PodcastsTechnologiesThe Elephant in AppSec

The Elephant in AppSec

The Elephant in AppSec
The Elephant in AppSec
Dernier épisode

85 épisodes

  • The Elephant in AppSec

    What Mindset Shift Developers Need to Break Into Security? with Aleksandra Kornecka

    24/12/2025 | 38 min

    Today, I’m joined by Aleksandra Kornecka, a security engineer with a global mindset. She recently transitioned from Senior AppSec Engineer to Cloud Infrastructure Security Engineer, and has a background in software testing and cognitive science — a combination that gives her a unique take on both the technical and human sides of security.As a member of the OWASP Security Champions Guide and the project's Artifact stream, Aleksandra also put efforts to collect templates, documents, and other artifacts useful to build the security champions program.In this episode, we dive into the mindset shift developers need to successfully break into security and why security champions are critical for scaling security awareness across organizations.We also explore how curiosity fuels a lasting passion for security, and unpack why Zero Trust is often misunderstood and overhyped.Dive right in!

  • The Elephant in AppSec

    Is the AI–API interaction the biggest security blind spot? with Gowtham Sundar

    20/12/2025 | 31 min

    Today, I’m joined by Gowtham Sundar, a Senior Lead Engineer - 3A Security (AI and API included as you can guess) at SPH Media and a seasoned AppSec leader with over a decade of experience across enterprise security, penetration testing, and secure product development.In this episode, Gowtham brings a real practitioner’s point of view on what it actually takes to secure AI systems. We dive into why APIs are at the heart of AI, why securing them is non-negotiable, and why automated API discovery is becoming critical for governance as systems scale.We also talk about how AI security is evolving at lightning speed, sometimes changing week by week, and what that means for security teams trying to keep up.And with that, get ready to hear Gowtham’s opinions. Dive right in!

  • The Elephant in AppSec

    What best drives the adoption of secure software practices? with Enrique Larios Vargas

    11/12/2025 | 38 min

    Today, I’m joined by Enrique Larios Vargas, a Security and Learning Specialist at Adyen.Enrique has over eight years of experience designing impactful learning and enablement programs across fintech, engineering, and security. He’s also been a university lecturer in software engineering in Peru, the Netherlands, and Canada.Bringing together technical expertise and behavioral science, Enrique is passionate about helping developers move beyond compliance and build a meaningful, human-centered security culture.In this episode, we dive into his research paper, “DASP: A Framework for Driving the Adoption of Software Security Practices,” co-authored with five others (all listed in the description). The paper explores how behavioral models like COM-B can drive secure development practices.We also get into incentives and Enrique’s controversial take on why we shouldn’t call security champions “champions” anymore. He’ll even be put to the test on this topic at the upcoming Elephant in AppSec conference, where he’ll debate it with other panelists.Dive right in!

  • The Elephant in AppSec

    Why AppSec Needs More Than Just a Checkbox ⎢ Marcos Vinicius Cassel

    03/12/2025 | 42 min

    Today, I’m joined by Marcos Vinicius Cassel, Application Security Manager at PowerSchool.With over a decade of experience in the information security space, as a CISSP, ISO 27001 Lead Auditor, and a passionate technologist, Marcos has led security initiatives across multiple industries. He also previously led the OWASP Porto Alegre Chapter, and fun fact: we first met while volunteering together at BSides SF!In this episode, we dive into the real value of certifications in application security, how they can provide structure and credibility, but shouldn’t define a professional’s entire skill set. We also unpack the balance between compliance and risk management and between privacy and innovation, and why strong communication between security and engineering teams is more essential than ever.And with that, get ready to hear Marcos’ opinions.Dive right in!

  • The Elephant in AppSec

    The Supply Chain Crisis We Created: How AI, Extensions, and Dependencies Became the New Attack Surface with Aamiruddin Syed

    26/11/2025 | 40 min

    Today, I’m joined by Aamiruddin Syed, Senior Product Security Engineer at AGCO Corporation. Aamiruddin is the author of “Supply Chain Software Security book focusing on AI, IoT, and AppSec” and a recognized advocate for secure development. He’s a frequent speaker at major conferences, including RSA, DEFCON, and Black Hat.Fun facts: he was once ranked in the top 1% of all TryHackMe penetration testers, and a memorable milestone in his career was delivering a Cybersecurity Awareness talk to officer trainees of the Indian Army.He’s also a fellow podcaster, co-hosting the CyberGPT Pulse Podcast.In this episode, we dive into the complexities of software supply chain security, especially the risks introduced by third-party extensions, and how generative AI can strengthen defenses across the supply chain.We also explore the challenges of data quality when training AI models and discuss why strong governance is essential for secure developer practices.Dive right in!

Plus de podcasts Technologies

À propos de The Elephant in AppSec

Time to discuss AppSec issues no one talks about.
Site web du podcast

Écoutez The Elephant in AppSec, Underscore_ ou d'autres podcasts du monde entier - avec l'app de radio.fr

Obtenez l’app radio.fr
 gratuite

  • Ajout de radios et podcasts en favoris
  • Diffusion via Wi-Fi ou Bluetooth
  • Carplay & Android Auto compatibles
  • Et encore plus de fonctionnalités
Applications
Réseaux sociaux
v8.2.1 | © 2007-2025 radio.de GmbH
Generated: 12/25/2025 - 2:58:43 AM