89 épisodes
Why Security Loses Influence in High-Growth Companies (And What to Do About It) with Kavia Venkatesh
20/05/2026 | 31 minToday, I'm joined by Kavia Venkatesh, Director of Product Security at a large healthcare organization. She didn't take the traditional path into cybersecurity — she came from biotech. But that outsider lens turned out to be her edge.
With over 10 years of experience leading cybersecurity strategy for hyper-scale ecosystems, she's built many security programs from the ground up, navigating 9 acquisitions in 18 months at a large tech org, and along the way developed a rare ability to translate risk into language that executives actually act on.
Kavia is also a frequent speaker at premier global conferences, including DEF CON, BSides San Francisco, and Nullcon.
In this episode, we talked about what most security teams get completely wrong during integrations, what she'd change about how security teams show up in organizations and the "breachability mindset" that changes how you approach risk.
And much more!
Get ready, Kavia doesn't hold back her opinions. Let's dive right in!
This podcast is brought to you by Escape: https://escape.tech — Offensive security for the teams that are 100x outnumbered, combining Attack Surface Management, business-logic-aware DAST and AI pentesting solutions.
Connect with Kavia: https://www.linkedin.com/in/kaviavenkatesh/- Today, I’m joined by Jason Fernandes, VP of security and privacy at Mercari, the Japanese-born global marketplace now spanning e-commerce, FinTech, and crypto. It is this rare combination that puts him at the intersection of some of the strictest regulatory environments in tech.
He oversees everything from product and platform security to threat detection, privacy, and, since last year, AI security and AI governance.
In this episode, we also talked about the challenges of AI governance, the lethal trifecta for AI agents, the confused deputy problem, and how to justify AI security investments to the leadership and working with FinOps teams. And much more!
Dive right in!
This podcast is brought to you by
Escape: https://escape.tech — Offensive security for the teams that are 100x outnumbered, combining Attack Surface Management, business-logic-aware DAST and AI pentesting solutions.
Mentioned
FACADE (Google's internal fraud detection model) https://arxiv.org/abs/2412.06700
Meta Practical AI Agent Security (Rule of Two) https://ai.meta.com/blog/practical-ai-agent-security/
Simon Willison The Lethal Trifecta https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/
Hiroki's AI Security blog (Mercari) https://hi120ki.github.io/blog/posts/20260103/
Anthropic Project Vend https://www.anthropic.com/research/project-vend-2 - Today, I’m joined by Sam Stepanyan, an OWASP Global Board member and an OWASP London Chapter Leader. Sam is an Independent Application Security Consultant and Security Architect with over 20 years of experience in the IT industry.
Sam has worked for various financial services institutions in the City of London specialising in Application Security consulting, Secure Software Development Lifecycle (SDLC), developer training, source code reviews and vulnerability management.
He is also a Subject Matter Expert in Web Application Firewalls (WAF) and SIEM systems.
In this episode, we explore why, despite OWASP being around for over 25 years, many developers are still unaware of it—and why shifting focus toward developer conferences might be key to spreading security knowledge more effectively.
We also discuss the impact of AI on modern security practices, the growing role of automated penetration testing tools, and how even small changes—like adding the word “secure” to a vibe coding prompt—can help nudge developers toward more security-conscious decisions.
Dive right in!
This podcast is brought to you by
Escape: https://escape.tech — Offensive security for the teams that are 100x outnumbered, combining Attack Surface Management, business-logic-aware DAST and AI pentesting solutions. - Today, I’m joined by Amol Deshpande, a seasoned security engineer currently at Stripe, where he focuses on building secure systems at massive scale. With a background spanning product security and penetration testing at companies like Salesforce, Splunk, and Early Warning, Amol brings deep hands-on experience in securing complex, real-world platforms.
He’s also been a HackMIT judge and a long-time CTF competitor at DEF CON, giving him a very practical view of modern security challenges.
In this episode, we cover whether security must now belong in every AI strategy meeting, and how to embed it into AI development from the outset.
We also touch on how privacy concerns will only grow as agents are trained on sensitive data and why human oversight is essential for critical AI operations.
Dive right in! What Mindset Shift Developers Need to Break Into Security? with Aleksandra Kornecka
24/12/2025 | 38 minToday, I’m joined by Aleksandra Kornecka, a security engineer with a global mindset. She recently transitioned from Senior AppSec Engineer to Cloud Infrastructure Security Engineer, and has a background in software testing and cognitive science — a combination that gives her a unique take on both the technical and human sides of security.As a member of the OWASP Security Champions Guide and the project's Artifact stream, Aleksandra also put efforts to collect templates, documents, and other artifacts useful to build the security champions program.In this episode, we dive into the mindset shift developers need to successfully break into security and why security champions are critical for scaling security awareness across organizations.We also explore how curiosity fuels a lasting passion for security, and unpack why Zero Trust is often misunderstood and overhyped.Dive right in!
Plus de podcasts Technologies
Podcasts tendance de Technologies
À propos de The Elephant in AppSec
Time to discuss AppSec issues no one talks about.
Site web du podcastÉcoutez The Elephant in AppSec, Tech&Co, la quotidienne ou d'autres podcasts du monde entier - avec l'app de radio.fr

Obtenez l’app radio.fr gratuite
- Ajout de radios et podcasts en favoris
- Diffusion via Wi-Fi ou Bluetooth
- Carplay & Android Auto compatibles
- Et encore plus de fonctionnalités
Obtenez l’app radio.fr gratuite
- Ajout de radios et podcasts en favoris
- Diffusion via Wi-Fi ou Bluetooth
- Carplay & Android Auto compatibles
- Et encore plus de fonctionnalités


The Elephant in AppSec
Scannez le code,
Téléchargez l’app,
Écoutez.
Téléchargez l’app,
Écoutez.




































