The Application Security Podcast podcast artwork
Technology

The Application Security Podcast

by Chris Romeo and Robert Hurlbut
TechnologyNewsTech News

Where it charts

Today’s combined position on our country charts.

Ranking history

History builds daily. We started tracking this show on the Technology chart recently, so the trend line appears after a second day of data.

About the show

The Application Security Podcast is a practitioner-led show for anyone building or securing modern software—and now AI-powered applications. Hosts Chris Romeo and Robert Hurlbut talk with the people shaping application security about AI and LLM security, threat modeling, secure development, OWASP, cloud, DevSecOps, security champions, and building programs that help engineering teams move faster and safer. With more than 300 episodes, the show turns real-world experience into practical guidance for developers, architects, AppSec professionals, and security leaders.

Latest episodes

  • Your Opinion on AI Doesn't Matter. Learned Fragility Does

    October 5, 2026 · 53 min

    What happens when a tsunami of AI-written code meets a security industry that has spent decades chasing vulnerabilities? Brook S.E. Schoenfield, CTO of Rezliant and author of Securing Systems, returns to warn about "the illusion of…

  • Why AI Code Review Will Replace Human Review Faster Than You Think

    September 29, 2026 · 49 min

    Jim Manico thinks the era of human code review is ending, and that clinging to it will hurt your company. The founder of Manicode Security returns to explain why AI didn't kill AppSec education but supercharged it, why vague prompting on…

  • Vulnerability Jail and the AI-Era AppSec Engineer

    September 22, 2026 · 45 min

    Three years ago, Jeevan Singh mapped out what an application security engineer needed to know. AI has rewritten the job since. Jeevan, Director of Security Engineering at Rippling, returns to unpack how his team polices thousands of…

  • How Agentic AI Fails—and Which Controls Actually Stop It

    September 15, 2026 · 37 min

    Most fault trees get built on gut feeling. Petra Vukmirovic did something rarer: she borrowed the actual math from aviation and nuclear-plant safety engineering and pointed it at AI agents. Petra traded emergency medicine for application…

  • Your AppSec Bottleneck Is a People Problem

    September 7, 2026 · 48 min

    Most security champions programs don't fail on tooling — they fail on people. Lisi Hocke spent three years as a champion before moving fully into product security, which means she has argued both sides of this from inside the trenches…

  • AI Pen Testing Killed Traditional DAST

    August 31, 2026 · 44 min

    Is traditional DAST finally dead? James Berthoty came back to settle the argument that his last episode started. James is the founder and analyst behind Latio, and he argues that AI pentesting is a genuinely different animal — payloads…

  • AI Security: OWASP Meets Global Standards

    August 26, 2026 · 48 min

    AI security has no shortage of standards — the problem is turning them into something a team can actually use. Rob van der Veer has spent 34 years in AI and security, founded the OWASP AI Exchange, and created MOSAIC, the agreement that…

  • The Future of Open-Source Threat Modeling

    August 17, 2026 · 40 min

    You don't have to let AI do the thinking for you. In this episode, Vikram Narayan shares why the smartest teams use AI as an accelerant — not a replacement — and why human judgment still matters most in threat modeling. Vikram created…