59 episodes

The Future of Application Security is a podcast for ambitious leaders who want to build a modern and effective AppSec program. Doing application security right is really hard and we want to help other experts build the future of AppSec by curating the best industry insights, tips and resources.

Future of Application Security Tromzo

    • Business
    • 5.0 • 3 Ratings

The Future of Application Security is a podcast for ambitious leaders who want to build a modern and effective AppSec program. Doing application security right is really hard and we want to help other experts build the future of AppSec by curating the best industry insights, tips and resources.

    EP 59 - Nat Mokry on Advancing Application Security in the Gaming Industry

    EP 59 - Nat Mokry on Advancing Application Security in the Gaming Industry

    In our latest episode of the Future of Application Security podcast, Nat Mokry, VP of Application & Product Security at Xbox (formerly of Activision Blizzard at the time of recording), shares valuable insights into the world of application security, from the mission of defending player trust to emphasizing the importance of technical skills in cybersecurity. 

    Nat provides guidance on building effective security teams and navigating the evolving challenges in the industry.

    Topics discussed:

    - Earning and defending player trust as a guiding principle of business and strategies for making mission statements actionable.
    - Building and structuring a diverse security team, and the challenges faced by appsec teams in the current landscape.
    - The concept of the ”piggy bank of trust” in security relationships that Nat says helps him and his team remember that people skills are important too.
    - Balancing technical expertise and security knowledge, depending on what your data is telling you. 
    - Having the humility to ask questions and not have all the answers.
    - The difference between solving problems for people and minimizing the chances of them doing something wrong.

    • 26 min
    EP 58 — Asana's Felix Matenaar on Building Resilient Security Practices for the Future

    EP 58 — Asana's Felix Matenaar on Building Resilient Security Practices for the Future

    In this episode of the Future of Application Security podcast, Harshil interviews Felix Matenaar, Head of Product Security at Asana. Felix shares insights into his journey from Germany to Silicon Valley, where he transitioned from mobile security to leading Asana’s product security efforts.

    The conversation highlights Felix’s experience in creating security frameworks that eliminate vulnerabilities by building secure product lifecycles and ensuring alignment with business objectives. His approach integrates rigorous security measures directly into the development process, reflecting Asana’s commitment to robust, proactive security.

    Topics Discussed:

    - Felix discusses his transition from software engineering to product security and his strategic move from Google to Asana.
    - Strategies for integrating security seamlessly into product development to enhance safety without compromising functionality.
    - How effective security practices can accelerate business processes and foster trust with users.
    - The importance of collaboration across different organizational functions to ensure comprehensive security coverage.
    - The role of leadership in fostering a security-centric culture within tech companies.
    - Insights into upcoming challenges and innovations in the field of application security.

    • 32 min
    EP 57 — Clari's Steve Lukose on Using SLAs as Benchmarks for Businesses

    EP 57 — Clari's Steve Lukose on Using SLAs as Benchmarks for Businesses

    In this episode of the Future of Application Security, Harshil speaks with Steve Lukose, Vice President of Security at Clari, about how security is becoming a business enabler rather than just an organization. 

    Steve explains why SLAs will become one of the benchmarks for security experts to use, but that it won’t necessarily be for all aspects of security. Still, they’ll be a great tool to help security organizations plan ahead for their next steps. 

    They also discuss the importance of cross functional collaboration, why your team should build relationships outside of the group, and how regulatory bodies are driving change. 

    Topics discussed:

    - The importance of building relationships within your team and outside of it.
    - Why SLAs will become a benchmark for security leaders to use for planning their next business steps.
    - How security leaders can work with their teams, partners such as engineers, and stakeholders to make sure they stay on track and keep focus.
    - How product managers can help facilitate projects by understanding what each stakeholder needs.
    - How security transcends barriers by becoming a business enabler, shifting from a restrictive function to one that supports and enhances organizational objectives and growth.
    - The importance of cross functional collaboration.
    - How scrutiny from regulatory bodies such as the SEC is driving change.

    • 27 min
    EP 56 — Aruneesh Salhotra on Why Security is Everyone’s Job

    EP 56 — Aruneesh Salhotra on Why Security is Everyone’s Job

    In this episode of the Future of Application Security, Harshil speaks with Aruneesh Salhotra, CEO and Fractional CISO, SNM Consulting Inc. They discuss the unique challenges and opportunities of application security in the financial sector, including how the ”necessary evil” of regulations is increasing accountability around security efforts. They also talk about the need for more vigilant software supply chain security, two better approaches to vulnerability management, and how AI can create self-sufficiency among developers.

    Topics discussed:

    - The ”necessary evil” of regulations and how they’re increasing accountability around data storage, pen testing, and more.
    - Two approaches security teams can take to better manage application vulnerabilities: a call graph and runtime SCA.
    - What your attack surface is and how to effectively manage it.
    - The increasing importance of software supply chain security and the value of establishing an open source program office.
    - Why security should be everyone’s job and how adopting security today will bear fruit tomorrow.
    - How AI can increase developer self-sufficiency by giving feedback and insights on security actions.

    • 24 min
    EP 55 — BlackBerry's Christine Gadsby on What's Driving Software Supplier Transparency and Accountability

    EP 55 — BlackBerry's Christine Gadsby on What's Driving Software Supplier Transparency and Accountability

    In this episode of the Future of Application Security, Harshil speaks with Christine Gadsby, VP, Product Security at BlackBerry, a software company specializing in cybersecurity. They discuss the new initiatives driving software transparency, like SBOMs and VEX, and how adoption will not only come from regulations but from companies holding their software suppliers more accountable. They also talk about the need for better telemetry practices and more connected tooling and how security professionals can get involved in industry change and mentorship.

    Topics discussed:

    - The important role frameworks like NIST 800-218 and CISA’s Secure By Design will play in establishing standards.
    - The ways in which SBOMs and VEX are driving software transparency that will keep customers safer.
    - How commercial industries will increase their software supplier accountability in response to the rising cost of insecurity.
    - How many companies lack knowledge about what’s in the software they sell and the importance of having good telemetry practices.
    - Why lack of good tools and the ability to connect tools is a challenge to product security today.
    - Advice to security professionals about not letting things like SBOM and VEX get away from you as you prepare for the future of software development.
    - How product security professionals can get involved with industry efforts to drive change.

    • 26 min
    EP 54 — LPL Financial's Chad Girouard on Improving Application Security Through Better Tools and Relationships

    EP 54 — LPL Financial's Chad Girouard on Improving Application Security Through Better Tools and Relationships

    In this episode of the Future of Application Security, Harshil speaks with Chad Girouard, AVP Application Security at LPL Financial, a provider of investment and business solutions. They discuss how security teams can better engage with developers, and how they can encourage secure coding through scanning tools and security champion programs. They also talk about how to manage the ”results deluge” with single-pane-of-glass tools, how AI can help with more meaningful reporting, and why security buy-in is a team effort.

    Topics discussed:

    - How to manage the various challenges of application security: competing tools, relationships, maturity, and more.
    - How to bridge the different priorities of security teams and developers.
    - How to encourage more secure coding by shifting left and developing a security champions program.
    - Why leading and implementing security buy-in and processes is a team effort across the organization.
    - How to manage today’s “results deluge” with single-pane-of-glass tools and more meaningful reporting.
    - How AI can help discern real findings from all the information that a security team collects.

    • 23 min

Customer Reviews

5.0 out of 5
3 Ratings

3 Ratings

Top Podcasts In Business

The Ramsey Show
Ramsey Network
REAL AF with Andy Frisella
Andy Frisella #100to0
Money Rehab with Nicole Lapin
Money News Network
Prof G Markets
Vox Media Podcast Network
The Prof G Pod with Scott Galloway
Vox Media Podcast Network
The Money Mondays
Dan Fleyshman

You Might Also Like

The Application Security Podcast
Chris Romeo and Robert Hurlbut
The Security Table
Izar Tarandach, Matt Coles, and Chris Romeo
Application Security Weekly (Video)
Security Weekly
Cyber Security Headlines
CISO Series
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
401 Access Denied
Delinea