

Today we are joined by Paul Breitbarth, Director, Global Policy & EU Strategy at TrustArc , to talk about integrating privacy into software development. We will start by educating you about the process of privacy impact assessment which will help us understand how to bridge the gap between privacy and DevOps. The inherent cross-functional nature of balancing speed and privacy necessitates early in...

Ayhan Tek - Scaling Threat Modeling to Achieve Software Development Compliance 14.05.2021

Today we are joined by Ayhan Tek, VP of Information Security at Cyber Electra , to talk about how a security practitioner can help support compliance related security activities in software development. In order to make threat modeling scalable, the cross-functional nature of software development needs to extend beyond data flow diagrams into the business realm. Once in the business domain, the di...

Spencer Koch - Scale Your Threat Modeling Beyond STRIDE and Data Flow Diagrams 30.04.2021

Today we are joined by Spencer Koch, Offensive Security Professional at Reddit , to talk about threat modeling and the issues with scaling the traditional processes. These days, we don’t have enough security practitioners to perform threat modeling on every system. In many cases, there is also an emphasis on trying to achieve perfection instead of doing what’s “good enough.”  In this episode, we d...

Leaders in Product Security - Timo Skytta 16.04.2021

Leaders in Product Security: In the tenth episode of this series, we are joined by Timo Skytta, Managing Director, Head of Advisory (Security) at Goldman Sachs, to talk about his experience with workload, priority management, and automation. We will delve into what problem their company was trying to solve, the challenges they ran into, unexpected pushback from the stakeholders, and how they align...

Leaders in Product Security - David Lenoe 09.04.2021

Leaders in Product Security: In the ninth episode of this series, we are joined by David Lenoe, Director, Secure Software Engineering at Adobe , to talk about product security and its evolution at Adobe. David will also share his insights on working with engineering teams, the importance of security champions, and why compliance is not necessarily a barrier to security.

Leaders in Product Security - Matthew Bohne 02.04.2021

Leaders in Product Security: In the eighth episode of this series, we are joined by Matthew Bohne, Vice President and Chief Product Security Officer for Honeywell Corporation , to talk about the unique challenges of running a security program at a global scale. Drawing on his experience in leading one of the largest product security teams globally, he shares his thoughts on emerging regulatory sta...

Leaders in Product Security - Sudharma Thikkavarapu 26.03.2021

Leaders in Product Security: In the seventh episode of this series, we are joined by Sudharma Thikkavarapu to talk about product, application, and cloud security. He shares his perspectives on software-defined infrastructures and how it impacts the way we think about security. He also throws light on what it takes to make product security successful, including how to evolve security thinking to ke...

Leaders in Product Security - Khaja Ahmed 19.03.2021

Leaders in Product Security: In the sixth episode of this series, we are joined by Khaja Ahmed, Sr. VP, Product and Application Security at SAP, who shares his unique insights from working in the cloud security space with companies like Amazon, Microsoft, and Google. We will talk about the impact of reporting structure on product security, differences between start-ups and enterprises, and how pro...

Leaders in Product Security - Janne Uusilehto 12.03.2021

Leaders in Product Security: In the fifth episode of this series, we are joined by Janne Uusilehto, Lead Privacy PgM at Google , to gain insights into product security as he shares his experiences from the early days of mobile device security. We will also discuss how product security has evolved over the years and the progress being made by organizations with the changes in this space.

John Weigelt - Check Your Security Biases When Deploying IoT and Hardware 08.03.2021

Today we are joined by John Weigelt, Lead for Microsoft Canada’s Strategic Policy and Technology Efforts , to talk about IoT and Hardware Security from a security executive’s perspective. We will start by looking at the context of IoT and hardware products and the importance of not getting biased toward an exclusively desktop computing frame of reference. We will then discuss how security teams ca...

Leaders in Product Security - Jason Christman 05.03.2021

Leaders in Product Security: In the fourth episode of this series, we are joined by Jason Christman, VP, Chief Product Security Officer at Johnson Controls. Jason is a recognized champion of the Chief Product Security Officer (CPSO) role. In this podcast we discuss the role and its core responsibilities, top priorities, and compare the role with the Chief Information Security Officer (CISO). We al...

Leaders in Product Security - Laksh Raghavan 26.02.2021

Leaders in Product Security: In the third episode of this series, we are joined by Laksh Raghavan, Head of Product, Platform and Enterprise Security at LinkedIn ,he explains how cross-disciplinary thinking — specifically behavioral science and systems thinking are critical to driving success in product security. Laksh also shares how he has successfully driven developer buy-in for security, and ho...

Tony Carrato - Address Key Security Concerns around IoT and Hardware Products 22.02.2021

Today we are joined by Altaz Valani from Security Compass and Tony Carrato , an Independent Architecture Consultant, to talk about IoT and Hardware Security from a security executive’s perspective. We will start the discussion by talking about the top security challenges with IoT and hardware products, such as emerging standards, data movement, and default passwords. We will then turn our attentio...

Leaders in Product Security - Brad Arkin 19.02.2021

Leaders in Product Security: In the second episode of this series, we are joined by Brad Arkin , Senior Vice President, Chief Security and Trust Officer, Cisco, who shares his unique insights from his extensive experience in product, and more holistically, information security. In this podcast, we are going over the major shifts in product security, how we might solve the talent gap, and what role...

Leaders in Product Security - Steve Lipner 12.02.2021

Leaders in Product Security: In the first episode of this series, we are joined by Steve Lipner, Executive Director of SAFECode , who is inarguably one of the most experienced and prolific specialists in product security. We will talk about how Steve got into software security, the impact of Bill Gates' famous Trustworth Computing Memo, how consumers and businesses can assess a vendor's product se...

Spencer Koch - Cloud Security is not about Starting from Scratch 05.02.2021

Today we are joined by Spencer Koch, Offensive Security Professional at Reddit , to talk about cloud enablement from a security practitioner’s perspective. We will start by looking at how security teams can help with creating a culture around cloud enablement. We will then look deeper into the guardrails and metrics, and whether current security metrics still apply to the cloud. And, finally, we w...

Ayhan Tek - How Security Teams Can Enable Cloud Adoption 29.01.2021

Today we are joined by Ayhan Tek, VP of Information Security at Cyber Electra , to talk about how a security practitioner can help enable cloud adoption for their organization. From a cultural standpoint, we will discuss the role of security practitioners in enabling cloud adoption as well as some common pitfalls around cloud security. And, finally, given our rapid delivery CI/CD pipelines, we wil...

David A. Wheeler - Security Lessons From a Rapidly Evolving Open Source Ecosystem 22.01.2021

Today we are joined by David Wheeler , Director of Open Source Supply Chain Security at the Linux Foundation, to talk about securing open source software. We will start with a brief discussion on the “2020 FOSS Contributor Survey” report, co-authored by David. We will then delve deeper into some surprising insights from that report as it relates to the dynamic nature of fast-moving open source dev...

Wayne Howell - Managing Speed and Security Through Product Governance 15.01.2021

Today we are joined by Altaz Valani from Security Compass and Wayne Howell Jr. , Cyber Security Process & Governance Leader at Honeywell, to talk about product security governance and bridging the gap between product and software security. We will talk about the similarities and differences between product and software security, particularly around the end — i.e. the post-deployment product suppor...

Katie Stewart - Developing the CMMC 08.01.2021

Today we are joined by Katie Stewart , co-author of CMMC and Senior Member of the Technical Staff within the CERT® Division at the Software Engineering Institute, to talk about the creation and ongoing evolution of CMMC. We will start by talking about the history of CMMC and the response received so far. We will then turn our discussion to the ongoing evolution of CMMC and ways that people can get...

Sesh Vaidyula & Harvey Nusz - CMMC in a Commercial Context 18.12.2020

Today we are joined by Altaz Valani from Security Compass, Sesh Vaidyula , Partner at Templar shield, and Harvey Nusz , Principal at 4IT Security, Governance & Compliance, to talk about CMMC in a commercial context, given its overlap with NIST 800-53, NISC CSF, and ISO 27001. We will also discuss its similarities with other non-maturity standards and regulations such as PCI, HIPAA, GDPR. To conclu...

Listen to the Threat Modeling Unleashed podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.