Find partners
The Application Security Podcast

The Application Security Podcast

Hosted by Chris Romeo and Robert Hurlbut

TechnologyNewsEducationInterviews guests

Episodes

306

Latest episode

Aug 2026

Language

EN-US

About the show

The Application Security Podcast is a practitioner-led show for anyone building or securing modern software—and now AI-powered applications. Hosts Chris Romeo and Robert Hurlbut talk with the people shaping application security about AI and LLM security, threat modeling, secure development, OWASP, cloud, DevSecOps, security champions, and building programs that help engineering teams move faster and safer. With more than 300 episodes, the show turns real-world experience into practical guidance for developers, architects, AppSec professionals, and security leaders.

Listen to episodes

60 recent
September 7, 2026Episode 1148 min

Your AppSec Bottleneck Is a People Problem

What makes a security champions program successful—and why do so many fail? Lisi Hocke explains how psychological safety, cognitive load, power sources, and community can help create sustainable programs. We also explore reducing security wait times, gaining organizational support, the role of AI, why champions meetings shouldn’t be recorded, and the importance of putting people first. This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it. Learn more at Corgea.com . About Corgea Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely. Learn more about Corgea . FOLLOW US ON SOCIAL MEDIA: ➜ X: @AppSecPodcast ➜ LinkedIn: The Application Security Podcast ➜ YouTube: @ApplicationSecurityPodcast ➜ Instagram: @appsecpodcast ➜ Facebook: Application Security Podcast ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

August 31, 2026Episode 1043 min

AI Pen Testing Killed Traditional DAST

Is traditional DAST finally dead? James Berthoty explains how AI pentesting is changing the dynamics of security testing through contextual payloads, autonomous agents, and application-aware vulnerability discovery. We also explore token costs, AI-native security vendors, the future of bug bounties, testing in production, and whether model providers could eventually absorb today’s security tools. This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it. Learn more: https://bit.ly/4wMCNUf About Corgea Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely. Learn more about Corgea → https://bit.ly/4wMCNUf FOLLOW US ON SOCIAL MEDIA: ➜ X: @AppSecPodcast ➜ LinkedIn: The Application Security Podcast ➜ YouTube: @ApplicationSecurityPodcast ➜ Instagram: @appsecpodcast ➜ Facebook: Application Security Podcast ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

August 26, 2026Episode 947 min

AI Security: OWASP Meets Global Standards

AI security has no shortage of standards—but how do we turn them into practical guidance? Rob van der Veer explains how OWASP, the AI Exchange, and MOSAIC are coordinating global AI security efforts. We also explore responsible AI, agentic red teaming, vulnerability discovery, and how AI could level the playing field between attackers and defenders. This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it. Learn more: Corgea.com About Corgea Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely. Learn more about Corgea → https://bit.ly/4wMCNUf FOLLOW OUR SOCIAL MEDIA: ➜ Twitter: @AppSecPodcast ➜ LinkedIn: The Application Security Podcast ➜ YouTube: @ApplicationSecurityPodcast FOLLOW US ON SOCIAL MEDIA: ➜ X: @AppSecPodcast ➜ LinkedIn: The Application Security Podcast ➜ YouTube: @ApplicationSecurityPodcast ➜ Instagram: @appsecpodcast ➜ Facebook: Application Security Podcast ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

August 17, 2026Episode 840 min

The Future of Open-Source Threat Modeling

This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it. Learn more: Corgea.com You don’t have to let AI do the thinking for you. In this episode, Vikram shares why the smartest teams use AI as an accelerant — not a replacement — and why human judgment still matters most in threat modeling. We dig into the tension among speed, compliance, and real risk, and what it means to “fight the AI” so that critical thinking stays sharp. If you care about AppSec, AI, and the future of threat modeling, this conversation will give you a lot to think about. About Corgea Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting — helping security and engineering teams find risk earlier, fix what matters, and ship securely. Learn more about Corgea → Corgea.com FOLLOW US ON SOCIAL MEDIA: ➜ X: @AppSecPodcast ➜ LinkedIn: The Application Security Podcast ➜ YouTube: @ApplicationSecurityPodcast ➜ Instagram: @appsecpodcast ➜ Facebook: Application Security Podcast ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

July 28, 2026Episode 749 min

Isaac Evans - AppSec in the Age of AI

In this episode, we sit down with Isaac Evans, co-founder and CEO of Semgrep, to talk about how AI is reshaping application security faster than almost anyone expected. Isaac walks us through why CI is losing its place as the central security control point, replaced by deep background jobs that hunt for vulnerabilities using large models and real-time plugins that sit inside coding agents and force them to regenerate code until it meets an organization's security bar. We dig into what this means for the role of the security engineer, why customization is replacing universal rule sets, and how trust, verification, and the limits of reasoning about model behavior remain the hardest problems in the room. We also talk about vibe coding at scale, the return of business logic flaws as SQL injection becomes easier for models to catch, and why Isaac sees more opportunity than threat in this shift, even as he expects a wave of new vulnerabilities and cleanup work along the way. FOLLOW US ON SOCIAL MEDIA: ➜ X: @AppSecPodcast ➜ LinkedIn: The Application Security Podcast ➜ YouTube: @ApplicationSecurityPodcast ➜ Instagram: @appsecpodcast ➜ Facebook: Application Security Podcast ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

July 21, 2026Episode 852 min

José Carlos Chávez - When Museums Get Hacked: OWASP Top 10 Lessons from Heists

In this episode, we sit down with Jose Carlos Chavez from Okta to break down the OWASP Top 10 for 2025 and what actually changed since 2021. We trace Jose's path from software engineering and observability into security, dig into why broken access control still holds the number one spot despite mature tooling, and ask the question that never seems to get old: why is injection still a top five risk after decades of parameterized queries and ORMs? Jose walks us through the growing role of supply chain and software integrity failures, the surprisingly weak security posture around AI skills and agent permissions, and why immutable, reliable logging still matters as much as ever. We close on root causes that show up across nearly every category on the list and why ownership, not tooling alone, is what actually moves the needle on security. FOLLOW US ON SOCIAL MEDIA: ➜ X: @AppSecPodcast ➜ LinkedIn: The Application Security Podcast ➜ YouTube: @ApplicationSecurityPodcast ➜ Instagram: @appsecpodcast ➜ Facebook: Application Security Podcast ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

June 16, 2026Episode 648 min

Michael Burch - AI-Enabled Citizen Developers

AI adoption is accelerating faster than most organizations know how to handle it, and the gap between curiosity and confident use is where things go wrong. Michael Burch, VP of AI Enablement and Acceleration, joins to break down what it actually takes to move teams from "interested in AI" to using it responsibly and effectively in their day-to-day work. He shares why successful adoption depends less on the technology itself and more on trust, clear guidance, and making AI approachable for non-technical teams. Whether you are leading an AI initiative or just trying to figure out where to start, this episode is a practical look at what real adoption looks like inside organizations today. FOLLOW US ON SOCIAL MEDIA: ➜ X: @AppSecPodcast ➜ LinkedIn: The Application Security Podcast ➜ YouTube: @ApplicationSecurityPodcast ➜ Instagram: @appsecpodcast ➜ Facebook: Application Security Podcast ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

June 2, 2026Episode 540 min

Josh Grossman--AI & SAST: Is it a match?

AI coding tools are accelerating development fast, but they’re also exposing the limits of traditional AppSec tooling. Josh Grossman, CTO of Bounce Security and longtime AppSec consultant, joins the podcast to break down AGHAST, his new open-source security tool that combines static analysis with AI to uncover business logic flaws and authorization issues that traditional scanners miss. FOLLOW US ON SOCIAL MEDIA: ➜ X: @AppSecPodcast ➜ LinkedIn: The Application Security Podcast ➜ YouTube: @ApplicationSecurityPodcast ➜ Instagram: @appsecpodcast ➜ Facebook: Application Security Podcast ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

May 14, 2026Episode 445 min

Dwayne McDaniel -- Secrets Sprawl and How AI is Impacting Secrets

GitGuardian found 29 million hard-coded secrets leaked in public GitHub commits in a single year, a 34% jump and the biggest spike they've ever recorded. Dwayne McDaniel joins to break down why AI coding tools, MCP servers, and a false sense of security in private repos are making the problem worse, and what it'll actually take to fix it. Check out the report here - https://www.gitguardian.com/files/the-state-of-secrets-sprawl-report-2026 . Dwayne McDaniel is a Principal Developer Advocate who has been on a mission to "help people figure stuff out" for over a decade. At GitGuardian, he specializes in secrets security and non-human identity governance across cloud and DevOps environments. FOLLOW US ON SOCIAL MEDIA: ➜ X: @AppSecPodcast ➜ LinkedIn: The Application Security Podcast ➜ YouTube: @ApplicationSecurityPodcast ➜ Instagram: @appsecpodcast ➜ Facebook: Application Security Podcast ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

April 30, 2026Episode 347 min

Tanya Janca - Secure Vibe Coding

AI isn’t just helping developers anymore; it’s writing the code, and that changes everything. In this episode, Tanya Janca breaks down “vibe coding,” the hidden security risks behind it, and how teams need to rethink AppSec from the ground up. If you’re building with AI, this is the wake-up call you can’t afford to miss. Tanya Janca, AKA SheHacksPurple, is an author, founder, trainer, speaker, software developer, but most of all, a nerd obsessed with security. She speaks and teaches secure coding worldwide and through her podcast, DevSec Station. Check it out here: https://www.youtube.com/@DevSecStation FOLLOW US ON SOCIAL MEDIA: ➜ X: @AppSecPodcast ➜ LinkedIn: The Application Security Podcast ➜ YouTube: @ApplicationSecurityPodcast ➜ Instagram: @appsecpodcast ➜ Facebook: Application Security Podcast ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Is this your show?

Claim this listing to keep it up to date, reach guests who want to pitch you, and manage bookings with Guestify.

Claim this listing

More Technology podcasts