Home Podcasts The Boring AppSec Podcast
The Boring AppSec Podcast

The Boring AppSec Podcast

The Boring AppSec Podcast 37 Episodes Mar 11, 2026

This podcast discusses the hosts' experiences working at various companies, from startups to large enterprises and from tech to security firms. They cover both the positive and negative aspects of their career paths, including building side projects and startups. The show features candid conversation and strong opinions on all things security. The tone is casual and straightforward, aiming to share real-world insights from the application security field.

Episodes

Ep 37: The Future of Security Testing in an AI-Driven World with Jason Haddix
Ep 37: The Future of Security Testing in an AI-Driven World with Jason Haddix Mar 11, 2026 01:01:18 In this episode, Jason Haddix (CEO of Arcanum Information Security and creator of the Bug Hunter’s Methodology) joins us to examine how AI is changing penetration testing and security research. He explains that while AI agents can automate reconnaissance, code analysis, and parts of vulnerability discovery, meaningful results still depend on human expertise, methodology, and context engineering.Th
Ep 36: Discussing AI's Current State of Affairs
Ep 36: Discussing AI's Current State of Affairs Mar 2, 2026 00:50:11 In this episode, we examine what is shifting in AI, AppSec, and product security and what remains fundamentally the same.For years, application security has operated on a familiar model: siloed reviews, tool-driven findings, and periodic assessments that struggle to keep pace with modern development. AI doesn’t eliminate those pressures, it amplifies them. Code is generated faster, systems are mor
Ep 35: Exploring Security After Determinism with Jens Ernstberger
Ep 35: Exploring Security After Determinism with Jens Ernstberger Feb 16, 2026 00:49:50 In this episode, we sit down with Jens to explore why AI agents fundamentally break traditional security assumptions, from API keys and browser sessions to composability and access control.Drawing parallels to DeFi exploits and smart contract failures, he explains why agent identity, short-lived delegated authorization, and zero trust aren’t optional add-ons, but the foundation for safely running
Security at Scale in a Probabilistic World with Ankur Chakraborty
Security at Scale in a Probabilistic World with Ankur Chakraborty Feb 2, 2026 00:56:37 In this episode, Ankur Chakraborty discusses the evolution of AI security, emphasizing the importance of foundational security principles in the context of generative AI. He explores the challenges of scaling security measures in an era of rapid feature deployment and the necessity of integrating AI tools into security practices. The conversation delves into the balance between human oversight and
The Future of Identity in AI Agents with Ian Livingstone
The Future of Identity in AI Agents with Ian Livingstone Jan 28, 2026 00:55:01 In this conversation, Ian Livingstone discusses the changing landscape of AI and security, focusing on the challenges of agent identity and the need for a new approach to application security. He emphasizes the importance of understanding the non-deterministic nature of AI agents and the implications for identity management, permissions, and data security. The discussion also touches on the future
Rethinking Enterprise Security in an AI- and Platform-First World with Kane Narraway
Rethinking Enterprise Security in an AI- and Platform-First World with Kane Narraway Jan 19, 2026 00:49:35 In this episode, we sit down with Kane Narraway to unpack how enterprise security is changing as AI, platforms, and developer-driven security become the norm. Kane shares his path from digital forensics to leading security at Canva, and why understanding company culture matters just as much as choosing the right tools.We discuss why modern security is becoming platform-first, why much of the secur
The Future of Developer Security with Travis McPeak
The Future of Developer Security with Travis McPeak Dec 15, 2025 00:51:51 In this episode, we sit down with Travis McPeak, one of the most prominent thinkers in the space of developer security. Travis, who built his career at the intersection of security automation and developer productivity, shares his philosophy on achieving security at scale in the AI era. His career spans security leadership roles at major tech companies, including Symantec, IBM, Netflix, and Databr
Scaling Product Security In The AI Era with Teja Myneedu
Scaling Product Security In The AI Era with Teja Myneedu Dec 4, 2025 00:51:39 In this episode, we sit down with Teja Myneedu, Sr. Director, Security and Trust at Navan. He shares his philosophy on achieving security at scale, discussing some challenges and approaches specially in the AI era. Teja's career spans over two decades on the front lines of product security at hyper-growth companies like Splunk. He currently operates at the complex intersection of FinTech and c
Architecting AI Security: Standards and Agentic Systems with Ken Huang
Architecting AI Security: Standards and Agentic Systems with Ken Huang Nov 24, 2025 00:45:30 In this episode, we sit down with Ken Huang, a core architect behind modern AI security standards, to discuss the revolutionary challenges posed by agentic AI systems. Ken, who chairs the OWASP AIVSS project and co-chairs the AI safety working groups at the Cloud Security Alliance, breaks down how security professionals are writing the rulebook for a future driven by autonomous agents.Key Takeaway
The Attacker's Perspective on AI Security with Aryaman Behera
The Attacker's Perspective on AI Security with Aryaman Behera Oct 1, 2025 00:48:15 In this episode, hosts Sandesh and Anshuman chat with Aryaman Behera, the Co-Founder and CEO of Repello AI. Aryaman shares his unique journey from being a bug bounty hunter and the captain of India's top-ranked CTF team, InfoSec IITR, to becoming the CEO of an AI security startup. The discussion offers a deep dive into the attacker-centric mindset required to secure modern AI applications, whi
From Toil to Intelligence: Brad Geesaman on the Future of AppSec with AI Agents
From Toil to Intelligence: Brad Geesaman on the Future of AppSec with AI Agents Sep 8, 2025 00:51:54 In this episode, host Anshuman Bhartiya sits down with Brad Geesaman, a Google Cloud Certified Fellow and Principal Security Engineer at Ghost Security, to explore the cutting edge of Application Security. With 22 years in the industry, Brad shares his journey and discusses how his team is leveraging agentic AI and Large Language Models (LLMs) to tackle some of the oldest challenges in AppSec, aim
The Future of Autonomous Red Teaming with Ads Dawson
The Future of Autonomous Red Teaming with Ads Dawson Sep 2, 2025 00:53:51 In this episode, we talk to Ads Dawson (Staff AI Security Researcher @ Dreadnode). We discuss the evolving landscape of offensive security in the age of AI. The conversation covers the practical application of AI agents in red teaming, a critical look at industry standards like the OWASP Top 10 for LLMs, and Ad's hands-on approach to building and evaluating autonomous hacking tools. He shares

Recommended