Home Podcasts The Application Security Podcast
The Application Security Podcast

The Application Security Podcast

Chris Romeo and Robert Hurlbut 301 Episodes Jun 16, 2026

Chris Romeo and Robert Hurlbut explore the strategies, projects, and tactics that make application security professionals successful. They cover topics like threat modeling, OWASP, DevSecOps, and security champions, explaining details in an educational way for newcomers. Chris Romeo is CEO of Devici and a General Partner at Kerr Ventures, while Robert Hurlbut is a Principal Application Security Architect at Aquia.

Episodes

Michael Burch - AI-Enabled Citizen Developers Jun 16, 2026 2938 AI adoption is accelerating faster than most organizations know how to handle it, and the gap between curiosity and confident use is where things go wrong. Michael Burch, VP of AI Enablement and Acceleration, joins to break down what it actually takes to move teams from "interested in AI" to using it responsibly and effectively in their day-to-day work. He shares why successful adoption
Josh Grossman--AI & SAST: Is it a match? Jun 2, 2026 2429 AI coding tools are accelerating development fast, but they’re also exposing the limits of traditional AppSec tooling. Josh Grossman, CTO of Bounce Security and longtime AppSec consultant, joins the podcast to break down AGHAST, his new open-source security tool that combines static analysis with AI to uncover business logic flaws and authorization issues that traditional scanners miss. FOLLOW OUR
Dwayne McDaniel -- Secrets Sprawl and How AI is Impacting Secrets May 14, 2026 2727 GitGuardian found 29 million hard-coded secrets leaked in public GitHub commits in a single year, a 34% jump and the biggest spike they've ever recorded. Dwayne McDaniel joins to break down why AI coding tools, MCP servers, and a false sense of security in private repos are making the problem worse, and what it'll actually take to fix it. Check out the report here - https://www.gitguardi
Tanya Janca - Secure Vibe Coding Apr 30, 2026 2877 AI isn’t just helping developers anymore; it’s writing the code, and that changes everything. In this episode, Tanya Janca breaks down “vibe coding,” the hidden security risks behind it, and how teams need to rethink AppSec from the ground up. If you’re building with AI, this is the wake-up call you can’t afford to miss. Tanya Janca, AKA SheHacksPurple, is an author, founder, trainer, speaker, sof
Caroline Wong--The AI Cybersecurity Handbook Apr 21, 2026 2693 Caroline Wong, author of The AI Cybersecurity Handbook and Chief Strategy Officer at Axari, is back! Caroline shares how AI is rapidly changing AppSec, driving massive increases in code, accelerating risk, and challenging traditional security practices. The conversation covers AI-generated code, trust and explainability, and how security teams must adapt to keep up.FOLLOW OUR SOCIAL MEDIA:➜Twitter
Steve Wilson--OpenClaw and Advanced AI Agents Apr 15, 2026 2970 In this episode of the Application Security Podcast, Chris Romeo and Robert Hurlbut welcome back Steve Wilson, a global leader in AI security and Chief AI and Product Officer at Exabeam, as well as founder of the OWASP Gen AI Security Project.Steve shares how his AI assistant was “hacked” using a simple phishing attack, highlighting a major shift in security—AI agents behave more like humans than
Brad Geesaman - Redefining AppSec with AI: Shrinking Toil, Expanding Impact - How LLMs are able to reduce toil in triage-heavy AppSec workflows Oct 28, 2025 2539 Brad Geesaman, Principal Security Engineer at Ghost, joins the podcast today to explore how AI and large language models are transforming the world of application security. The discussion starts with the concept of "toil"—the repetitive, exhausting work that drains AppSec teams as they struggle to keep up with mountains of security findings and alerts. Brad shares his insights on how LLM
OWASP Candidate Debate - 2025 Edition Oct 15, 2025 4089 In this special episode of the Application Security Podcast we meet nine of the OWASP Board of Directors candidates. Each candidate discusses their unique qualifications, experiences, and vision for OWASP's future. Topics include enhancing OWASP's impact, improving outreach and education, securing funding, and engaging local chapters. Don't miss this insightful debate as these candi
Francesco Cipollone - Agentic AI Manifesto Sep 23, 2025 1999 Francesco Cipollone, the CEO of Phoenix Security, shares his extensive experience in AI and security, discussing the crucial difference between true AI agents and glorified chatbots. Learn why Phoenix Security utilizes six different LLMs instead of a single super agent. Understand the sobering economics behind AI implementation and the importance of adopting AI responsibly. Get practical advice on
Simon Gibbs & Devika Gibbs -- Building Bridges with Games Sep 16, 2025 2163 Simon and Devika Gibbs, the innovative minds behind Cybersec Games, join us on the episode today. Discover how the Gibbs duo are revolutionizing the way we teach and learn security concepts through interactive gaming. Learn about their journey from developing stationary for agile teams to delving into the world of threat modeling games like Elevation of Privilege. We talk about the power of gamifi
Akansha Shukla - Modern AppSec: Securing APIs with Threat Modeling and DevSecOps Sep 2, 2025 2135 Our guest today is Akansha Shukla, an information security professional with over 10 years of experience in application security, DevSecOps, and API security. We’re discussing why API security remains one of the least mature areas of AppSec today and exploring the challenges developers face when securing APIs. Akansha shares her insights on incorporating APIs into threat modeling exercises, the on
Getting Ready for the EU CRA Aug 20, 2025 2446 The European Union's Cyber Resilience Act is set to revolutionize how we approach product security worldwide. In this episode, we sit down with application security expert Nariman Aga-Tagiyev to break down everything you need to know about this legislation. Nariman has over 20 years of software development experience and today he’s sharing his expertise with us. Learn what the EU CRA is and w

Recommended