Home Podcasts The Elephant in AppSec
The Elephant in AppSec

The Elephant in AppSec

The Elephant in AppSec 89 Episodes Aug 4, 2026

A podcast dedicated to exploring overlooked and uncomfortable topics in application security. Each episode aims to bring attention to issues in AppSec that are rarely discussed openly. The show provides a platform for honest conversations about the challenges facing security professionals.

Episodes

The Docker mistakes everyone's still making and how to fix them with Advait Patel
The Docker mistakes everyone's still making and how to fix them with Advait Patel Aug 4, 2026 00:36:03 Today I'm joined by Advait Patel, Senior Site Reliability Engineer and the creator of DockSec, an open-source, AI-powered Docker security scanner that's now an official OWASP Incubator project.In this episode, we get into:Why dumping 200 container findings into a Jira ticket is the fastest way to get developers to fix nothing and how DockSec cuts that down to the 5 that actually matterThe
Why Security Loses Influence in High-Growth Companies (And What to Do About It) with Kavia Venkatesh
Why Security Loses Influence in High-Growth Companies (And What to Do About It) with Kavia Venkatesh May 20, 2026 00:31:48 Today, I'm joined by Kavia Venkatesh, Director of Product Security at a large healthcare organization. She didn't take the traditional path into cybersecurity — she came from biotech. But that outsider lens turned out to be her edge. With over 10 years of experience leading cybersecurity strategy for hyper-scale ecosystems, she's built many security programs from the ground up, navigat
The Lethal Trifecta or why your AI agent knows too much - Jason Fernandes
The Lethal Trifecta or why your AI agent knows too much - Jason Fernandes May 11, 2026 00:33:03 Today, I’m joined by Jason Fernandes, VP of security and privacy at Mercari, the Japanese-born global marketplace now spanning e-commerce, FinTech, and crypto. It is this rare combination that puts him at the intersection of some of the strictest regulatory environments in tech. He oversees everything from product and platform security to threat detection, privacy, and, since last year,  AI securi
25 years of the same problem in Application Security - Sam Stepanyan
25 years of the same problem in Application Security - Sam Stepanyan Apr 22, 2026 00:37:36 Today, I’m joined by Sam Stepanyan,  an OWASP Global Board member and an OWASP London Chapter Leader. Sam is an Independent Application Security Consultant and Security Architect with over 20 years of experience in the IT industry.Sam has worked for various financial services institutions in the City of London specialising in Application Security consulting, Secure Software Development Lifecycle (
Should security belong in every AI strategy meeting? with Amol Deshpande
Should security belong in every AI strategy meeting? with Amol Deshpande Dec 29, 2025 00:47:14 Today, I’m joined by Amol Deshpande, a seasoned security engineer currently at Stripe, where he focuses on building secure systems at massive scale. With a background spanning product security and penetration testing at companies like Salesforce, Splunk, and Early Warning, Amol brings deep hands-on experience in securing complex, real-world platforms. He’s also been a HackMIT judge and a long-time
What Mindset Shift Developers Need to Break Into Security? with Aleksandra Kornecka
What Mindset Shift Developers Need to Break Into Security? with Aleksandra Kornecka Dec 24, 2025 00:38:42 Today, I’m joined by Aleksandra Kornecka, a security engineer with a global mindset. She recently transitioned from Senior AppSec Engineer to Cloud Infrastructure Security Engineer, and has a background in software testing and cognitive science — a combination that gives her a unique take on both the technical and human sides of security.As a member of the OWASP Security Champions Guide and the pr
Is the AI–API interaction the biggest security blind spot? with Gowtham Sundar
Is the AI–API interaction the biggest security blind spot? with Gowtham Sundar Dec 20, 2025 00:31:29 Today, I’m joined by Gowtham Sundar, a Senior Lead Engineer - 3A Security (AI and API included as you can guess) at SPH Media and a seasoned AppSec leader with over a decade of experience across enterprise security, penetration testing, and secure product development.In this episode, Gowtham brings a real practitioner’s point of view on what it actually takes to secure AI systems. We dive into why
What best drives the adoption of secure software practices? with Enrique Larios Vargas
What best drives the adoption of secure software practices? with Enrique Larios Vargas Dec 11, 2025 00:38:10 Today, I’m joined by Enrique Larios Vargas, a Security and Learning Specialist at Adyen.Enrique has over eight years of experience designing impactful learning and enablement programs across fintech, engineering, and security. He’s also been a university lecturer in software engineering in Peru, the Netherlands, and Canada.Bringing together technical expertise and behavioral science, Enrique is pa
Why AppSec Needs More Than Just a Checkbox ⎢ Marcos Vinicius Cassel
Why AppSec Needs More Than Just a Checkbox ⎢ Marcos Vinicius Cassel Dec 3, 2025 00:42:32 Today, I’m joined by Marcos Vinicius Cassel, Application Security Manager at PowerSchool.With over a decade of experience in the information security space, as a CISSP, ISO 27001 Lead Auditor, and a passionate technologist, Marcos has led security initiatives across multiple industries. He also previously led the OWASP Porto Alegre Chapter, and fun fact: we first met while volunteering together at
The Supply Chain Crisis We Created: How AI, Extensions, and Dependencies Became the New Attack Surface with Aamiruddin Syed
The Supply Chain Crisis We Created: How AI, Extensions, and Dependencies Became the New Attack Surface with Aamiruddin Syed Nov 26, 2025 00:40:32 Today, I’m joined by Aamiruddin Syed, Senior Product Security Engineer at AGCO Corporation. Aamiruddin is the author of “Supply Chain Software Security book focusing on AI, IoT, and AppSec” and a recognized advocate for secure development. He’s a frequent speaker at major conferences, including RSA, DEFCON, and Black Hat.Fun facts: he was once ranked in the top 1% of all TryHackMe penetration test
Why AppSec Is breaking: Vibe Coding, DevSecOps backlogs & the new OWASP Top 10 (with Tanya Janca)
Why AppSec Is breaking: Vibe Coding, DevSecOps backlogs & the new OWASP Top 10 (with Tanya Janca) Nov 13, 2025 00:51:09 Today, I’m joined once again by Tanya Janca for her second appearance on the podcast. Her first episode was a hit, so we figured: why not record another? And the timing couldn’t be better, as Tanya has just embarked on a brand-new chapter in her career this year. In our first conversation, I highlighted many of Tanya’s accomplishments, and she’s only added to the list since then. Most notably, she
Secure by Design: Who’s Really Responsible? with Abhijeth Dugginapeddi
Secure by Design: Who’s Really Responsible? with Abhijeth Dugginapeddi Nov 4, 2025 00:43:24 Today on the show, I’m joined by Abhijeth Dugginapeddi, Director of Offensive Security at Palo Alto Networks. Before this, he built and led product and cloud security at BigCommerce, and worked on application security at Commonwealth Bank and Adobe.Abhijeth is deeply passionate about giving back to the community. He’s taught advanced web application security at UNSW, mentored through multiple outr

Recommended