The Security Champions Podcast

Mike Burch

Automation, Generative AI, Shift Left - the world of application security is evolving fast, and so are the conversations that shape it. Welcome to The Security Champions Podcast, the go-to resource for insights from the front lines of application security. The podcast is cohosted by Michael Burch, Director of Application Security for Security Journey, and Dustin Lehr, the Director of AppSec Advocacy. Each month, one of them shares a candid conversation with security leaders, engineering voices, and software experts.  From championing secure development practices to navigating real-world challenges in modern SDLCs, this show explores how teams are scaling appsec, strategy and culture.  New Episodes drop monthly, with even more security content at https://www.securityjourney.com/ Always remember: Security is a Journey, not a Destination. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ This podcast is sponsored by Security Journey. FOLLOW US to stay up-to-date with new content!X (https://x.com/SecurityJourney)LinkedIn (https://www.linkedin.com/company/7574213)Instagram (https://www.instagram.com/securityjourney/?hl=en)YouTube (https://www.youtube.com/@UCBVPnBCNcZqx_WAuCsV6BuA )Online (securityjourney.com)CONTACT: hello@securityjourney.com

  1. 6 мая

    Spandana Sarala Gorantla - Scaling Security: How AI and Collaboration Transform Threat Modeling

    Spandana Sarala Gorantla is a Senior Product Security Engineer at Adobe, specializing in product security, threat modeling, and secure development practices. She is passionate about making threat modeling collaborative, practical, and scalable, especially as AI and agentic systems reshape how teams build software. Spandana joined The Security Champions Podcast to discuss why threat modeling matters more than ever in the age of AI. In this episode, she shares how threat modeling became a central part of her security career, why collaboration across engineering, product, business, and security teams is essential, and how AI can help scale early risk identification without replacing human judgment. The conversation explores practical approaches to threat modeling, the role of Security Champions, and why frameworks like STRIDE and MAESTRO can help teams ask better questions about modern systems. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Podcast sponsored by Security Journey, Secure Coding Training for Developers and Everyone in the SDLC. Learn more at securityjourney.com.  FOLLOW US to stay up-to-date with new content! LinkedIn (linkedin.com/company/security-journey)  Instagram (https://www.instagram.com/securityjourney)YouTube (youtube.com/c/securityjourney)Twitter (twitter.com/SecurityJourney)Online (securityjourney.com)  CONTACT: hello@securityjourney.com Get your free VIBE Coding Field Guide: https://hubs.ly/Q043-zdS0

  2. 8 апр.

    Nariman Aga-Tagiyev - Understanding the EU Cyber Resiliency Act: What You Need to Know

    Nariman Aga-Tagiyev is an application security expert with over two decades of experience in software development across diverse technology stacks, including cloud-native environments. Since 2016, he has been in charge of the Application Security program and the Secure Software Development Lifecycle, with deep expertise in frameworks such as BSIMM, OWASP SAMM, and NIST SSDF.  In this episode, Nariman breaks down the EU Cyber Resilience Act (CRA) and why it’s far more than a regional regulation. It’s a global shift in how software security is expected to be built and maintained. He explains what the CRA requires, how it impacts software vendors and open source, and what “secure by design” really looks like in practice. The conversation also covers practical steps teams can take today to prepare, without overcomplicating their approach. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Podcast sponsored by Security Journey, Secure Coding Training for Developers and Everyone in the SDLC. Learn more at securityjourney.com.  FOLLOW US to stay up-to-date with new content! LinkedIn (linkedin.com/company/security-journey)  Instagram (https://www.instagram.com/securityjourney)YouTube (youtube.com/c/securityjourney)Twitter (twitter.com/SecurityJourney)Online (securityjourney.com)  CONTACT: hello@securityjourney.com Get your free VIBE Coding Field Guide: https://hubs.ly/Q043-zdS0

Об этом подкасте

Automation, Generative AI, Shift Left - the world of application security is evolving fast, and so are the conversations that shape it. Welcome to The Security Champions Podcast, the go-to resource for insights from the front lines of application security. The podcast is cohosted by Michael Burch, Director of Application Security for Security Journey, and Dustin Lehr, the Director of AppSec Advocacy. Each month, one of them shares a candid conversation with security leaders, engineering voices, and software experts.  From championing secure development practices to navigating real-world challenges in modern SDLCs, this show explores how teams are scaling appsec, strategy and culture.  New Episodes drop monthly, with even more security content at https://www.securityjourney.com/ Always remember: Security is a Journey, not a Destination. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ This podcast is sponsored by Security Journey. FOLLOW US to stay up-to-date with new content!X (https://x.com/SecurityJourney)LinkedIn (https://www.linkedin.com/company/7574213)Instagram (https://www.instagram.com/securityjourney/?hl=en)YouTube (https://www.youtube.com/@UCBVPnBCNcZqx_WAuCsV6BuA )Online (securityjourney.com)CONTACT: hello@securityjourney.com