
The Elephant in AppSec
A podcast dedicated to exploring overlooked and uncomfortable topics in application security. Each episode aims to bring attention to issues in AppSec that are rarely discussed openly. The show provides a platform for honest conversations about the challenges facing security professionals.
Episodes

The Docker mistakes everyone's still making and how to fix them with Advait Patel
Today I'm joined by Advait Patel, Senior Site Reliability Engineer and the creator of DockSec, an open-source, AI-powered Docker security scanner that's now an official OWASP Incubator project.In this episode, we get into:Why dumping 200 container findings into a Jira ticket is the fastest way to get developers to fix nothing and how DockSec cuts that down to the 5 that actually matterThe

Why Security Loses Influence in High-Growth Companies (And What to Do About It) with Kavia Venkatesh
Today, I'm joined by Kavia Venkatesh, Director of Product Security at a large healthcare organization. She didn't take the traditional path into cybersecurity — she came from biotech. But that outsider lens turned out to be her edge. With over 10 years of experience leading cybersecurity strategy for hyper-scale ecosystems, she's built many security programs from the ground up, navigat

The Lethal Trifecta or why your AI agent knows too much - Jason Fernandes
Today, I’m joined by Jason Fernandes, VP of security and privacy at Mercari, the Japanese-born global marketplace now spanning e-commerce, FinTech, and crypto. It is this rare combination that puts him at the intersection of some of the strictest regulatory environments in tech. He oversees everything from product and platform security to threat detection, privacy, and, since last year, AI securi

25 years of the same problem in Application Security - Sam Stepanyan
Today, I’m joined by Sam Stepanyan, an OWASP Global Board member and an OWASP London Chapter Leader. Sam is an Independent Application Security Consultant and Security Architect with over 20 years of experience in the IT industry.Sam has worked for various financial services institutions in the City of London specialising in Application Security consulting, Secure Software Development Lifecycle (

Should security belong in every AI strategy meeting? with Amol Deshpande
Today, I’m joined by Amol Deshpande, a seasoned security engineer currently at Stripe, where he focuses on building secure systems at massive scale. With a background spanning product security and penetration testing at companies like Salesforce, Splunk, and Early Warning, Amol brings deep hands-on experience in securing complex, real-world platforms. He’s also been a HackMIT judge and a long-time

What Mindset Shift Developers Need to Break Into Security? with Aleksandra Kornecka
Today, I’m joined by Aleksandra Kornecka, a security engineer with a global mindset. She recently transitioned from Senior AppSec Engineer to Cloud Infrastructure Security Engineer, and has a background in software testing and cognitive science — a combination that gives her a unique take on both the technical and human sides of security.As a member of the OWASP Security Champions Guide and the pr

Is the AI–API interaction the biggest security blind spot? with Gowtham Sundar
Today, I’m joined by Gowtham Sundar, a Senior Lead Engineer - 3A Security (AI and API included as you can guess) at SPH Media and a seasoned AppSec leader with over a decade of experience across enterprise security, penetration testing, and secure product development.In this episode, Gowtham brings a real practitioner’s point of view on what it actually takes to secure AI systems. We dive into why

What best drives the adoption of secure software practices? with Enrique Larios Vargas
Today, I’m joined by Enrique Larios Vargas, a Security and Learning Specialist at Adyen.Enrique has over eight years of experience designing impactful learning and enablement programs across fintech, engineering, and security. He’s also been a university lecturer in software engineering in Peru, the Netherlands, and Canada.Bringing together technical expertise and behavioral science, Enrique is pa

Why AppSec Needs More Than Just a Checkbox ⎢ Marcos Vinicius Cassel
Today, I’m joined by Marcos Vinicius Cassel, Application Security Manager at PowerSchool.With over a decade of experience in the information security space, as a CISSP, ISO 27001 Lead Auditor, and a passionate technologist, Marcos has led security initiatives across multiple industries. He also previously led the OWASP Porto Alegre Chapter, and fun fact: we first met while volunteering together at

The Supply Chain Crisis We Created: How AI, Extensions, and Dependencies Became the New Attack Surface with Aamiruddin Syed
Today, I’m joined by Aamiruddin Syed, Senior Product Security Engineer at AGCO Corporation. Aamiruddin is the author of “Supply Chain Software Security book focusing on AI, IoT, and AppSec” and a recognized advocate for secure development. He’s a frequent speaker at major conferences, including RSA, DEFCON, and Black Hat.Fun facts: he was once ranked in the top 1% of all TryHackMe penetration test

Why AppSec Is breaking: Vibe Coding, DevSecOps backlogs & the new OWASP Top 10 (with Tanya Janca)
Today, I’m joined once again by Tanya Janca for her second appearance on the podcast. Her first episode was a hit, so we figured: why not record another? And the timing couldn’t be better, as Tanya has just embarked on a brand-new chapter in her career this year. In our first conversation, I highlighted many of Tanya’s accomplishments, and she’s only added to the list since then. Most notably, she

Secure by Design: Who’s Really Responsible? with Abhijeth Dugginapeddi
Today on the show, I’m joined by Abhijeth Dugginapeddi, Director of Offensive Security at Palo Alto Networks. Before this, he built and led product and cloud security at BigCommerce, and worked on application security at Commonwealth Bank and Adobe.Abhijeth is deeply passionate about giving back to the community. He’s taught advanced web application security at UNSW, mentored through multiple outr

The Pressure of Security Leadership: What SLAs Actually Work? with Terry O'Daniel
Today, I’m excited to be joined by Terry O’Daniel, former global head of security at Amplitude, Instacart, and Netflix, and a trusted advisor in the security space. Terry thrives in high-growth environments and loves tackling complex challenges.With a strong background in engineering and security, he builds teams that focus on solving security problems at scale through automation and instrumentati

Can We Make AI Agents Smarter Than Security Teams? with Anshuman Bhartiya
Today, I’m excited to welcome Anshuman Bhartiya, an AppSec tech lead at Lyft. Before that, he worked as a security engineer at companies like Thirty Madison, Intuit, and Atlassian.Anshuman is also a fellow podcaster and co-host of the Boring AppSec podcast, alongside one of my previous guests, Sandesh Mysore Anand.Recently, he’s been experimenting extensively with building AI agents for both offen

Why DevSecOps isn't enough without deep cloud context with Anjali Singh Shukla
Today I’m joined by Anjali Singh Shukla, Senior Security Engineer Cloud at Flipkart. She bridges the worlds of Cloud Security and DevSecOps, having led audits and defense strategies across AWS, Azure, and GCP, with a strong focus on Kubernetes and container security. Beyond building secure pipelines, Anjali designs training programs and speaks at global conferences like Black Hat and OWASP. Most r

Decoding a Healthy Security Program: What Does "Healthy" Even Mean? with Maxwell Zhou
Today, I’m joined by Maxwell Zhou, the Founding Partner of PolarStar Cybersecurity Group, a cybersecurity firm focused on helping fintech organizations strengthen their product security. Throughout his career at Greenlight, Visa, and T-Mobile, Maxwell has specialized in penetration testing, vulnerability assessments, and secure coding practices. He’s particularly excited about building world-class

Why SAP Security Can be a Hidden Weakness for Enterprises with Oumaima Baira
Today, I’m joined by Oumaima Baira, Directrice of Enterprise Security at Deloitte. With nearly a decade of experience, she’s helped organizations strengthen their defenses — from DevSecOps and SAP application security to enterprise-wide security strategy. She began her career in cloud engineering before moving into cyber consulting, and quickly rose through Deloitte’s leadership ranks, blending de

Latin America’s AppSec Culture: What’s Lost (and Found) in Translation?
Today, I’m joined by Max Alejandro Gómez-Sánchez Vergaray, Defensive Cybersecurity Manager at Banco de Crédito BCP. With a background in software engineering, Max transitioned into AppSec and has become a leading voice in promoting DevSecOps awareness and building robust AppSec programs using SAMM across Latin America and beyond. He actively contributes to OWASP projects like Cornucopia and regula

OWASP SAMM vs BSIMM: Which Maturity Model Reigns Supreme?
Today, I'm joined by Nariman Aga-Tagiyev, a seasoned cybersecurity architect and threat modeling coach, bringing over two decades of experience in the software development industry. As the founder of SecureHabits, he’s on a mission to help software manufacturers mature their secure software development lifecycle.Nariman is a familiar face at OWASP Netherlands Chapter events and an active contr

Security Culture: When Are We Really Creating Change? with Marisa Fagan
Today, I'm joined by Marisa Fagan, a lifelong community builder and security culture enthusiast. As the Head of Product at Katilyst, Marisa leads the development of security champion programs that empower Security Champions to drive cultural change.Previously, she served as Head of Trust Culture & Training at Atlassian and has managed security programs at Synopsys, Salesforce, and Meta.Mar

Security Wins Only When Institutionalized – Here’s Why!⎜Kevan Bard
Today, I'm joined by Kevan Bard, Director of Product Security at Morningstar. With 20 years of experience in information security, Kevan has helped shape security practices across various organizations. He’s passionate about building blue team careers, with a focus on recruiting, mentoring, and staff development.When not busy cultivating kaizen, emotional intelligence, secure coding practices,

Why Your Security Program Might Be Failing Before It Even Starts with Sean Finley
Today, I’m joined by Sean Finley, an experienced Information and Application Security leader with deep expertise in AppSec, security operations, vulnerability management, and governance.Sean’s AppSec career started at GEICO, one of the most recognizable names in U.S. insurance. He made the leap from business analyst to the company’s very first AppSec engineer, teaching himself everything along the

The Future of Pentesting: Can AI Replace Human Expertise?
Today I’m joined by Jyoti Raval, a security leader with a diverse background across consulting, product security at Qualys and Harness, and now serving as Director of Cyber Security Engineering at Baker Hughes.Jyoti is a passionate pentester and international speaker. She’s also the author of Phishing Simulation and MPT: Pentest in Action and has discovered multiple CVEs.Beyond her technical exper

How to Fix the Lack of Clear Guidance in Building Effective Security Programs | Luís Fontes
Today's episode features Luís Fontes, who, after five years working with various technologies as a full-stack developer, transitioned to the AppSec world. Luís worked as an AppSec engineer at major companies like Checkmarx and then moved to IOVLabs (RSK) and the cryptocurrency space. Nowadays, Luís works at Xapo, a crypto bank, and is an expert in both product security and blockchain security.

AI Security: Do You Need a Dedicated Vendor? | Insights with James Berthoty
Welcome to Season 4 of The Elephant in AppSec! Get ready for a season packed with even spicier takes! Today's episode features none other than James Berthoty, a security engineer turned founder and CEO of Latio. James is always ready to share his unfiltered opinions, and I’ve had the pleasure of chatting with him for last couple of years. Over the past few months, there were a lot of discussio

Why AppSec isn’t just for tech — Surprising Insights ⎜ Olga Dzięgielewska
Today, I’m joined by Olga Dzięgielewska, Senior Manager of InfoSec Application Security at Philip Morris International. With over 10 years of experience in secure code reviews, a PhD in IT Security, and now leading global AppSec teams, Olga specializes in secure development practices, IT assurance, ethical hacking, API security and SAP security, driving security initiatives across multiple interna

Are Traditional WAFs Dead? The Impact of OpenAPI Specs on Web Security with Nathan Byrd
Today, I’m joined by Nathan Byrd, a Principal AppSec Architect at Applied Systems. Nathan’s journey is truly unique: before joining Applied Systems, he spent an impressive 24 years at Mastercard, where he rose from a software engineer to a Principal AppSec Architect. That’s the longest tenure we’ve seen from anyone on the podcast!Nathan is passionate about building things, whether it’s his early d

Finding AppSec tools that developers love — is it possible? with Linda Fay
Today I’m joined by Linda Fay, a seasoned leader in Application Security with over 13 years of experience. She’s led large-scale security programs, most recently as Director of Product Security Engineering, where she secured thousands of applications and delivered major cost savings. Now working as an independent consultant, she helps organizations improve their AppSec posture and explore the inte

What Most Security Teams Miss: An Engineering Manager’s Take on AppSec with Desmond Lamptey
Today’s episode is a special one. I’m joined by Desmond Lamptey, a Software Engineering Manager at a large financial organization.I first came across Desmond during his talk on API Security at APIDays Paris—and honestly, it was one of the best talks I’ve seen. Not only because of the insights, but also the dad jokes.That talk made me curious: What drives a seasoned engineer like Desmond to speak a

Compliance in Cyber: Can Regulation and Innovation coexist?⎜Chris Hughes
Today, I’m joined by Chris Hughes, the CEO & Co-Founder of Aquia, a cybersecurity consulting firm supporting secure digital transformation for U.S. federal, state, and defense agencies. He previously served as a Cyber Innovation Fellow at CISA.Chris is also the co-author of Software Transparency and Effective Vulnerability Management (Wiley) books, and hosts the Resilient Cyber podcast and Sub

The Future of Product Security: Quality Engineering or something more? with Michael Novack
Today, I’m joined by Michael Novak, a seasoned Application Security Architect turned Technical Product Manager. At the time of this recording, he was still working hands-on in AppSec! Having started his career as a Java software engineer, Michael knows firsthand the challenges developers face when it comes to building secure applications.Outside of his technical roles, Michael has created several

Should We Fix All Bad Code? with Eitan Worcel
Today, I’m joined by Eitan Worcel, CEO and co-founder of Mobb — an AI Security Assistant that fixes vulnerabilities. With over 15 years of experience in the application security field, Eitan has worn many hats, including developer, product management leader, and now startup founder.Eitan has also shared his expertise at events such as Black Hat, BSides Las Vegas, and OWASP chapter meetings, where

AI, Speed, and Startup Chaos: Is ‘Minimum Viable Security’ the Fix? ⎜ Kalyani Pawar
Today, I’m joined by Kalyani Pawar, an Application Security Engineer at Zipline and a seasoned AppSec expert with a deep commitment to the startup ecosystem. Beyond her day job, she actively advises startups and VCs on what really matters in application security. Kalyani is also the co-host of the Application Security Weekly podcast and a speaker at top conferences like DEFCON, BSides SF, and RSA.

Security IDE Plugins: Can They Really Boost Your Coding Security? ⎜Jamie Scott
Today, I'm joined by Jamie Scott, a recovering cybersecurity practitioner turned founding product manager at Endor Labs. Previously, Jamie served as Product Manager of Security at Redis, where he was an active open-source contributor, and as DevSecOps Manager at Cygna Healthcare.Jamie is also a Certified Information Systems & Cloud Security Professional and continues to contribute to the c

DAST Tools: Can We Change the AppSec Community Perception? with Chris Lindsey
Today, I’m joined by Chris Lindsey, who, at the time of recording, was an AppSec Evangelist at Mend. Formerly an AppSec Architect, Chris brings over 15 years of direct security experience and more than 35 years of leadership in programming, software, solutions, and security architecture.For several years, Chris built and led an entire application security program, including oversight of security p

Secure Coding — Can we make it happen? with Tanya Janca
Today, I’m joined by someone many of you will instantly recognize — Tanya Janca, also known as She Hacks Purple and a key community leader at Semgrep.With nearly three decades in IT, Tanya has earned countless awards, including OWASP Lifetime Distinguished Member and Hacker of the Year. She’s spoken on stages around the world and trained thousands of software developers and security professionals

How Psychology Really Shapes AppSec Wins & Fails ⎢ Curtis Koenig
Today, I’m joined by Curtis Koenig, a seasoned application security leader managing AppSec programs for global brands. At Gen Inc., he secures all products through CI/CD integration, secure coding, and a bug bounty program. Previously, at Booking.com and Snap Inc., he scaled security operations, enhanced authentication systems, and streamlined compliance processes. With expertise in secure develop

The Open Source Security Crisis: Is Trust the Weakest Link in Supply Chain? with François Proulx
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the roomToday, I’m joined by François Proulx, Senior Product Security Engineer at BoostSecurity, where he leads the Supply Chain research team. With over 10 years of experience in building AppSec programs for both large corporations like Intel and innovative startups, François has been at

Are we truly managing Third-Party risks, or just playing security theater? ⎢Rachel Curran
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the roomToday, I’m joined by Rachel Curran, co-founder and CEO of Locktivity—a third-party risk management platform. She’s also the former Director of Risk and Compliance and Head of Infosec at Logik Systems.With over a decade of experience leading security and GRC initiatives, Rachel has

Hyped or Helpful? The Truth About Reachability & Developer Buy-In ⎢ Nir Valtman
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.Today, I’m joined by Nir Valtman, CEO & co-founder of Arnicaan ASPM platform with a pipelineless approach. Before founding Arnica, Nir led product and data security at Finastra, established security at Kabbage as CISO, and headed application security at NCR. He’s also a well-k

DevSecOps vs. Reality: What You REALLY Need to Succeed!
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.Today, I’m joined by Iman Ilbag, a DevSecOps Engineer at KPN, one of the leading telecom providers in the Netherlands.Previously, as the sole DevSecOps Engineer at Snappfood, he secured 70+ projects and trained hundreds of security champions. Iman transitioned from engineering to

Unpacking Opengrep—A Deep Dive with Its Backing Teams
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.Recently, Opengrep made headlines as a new open-source project based on a fork of Semgrep Community Edition, with the goal of democratizing SAST.As you know, I'm always ready to dive into controversial topics on The Elephant in AppSec, and this episode is no exception. But bef

Is There a Secret to Mastering Threat Modeling at Scale? Ashwini Siddhi (GoDaddy)
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.Today, I’m thrilled to be joined by Ashwini Siddhi, Director, Security Engineering at GoDaddy. With a background in electronics engineering, Ashwini discovered her true passion in cybersecurity and has since become a distinguished leader in the AppSec space. Her expertise spans mu

Can You Really Quantify AppSec ROI? Here’s the Truth! ⎜Irfaan Santoe
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.
Today, I’m joined by Irfaan Santoe, a seasoned security leader who has worn many hats—from CISO to Global Head of Application Security, and now Founder and CTO of RiskApp.
Beyond his leadership roles, Irfaan is a dedicated community
builder. He leads the OWASP Netherlands Chapt

How to Fix API Security Before It’s Too Late ⎜ Confidence Staveley
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.
Today, I’m joined by a true force in cybersecurity. With over a decade of experience, Confidence Staveley has dedicated her career to helping organizations build secure, innovative products. She’s the founder of MerkleFence, where she serves as Director of Application Security f

The Untold Benefits of Continuous Threat Modeling You Didn’t Know About ⎜Izar Tarandach
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.
Today, I’m joined by Izar Tarandach, a Senior Product Security Architect with extensive security experience at Datadog, Squarespace, and several other companies. Izar is also a renowned speaker and the co-author of Threat Modeling: A Practical Guide for Development Teams by O

What does “collaborate with engineering” actually mean in AppSec? ⎜Koen Hendrix (Zendesk)
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.
Today, I’m joined by Koen Hendrix, Director of Product Security at Zendesk. With over a decade of experience in the tech and gaming industries, Koen has been instrumental in building and scaling global security teams, integrating security into agile environments, and driving inn

Is your organization mature enough for its first AppSec hire?⎢Akira Brand
Today, I'm joined by Akira Brand, the AVP of Application Security at PRA Group. With nearly five years of experience in the security space, Akira has a diverse background, starting as a Developer Relations Engineer and transitioning into an Application Security role.
Passionate about education and Infosec, Akira has established herself as a distinguished public speaker, co-hosting the AppSec Weekl

Are we overlooking Kubernetes security in the race to deploy applications - Raunaq Arora
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.
Today, we’re joined by Raunaq Arora, Lead Application Security Engineer at Chipotle. Raunaq’s journey into security was almost accidental, starting as a developer who quickly developed a knack for breaking and building secure applications.
Now, his expertise lies in securing K

Is it actually realistic to see everyone as the greatest ally in security? - Alina Yakubenko
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.
Today, I’m excited to have Alina Yakubenko on the show. Alina, Senior Application Security Engineer at Toast, Inc and former developer and QA Engineer., is dedicated to empowering developers to integrate security into their everyday practices. Passionate about building a culture

Can DevSecOps Maturity Models Fail? The Hidden Gaps in AppSec Programs ⎜Timo Pagel
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.
Today, I’m thrilled to welcome a true expert in DevSecOps, Timo Pagel! With over 20 years of experience in security strategy, web development, and DevSecOps architecture, Timo brings a wealth of knowledge to the table.
As a freelance consultant and university lecturer, he’s pa

Risk, Product Management, and Supply Chain Security: Is There a Connection? ⎜Jesus Cuadrado
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.
Today, I’m thrilled to welcome Jesus Cuadrado to the show! Jesus is the Chief Product Officer at Xygeni, an ASPM platform focused on improving software supply chain security. With over a decade of experience in product management, he’s now leading the charge in creating user-frie

How hard is it to make DevSecOps work in a Hybrid Cloud? ⎜Michael Tayo
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.
Today, I’m thrilled to welcome Michael Tayo to the show! As the Information Security Lead at EDX Markets, Michael advises C-suite leaders and drives strategies to protect critical infrastructure in institutional crypto markets. With prior roles in Financial Services and Tempus A

Is It Possible to Maximize the Effectiveness of Security Champions? ⎜ Magdalena Modric
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.
Today, I’m thrilled to welcome Magdalena Modric to the show! Magdalena is an AppSec Program Strategist at Secure Code Warrior, where she’s been empowering developers in the German-speaking market to build secure applications since 2018.
Beyond her professional expertise, Magdale

Hacker Turned Policy Builder: What They Don’t Want You to Know
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.
Today, I’m thrilled to welcome Patrick Mathieu to the podcast! Patrick is currently a Senior Manager of Product Security at DoorDash, but his impact on the cybersecurity world spans years.
Fifteen years ago, he founded Hackfest.ca, Canada's largest bilingual infosec conference

Why Is Transforming Company Culture for Product Security So Challenging? ⎜ Ariel Shin
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.
Today, I’m super excited to have Ariel Shin on the podcast! Ariel started as a pentester, moved into appsec, and now she’s a Security Engineering Manager at Datadog. Before that, she led the Product Security team at Twilio, where she led an effort to democratize vulnerability man

The API Governance Problem: Why Your API Security Is at Risk (And How to Fix It) ⎜Akansha Shukla
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.
Today, I’m excited to welcome Akansha Shukla, a cybersecurity expert with over 10 years of experience, currently specializing in API security at ABN AMRO, one of the largest banks in the Netherlands. Akansha has a strong background in application security, DevSecOps, threat mode

AI Chatbots: Security Disaster or Can We Build Them Securely? ⎜Ante Gojsalic & Benjamin Dulieu
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.
Today, I have two incredible guests with me: Ante Gojsalic and Benjamin Dulieu.
Ben is a Chief Information Security Officer at Duck Creek Technologies, an Insurance SaaS provider supporting the end-to-end insurance process for many of the world’s largest carriers. A former U.S.

Open Source vs. Commercial Software: The Ultimate Showdown⎜Kyle Kelly
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.
Today, my guest is Kyle Kelly, Tech Lead for Supply Chain Security Research at Semgrep and the founder of the CramHacks weekly newsletter. You can subscribe here 👉 cramhacks.com
With a background in consulting and research, he specializes in supply chain security, using his exp

Privacy vs. Application Security: Can They Truly Coexist? | Kim Wuyts
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.
Today, my guest is Kim Wuyts, a leading privacy engineering expert with over 15 years of experience in security and privacy. Before joining PwC Belgium as Manager of Cyber & Privacy, Kim was a senior researcher at KU Leuven, where she led the development and extension of LIN

From PhD to AppSec: How to Bridge the Gap Between Research & Security Tools | Diego Sempreboni
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.
Today, I’m joined by Diego Sempreboni, a Senior Application Security Engineer at Pleo. Diego earned his PhD in Computer Science, specializing in security, at King’s College London. After realizing his passion lay in solving real-world problems, he transitioned from academia to p

AppSec for Startups: Critical or Overlooked? | Rob Picard
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.
Today, my guest is Rob Picard. Rob started his career as a pentester and went on to become an early security hire at both Robinhood and Vanta, where he helped establish scalable security programs. He is now leading Observa, a security consulting firm focused on helping startups

What are the risks associated with open source? | Kaiwen Jiang
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.
Today, my guest is Kaiwen Jiang, an Application Security Engineer at a financial services company in the UK. Her primary areas of focus are . She was previously a cybersecurity consultant at Deloitte.
Kaiwen also runs a blog, AppSec Kiki, where she shares her knowledge with the

Season 2 The Elephant in AppSec Podcast Trailer
Get ready for more bold opinions starting next week! 🔥

AI Security - How hard is it to develop secure AI? ⎪Rob van der Veer
Today, we have an amazing guest, Rob van der Veer, joining us.
Rob is an AI pioneer with 32 years of experience, specializing in engineering, security, and privacy. Currently, he is a Senior Principal Expert at the Software Improvement Group (SIG), where he leads global thought leadership, advisory, and innovation in AI and software security.
Rob is the lead author of the ISO/IEC 5338 standard

We Don’t Let the Bad Guys Win: Is It Possible with All Third-Party Apps in Oil & Gas? ⎜Catharina "DD" Budiharto
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.
Today, we have an amazing guest, Catharina "DD" Budiharto, joining us.
DD has extensive experience in cybersecurity, having worked for several years with multiple Oil and Gas companies. She also served as the chairperson for the American Petroleum Institute (API) IT

Why “shift-left” isn’t good enough ⎪Chris Romeo
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.
Today, we have an amazing guest, Chris Romeo, joining us.
Chris has 26 years of experience in cybersecurity, having worked for 11 years at CISCO, founded his own security education company, Security Journey, and now Devici, an AI-infused collaborative threat modeling tool.
Ch

What are the Non-Human Identity challenges? ⎪Andrew Wilder and Amir Shaked
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.
We have two incredible guests with us: Andrew Wilder and Amir Shaked.
Andrew is the Retained Chief Security Officer at Community Veterinary Partners and the former Regional CISO for Nestle, where he spent 18 years shaping cybersecurity across the Americas, Asia, and Europe.
A

API Security: Are Vendors Just Blowing Smoke? ⎪David Homoney
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.
Today, we have an amazing guest, David Homoney, join us.
David is the newly appointed Sales Engineer at Apiiro. Before stepping into this role, he made significant contributions as a Technical Solutions Architect II for Application, API, and Workload Security at World Wide Tec

The Truth About Software Supply Chain Risks ⎪Cassie Crossley
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.
Today, we’re excited to have an amazing guest, Cassie Crossley, join us.
Cassie is the Vice President, Supply Chain Security in the global Cybersecurity & Product Security Office at Schneider Electric.
Starting from a development background, she moved through different

How secure are your digital wallets? ⎪Max Imbiel (Bitpanda)
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.
Today we’re excited to have an amazing guest, Max Imbiel, join us.
Max is the driving force behind “Ahead Security,” an agency specializing in vCISO activities, and currently serves as the CISO at BitPanda, an online crypto trading platform.
Max’s career began in IT and sof

How security research can earn you $20m in tokens ⎪Swan Beaujard
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.
Today we’re excited to have an amazing guest, Swan Beaujard, join us.
Swan is a security software engineer at Escape, specializing in Dynamic Application Security Testing. He is a core contributor to a lot of open-source projects related to GraphQL security and is passionate

Securing cloud native applications: how hard is it? ⎪Mihir Shah
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.
Today we’re excited to have an amazing guest, Mihir Shah, join us.
Mihir Shah is a Senior Staff Application Security Engineer at ForgeRock, specializing in architecting secure cloud-based Identity & Access Management services hosted using Kubernetes and Google Cloud Platf

Are custom security tests a product security superpower? ⎜Keshav Malik (LinkedIn)
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.
Today we’re excited to have an amazing guest, Keshav Malik, join us.
Keshav is a Senior Product Security Engineer at LinkedIn. With experience in information security and a passion for automation, Keshav brings a unique blend of expertise to the table.
Keshav is also a dedic

The art and science of product security ⎥Jacob Salassi (Snowflake)
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.
Today we’re excited to have an amazing guest, Jacob Salassi, join us.
Jacob is the Director of Product Security and Regulatory Expansion at Snowflake, where he has played a pivotal role in guiding the company through its pre- and post-IPO phases.
With over 15 years of experi

Security Consultant vs. In-House Engineer: The Showdown⎜Ric Campo
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.
Today we’re excited to have an amazing guest, Ric Campo, join us.
Ric started his cybersecurity journey in the Royal Australian Air Force. With a decade of dedicated experience as an Application Security Engineer and Penetration Tester, he currently serves as a Principal Secur

Developers and security training: can they co-exist?⎜Laura Bell Main
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.
Today, we’re excited to have an amazing guest, Laura Bell Main, join us.
With over 20 years in software development and application security, Laura is the co-founder and CEO of SafeStack, an online education platform that offers secure development training for fast-moving comp

Adversarial machine learning: what is it and are we ready? ⎜Anmol Agarwal
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.
Today we’re excited to have an amazing guest, Anmol Agarwal, join us.
Anmol is a security researcher at Nokia, focused on securing AI and Machine Learning in 6G and securing 5G.
She also holds a doctoral degree in cybersecurity analytics from George Washington University. H

AppSec vendors and CISOs: a love - hate relationship? ⎜Olivia Rose
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.
Today, we're joined by an amazing guest, Olivia Rose.
You can find Olivia on LinkedIn: https://www.linkedin.com/in/oliviaros...
Olivia is an executive leader with more than 20 years of dedicated experience, having served as the former CISO at Amplitude and Mailchimp and c

Pentesting: What are the actual benefits?⎥Harsh Modi
Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.
Today, we're joined by an amazing guest, Harsh Modi.
You can find Harsh on LinkedIn: https://www.linkedin.com/in/neighborhoodpenetrationtester/
With over 8 years of dedicated experience as an Offensive Security Engineer and Penetration Tester, Harsh has honed an exception
Recommended

The Church of What's Happening Now: The New Testament

Deadline: White House

English Vocabulary Help

این نقطه

Solved Murders - True Crime Stories

紐約鳥|New York Aperture

Doctor Zhivago Slow Read

Apple News In Conversation

The Young and Called Podcast .

Jubal Phone Pranks from The Jubal Show

پلی لیست | PlayList

English with Olivia | Slow Conversations & Vocabulary