PodcastsTechnologiesThe Elephant in AppSec

The Elephant in AppSec

The Elephant in AppSec
The Elephant in AppSec
Dernier épisode

87 épisodes

  • The Elephant in AppSec

    25 years of the same problem in Application Security - Sam Stepanyan

    22/04/2026 | 37 min
    Today, I’m joined by Sam Stepanyan,  an OWASP Global Board member and an OWASP London Chapter Leader. Sam is an Independent Application Security Consultant and Security Architect with over 20 years of experience in the IT industry.
    Sam has worked for various financial services institutions in the City of London specialising in Application Security consulting, Secure Software Development Lifecycle (SDLC), developer training, source code reviews and vulnerability management. 
    He is also a Subject Matter Expert in Web Application Firewalls (WAF) and SIEM systems.
    In this episode, we explore why, despite OWASP being around for over 25 years, many developers are still unaware of it—and why shifting focus toward developer conferences might be key to spreading security knowledge more effectively.
    We also discuss the impact of AI on modern security practices, the growing role of automated penetration testing tools, and how even small changes—like adding the word “secure” to a vibe coding prompt—can help nudge developers toward more security-conscious decisions.
    Dive right in! 
    This podcast is brought to you by
    Escape: https://escape.tech  — Offensive security for the teams that are 100x outnumbered, combining Attack Surface Management, business-logic-aware DAST and AI pentesting solutions.
  • The Elephant in AppSec

    Should security belong in every AI strategy meeting? with Amol Deshpande

    29/12/2025 | 47 min
    Today, I’m joined by Amol Deshpande, a seasoned security engineer currently at Stripe, where he focuses on building secure systems at massive scale. With a background spanning product security and penetration testing at companies like Salesforce, Splunk, and Early Warning, Amol brings deep hands-on experience in securing complex, real-world platforms.
    He’s also been a HackMIT judge and a long-time CTF competitor at DEF CON, giving him a very practical view of modern security challenges.
    In this episode, we cover whether security must now belong in every AI strategy meeting, and how to embed it into AI development from the outset.
    We also touch on how privacy concerns will only grow as agents are trained on sensitive data and why human oversight is essential for critical AI operations.
    Dive right in!
  • The Elephant in AppSec

    What Mindset Shift Developers Need to Break Into Security? with Aleksandra Kornecka

    24/12/2025 | 38 min
    Today, I’m joined by Aleksandra Kornecka, a security engineer with a global mindset. She recently transitioned from Senior AppSec Engineer to Cloud Infrastructure Security Engineer, and has a background in software testing and cognitive science — a combination that gives her a unique take on both the technical and human sides of security.As a member of the OWASP Security Champions Guide and the project's Artifact stream, Aleksandra also put efforts to collect templates, documents, and other artifacts useful to build the security champions program.In this episode, we dive into the mindset shift developers need to successfully break into security and why security champions are critical for scaling security awareness across organizations.We also explore how curiosity fuels a lasting passion for security, and unpack why Zero Trust is often misunderstood and overhyped.Dive right in!
  • The Elephant in AppSec

    Is the AI–API interaction the biggest security blind spot? with Gowtham Sundar

    20/12/2025 | 31 min
    Today, I’m joined by Gowtham Sundar, a Senior Lead Engineer - 3A Security (AI and API included as you can guess) at SPH Media and a seasoned AppSec leader with over a decade of experience across enterprise security, penetration testing, and secure product development.
    In this episode, Gowtham brings a real practitioner’s point of view on what it actually takes to secure AI systems. We dive into why APIs are at the heart of AI, why securing them is non-negotiable, and why automated API discovery is becoming critical for governance as systems scale.
    We also talk about how AI security is evolving at lightning speed, sometimes changing week by week, and what that means for security teams trying to keep up.
    And with that, get ready to hear Gowtham’s opinions.
    Dive right in!
  • The Elephant in AppSec

    What best drives the adoption of secure software practices? with Enrique Larios Vargas

    11/12/2025 | 38 min
    Today, I’m joined by Enrique Larios Vargas, a Security and Learning Specialist at Adyen.
    Enrique has over eight years of experience designing impactful learning and enablement programs across fintech, engineering, and security. He’s also been a university lecturer in software engineering in Peru, the Netherlands, and Canada.
    Bringing together technical expertise and behavioral science, Enrique is passionate about helping developers move beyond compliance and build a meaningful, human-centered security culture.
    In this episode, we dive into his research paper, “DASP: A Framework for Driving the Adoption of Software Security Practices,” co-authored with five others (all listed in the description). The paper explores how behavioral models like COM-B can drive secure development practices.
    We also get into incentives and Enrique’s controversial take on why we shouldn’t call security champions “champions” anymore. He’ll even be put to the test on this topic at the upcoming Elephant in AppSec conference, where he’ll debate it with other panelists.
    Dive right in!

Plus de podcasts Technologies

À propos de The Elephant in AppSec

Time to discuss AppSec issues no one talks about.
Site web du podcast

Écoutez The Elephant in AppSec, Comptoir IA 🎙️🧠🤖 ou d'autres podcasts du monde entier - avec l'app de radio.fr

Obtenez l’app radio.fr
 gratuite

  • Ajout de radios et podcasts en favoris
  • Diffusion via Wi-Fi ou Bluetooth
  • Carplay & Android Auto compatibles
  • Et encore plus de fonctionnalités
Applications
Réseaux sociaux
v8.8.13| © 2007-2026 radio.de GmbH
Generated: 4/30/2026 - 9:11:59 AM