Home Podcasts The Application Security Podcast
The Application Security Podcast

The Application Security Podcast

Chris Romeo and Robert Hurlbut 301 Episodes Aug 16, 2026

Chris Romeo and Robert Hurlbut explore the strategies, projects, and tactics that make application security professionals successful. They cover topics like threat modeling, OWASP, DevSecOps, and security champions, explaining details in an educational way for newcomers. Chris Romeo is CEO of Devici and a General Partner at Kerr Ventures, while Robert Hurlbut is a Principal Application Security Architect at Aquia.

Episodes

The Future of Open-Source Threat Modeling
The Future of Open-Source Threat Modeling Aug 16, 2026 2414 This episode is sponsored by Corgea.Design it. Build it. Ship it. Corgea secures it.Learn more: Corgea.comYou don’t have to let AI do the thinking for you. In this episode, Vikram shares why the smartest teams use AI as an accelerant — not a replacement — and why human judgment still matters most in threat modeling. We dig into the tension among speed, compliance, and real risk, and what it means
Isaac Evans - AppSec in the Age of AI
Isaac Evans - AppSec in the Age of AI Jul 28, 2026 2949 In this episode, we sit down with Isaac Evans, co-founder and CEO of Semgrep, to talk about how AI is reshaping application security faster than almost anyone expected. Isaac walks us through why CI is losing its place as the central security control point, replaced by deep background jobs that hunt for vulnerabilities using large models and real-time plugins that sit inside coding agents and forc
José Carlos Chávez - When Museums Get Hacked: OWASP Top 10 Lessons from Heists
José Carlos Chávez - When Museums Get Hacked: OWASP Top 10 Lessons from Heists Jul 21, 2026 3159 In this episode, we sit down with Jose Carlos Chavez from Okta to break down the OWASP Top 10 for 2025 and what actually changed since 2021. We trace Jose's path from software engineering and observability into security, dig into why broken access control still holds the number one spot despite mature tooling, and ask the question that never seems to get old: why is injection still a top five
Michael Burch - AI-Enabled Citizen Developers
Michael Burch - AI-Enabled Citizen Developers Jun 16, 2026 2938 AI adoption is accelerating faster than most organizations know how to handle it, and the gap between curiosity and confident use is where things go wrong. Michael Burch, VP of AI Enablement and Acceleration, joins to break down what it actually takes to move teams from "interested in AI" to using it responsibly and effectively in their day-to-day work. He shares why successful adoption
Josh Grossman--AI & SAST: Is it a match?
Josh Grossman--AI & SAST: Is it a match? Jun 2, 2026 2429 AI coding tools are accelerating development fast, but they’re also exposing the limits of traditional AppSec tooling. Josh Grossman, CTO of Bounce Security and longtime AppSec consultant, joins the podcast to break down AGHAST, his new open-source security tool that combines static analysis with AI to uncover business logic flaws and authorization issues that traditional scanners miss. FOLLOW OUR
Dwayne McDaniel -- Secrets Sprawl and How AI is Impacting Secrets
Dwayne McDaniel -- Secrets Sprawl and How AI is Impacting Secrets May 14, 2026 2727 GitGuardian found 29 million hard-coded secrets leaked in public GitHub commits in a single year, a 34% jump and the biggest spike they've ever recorded. Dwayne McDaniel joins to break down why AI coding tools, MCP servers, and a false sense of security in private repos are making the problem worse, and what it'll actually take to fix it. Check out the report here - https://www.gitguardi
Tanya Janca - Secure Vibe Coding
Tanya Janca - Secure Vibe Coding Apr 30, 2026 2877 AI isn’t just helping developers anymore; it’s writing the code, and that changes everything. In this episode, Tanya Janca breaks down “vibe coding,” the hidden security risks behind it, and how teams need to rethink AppSec from the ground up. If you’re building with AI, this is the wake-up call you can’t afford to miss. Tanya Janca, AKA SheHacksPurple, is an author, founder, trainer, speaker, sof
Caroline Wong--The AI Cybersecurity Handbook
Caroline Wong--The AI Cybersecurity Handbook Apr 21, 2026 2693 Caroline Wong, author of The AI Cybersecurity Handbook and Chief Strategy Officer at Axari, is back! Caroline shares how AI is rapidly changing AppSec, driving massive increases in code, accelerating risk, and challenging traditional security practices. The conversation covers AI-generated code, trust and explainability, and how security teams must adapt to keep up.FOLLOW OUR SOCIAL MEDIA:➜Twitter
Steve Wilson--OpenClaw and Advanced AI Agents
Steve Wilson--OpenClaw and Advanced AI Agents Apr 15, 2026 2970 In this episode of the Application Security Podcast, Chris Romeo and Robert Hurlbut welcome back Steve Wilson, a global leader in AI security and Chief AI and Product Officer at Exabeam, as well as founder of the OWASP Gen AI Security Project.Steve shares how his AI assistant was “hacked” using a simple phishing attack, highlighting a major shift in security—AI agents behave more like humans than
Brad Geesaman - Redefining AppSec with AI: Shrinking Toil, Expanding Impact - How LLMs are able to reduce toil in triage-heavy AppSec workflows
Brad Geesaman - Redefining AppSec with AI: Shrinking Toil, Expanding Impact - How LLMs are able to reduce toil in triage-heavy AppSec workflows Oct 28, 2025 2539 Brad Geesaman, Principal Security Engineer at Ghost, joins the podcast today to explore how AI and large language models are transforming the world of application security. The discussion starts with the concept of "toil"—the repetitive, exhausting work that drains AppSec teams as they struggle to keep up with mountains of security findings and alerts. Brad shares his insights on how LLM
OWASP Candidate Debate - 2025 Edition
OWASP Candidate Debate - 2025 Edition Oct 15, 2025 4089 In this special episode of the Application Security Podcast we meet nine of the OWASP Board of Directors candidates. Each candidate discusses their unique qualifications, experiences, and vision for OWASP's future. Topics include enhancing OWASP's impact, improving outreach and education, securing funding, and engaging local chapters. Don't miss this insightful debate as these candi
Francesco Cipollone - Agentic AI Manifesto
Francesco Cipollone - Agentic AI Manifesto Sep 23, 2025 1999 Francesco Cipollone, the CEO of Phoenix Security, shares his extensive experience in AI and security, discussing the crucial difference between true AI agents and glorified chatbots. Learn why Phoenix Security utilizes six different LLMs instead of a single super agent. Understand the sobering economics behind AI implementation and the importance of adopting AI responsibly. Get practical advice on

Recommended