Join host Chris Lindsey as he digs into the world of Application Security with experts from leading enterprises. Each episode is theme based, so it's more conversational and topic based instead of the general interview style. Our focus is growing your knowledge, providing useful tips and advice. With Chris' development background of 35 years, 15+ years of secure coding and 3+ years running an application security program for large enterprise, the conversations will be deep and provide a lot of good takeaway's that you can use almost immediately.

Secrets of AppSec Champions
Claim This Podcastby Chris Lindsey
Podcast Authority
Beta
Podcast Overview
Join host Chris Lindsey as he digs into the world of Application Security with experts from leading enterprises. Each episode is theme based, so it's more conversational and topic based instead of the general interview style. Our focus is growing your knowledge, providing useful tips and advice. With Chris' development background of 35 years, 15+ years of secure coding and 3+ years running an application security program for large enterprise, the conversations will be deep and provide a lot of good takeaway's that you can use almost immediately.
Language
🇺🇲
Publishing Since
7/28/2024
Unlock The Full Podcast Authority Score Report
See how your podcast performs across key metrics
Podcast Authority
Beta
Recommendations available
Unlock the full report to see detailed tips
Recommendations available
Unlock the full report to see detailed tips
Unlock comprehensive insights including:
- • YouTube presence analysis
- • Social media reach metrics
- • RSS compliance scoring
- • Podcast 2.0 features
- • Technical standards
Detailed Analytics
- Complete breakdown of all 19 authority metrics
- Personalized recommendations for each metric
- Industry benchmarks and comparisons
- Technical RSS feed analysis and compliance scoring
Growth Strategies
- Step-by-step action plans for improvement
- Quick wins to boost your score immediately
- Pro tips from successful podcasters
See how your show performs across every key metric
High authority scores make your podcast more attractive to industry leaders and influencers who want to appear on credible shows.
Sponsors look for podcasts with proven authority and engagement. Your score demonstrates your podcast's value to potential partners.
Understanding your strengths and weaknesses helps you make data-driven decisions to expand your listener base effectively.
1 verified contact email on file for Secrets of AppSec Champions
Pitch yourself as a guest, propose sponsorships, or reach out directly to the host.
Recent Episodes

July 31, 2025
Building Security Programs That Actually Scale – with Bonnie Viteri | Secrets of AppSec Champions 🎙️
<p>Building great security programs takes more than checklists and best practices—it takes vision, collaboration, and adaptability. In this episode, Bonnie Viteri, Principal Technical Security Engineer at Yahoo, shares how to build scalable, resilient programs that evolve, survive leadership turnover, and actually provide value to the business.</p><p>🔔 Subscribe for more practical AppSec insights:<br>https://www.youtube.com/channel/UCLgzXoXJ-TGO-y7Eh9quDUQ?sub_confirmation=1</p><p>Chapters:<br>00:00 – Start with the End: Vision-Driven Program Design<br>01:08 – Meet Bonnie Viteri: From Behavioral Psychology to Cybersecurity<br>02:10 – Foundation First: Mission, Vision, and Cross-Team Buy-In<br>04:07 – Designing Security Documents with Developers, Not for Them<br>06:00 – Metrics, Failure, and the Power of Feedback Loops<br>08:25 – People, Process, or Tech? Defining the Program Purpose<br>09:31 – Five-Year Plans and Building for Scale<br>12:26 – Implementation: Ownership, Handoffs, and Real-World Use<br>14:15 – Documentation That Survives Team Turnover<br>16:51 – Centralizing Knowledge and Making It Discoverable<br>18:30 – Program Optimization Through Onboarding and Culture<br>20:48 – Keeping Programs Alive via Security Champions & Internal Comms<br>22:25 – Case Study: API Security Documentation That Worked<br>25:19 – Reporting Program Value in Business Language<br>27:03 – Best Advice: "Your Fire Isn’t My Fire"<br>29:11 – Worst Advice: “You’d Be Bored as a Manager”<br>29:58 – Final Thoughts: Build, Fail Fast, Pivot Smarter</p><p>What You’ll Learn:<br>- How to build and scale a security program across teams<br>- Why collaboration and early buy-in matter<br>- Strategies for long-term documentation and program handoff<br>- How to connect program value to business language and executive metrics<br>- Real-world case study of API security success at scale</p><p>📺 Watch Next:<br>▶️ Secrets of AppSec Champions Podcast: https://www.youtube.com/playlist?list=PLR-uH0PJFszFcbMJ29AfAcWIJAPbBJaC7<br>▶️ Our Customers’ Success Stories & Reviews: https://youtube.com/playlist?list=PLR-uH0PJFszHDC0p6CBEvccqx1uNx8fpT&si=SUI6d31ResR51434<br>▶️ OWASP Top 10 LLM is Dead: Here's Why: https://youtu.be/Wet1tkt1eAw?si=NTUef42qt1WzcHbn<br>▶️ Mend.io Product Overview Demo: https://youtu.be/HfZ3uK-Eg5c<br>▶️ The Truth Behind Successful Security Operations Centers (SOC): https://youtu.be/XMlrxoIJVXg</p><p>🌐 Connect with Us:<br>🔗 Website: https://www.mend.io<br>🐦 Twitter: https://twitter.com/mend_io<br>📘 Facebook: https://www.facebook.com/mendappsec<br>💼 LinkedIn: https://www.linkedin.com/company/2440656</p><p>📜 Disclaimer:<br>This video is for educational purposes only. Mend.io is not responsible for any security decisions made based on this content.</p><p>#appsecurity #cybersecurity #cybersecurityexperts </p><p>Mend.io, formerly known as Whitesource, has over a decade of experience helping global organizations build world-class AppSec programs that reduce risk and accelerate development -– using tools built into the technologies that software and security teams already love. Our automated technology protects organizations from supply chain and malicious package attacks, vulnerabilities in open source and custom code, and open-source license risks. With a proven track record of successfully meeting complex and large-scale application security needs, Mend.io is the go-to technology for the world’s most demanding development and security teams. The company has more than 1,000 customers, including 25 percent of the Fortune 100, and manages Renovate, the open source automated dependency update project. For more information, visit www.mend.io, the Mend.io blog, and Mend.io on LinkedIn and Twitter.</p>

July 17, 2025
Risk Mitigation and Cybersecurity Strategy with Samuel Brown | Secrets of AppSec Champions Podcast🎙️
<p>As cyber threats evolve, so must the strategies to prevent them. In this episode, Samuel Brown—CEO of PacketX and retired U.S. Army CW4—shares mission-critical insights on risk mitigation, layered security, and why backups and plans on paper aren't enough. From ransomware recovery to real-world network defense, this conversation is packed with hard-earned lessons for AppSec professionals and business leaders alike.</p><p>🔔 Subscribe for real-world insights and actionable AppSec stories:<br>https://www.youtube.com/channel/UCLgzXoXJ-TGO-y7Eh9quDUQ?sub_confirmation=1</p><p>Chapters:<br>00:00 – What Real Risk Mitigation Requires<br>00:55 – Meet Samuel Brown: CEO of PacketX & U.S. Army Veteran<br>02:43 – Risk Identification, Tiering, and Business Impact<br>04:28 – Ransomware Lessons: Why Tested Backups Matter<br>07:01 – Data vs. Devices: Smart Prioritization Decisions<br>08:13 – Ransomware Response: Steps to Contain and Recover<br>09:44 – Real-World Example: Website Compromise and Layered Security<br>11:14 – MFA and Role-Based Access: Core to Risk Reduction<br>13:47 – CAC Cards & Military Insights on Access Control<br>16:44 – Firewalls, Segmentation & Vendor Diversity<br>20:42 – Patch Management: Fixing Without Rebreaking<br>23:58 – Least Privilege: Why Admin Rights Are Dangerous<br>26:33 – Why Small Businesses Are Easy Targets<br>28:27 – Simple Risk Monitoring Tips for Any Company<br>30:43 – Best & Worst Advice in Cybersecurity<br>32:47 – Closing Thoughts & Call to Subscribe</p><p>What You’ll Learn:<br>- How to build a real, tested risk mitigation plan<br>- Why backups fail without proper testing<br>- Critical layers of defense: from firewalls to user training<br>- How military cybersecurity practices apply to private business<br>- The one mindset that can prevent massive breaches</p><p>📺 Watch Next:<br>▶️ Secrets of AppSec Champions Podcast: https://www.youtube.com/playlist?list=PLR-uH0PJFszFcbMJ29AfAcWIJAPbBJaC7<br>▶️ Our Customers’ Success Stories & Reviews: https://youtube.com/playlist?list=PLR-uH0PJFszHDC0p6CBEvccqx1uNx8fpT&si=SUI6d31ResR51434<br>▶️ OWASP Top 10 LLM is Dead: Here's Why: https://youtu.be/Wet1tkt1eAw?si=NTUef42qt1WzcHbn<br>▶️ Mend.io Product Overview Demo: https://youtu.be/HfZ3uK-Eg5c<br>▶️ The Truth Behind Successful Security Operations Centers (SOC): https://youtu.be/XMlrxoIJVXg</p><p>🌐 Connect with Us:<br>🔗 Website: https://www.mend.io<br>🐦 Twitter: https://twitter.com/mend_io<br>📘 Facebook: https://www.facebook.com/mendappsec<br>💼 LinkedIn: https://www.linkedin.com/company/2440656</p><p>📜 Disclaimer:<br>This video is for educational purposes only. Mend.io is not responsible for any security decisions made based on this content.</p><p>#Cybersecurity #RiskMitigation #AppSec #Infosec</p><p>Mend.io, formerly known as Whitesource, has over a decade of experience helping global organizations build world-class AppSec programs that reduce risk and accelerate development - using tools built into the technologies that software and security teams already love. Our automated technology protects organizations from supply chain and malicious package attacks, vulnerabilities in open source and custom code, and open-source license risks. With a proven track record of successfully meeting complex and large-scale application security needs, Mend.io is the go-to technology for the world’s most demanding development and security teams. The company has more than 1,000 customers, including 25 percent of the Fortune 100, and manages Renovate, the open source automated dependency update project. For more information, visit www.mend.io, the Mend.io blog, and Mend.io on LinkedIn and Twitter.</p>

July 3, 2025
From Developer to Cybersecurity Without Certs – Ed Urbasius' Story | Secrets of AppSec Champions 🎙️
Edvinas Urbasius shares his journey from developer to cybersecurity consultant without formal certifications, highlighting the importance of on-the-job learning in a Security Operations Center in this interview.
15 total episodes available
Recent guests on Secrets of AppSec Champions
Guests from recent episodes — sign up to see every guest that has ever appeared on this show.
Edvinas Urbasius
Guest
Deep-dive analytics for Secrets of AppSec Champions
Frequently asked questions
Have a different question and can't find the answer you're looking for? Reach out to our support team by sending us an email and we'll get back to you as soon as we can.
- What is Secrets of AppSec Champions?
- How often does this podcast release new episodes?
This podcast updates bi-weekly.
- Where can I listen to this podcast?
This podcast is available on 9 platforms including Apple Podcasts, Spotify, and more. You can also use the RSS feed directly.
- Does this podcast accept guests?
Yes, this podcast regularly features guests.
Legal Disclaimer
Pod Engine is not affiliated with, endorsed by, or officially connected with any of the podcasts displayed on this platform. We operate independently as a podcast discovery and analytics service.
All podcast artwork, thumbnails, and content displayed on this page are the property of their respective owners and are protected by applicable copyright laws. This includes, but is not limited to, podcast cover art, episode artwork, show descriptions, episode titles, transcripts, audio snippets, and any other content originating from the podcast creators or their licensors.
We display this content under fair use principles and/or implied license for the purpose of podcast discovery, information, and commentary. We make no claim of ownership over any podcast content, artwork, or related materials shown on this platform. All trademarks, service marks, and trade names are the property of their respective owners.
While we strive to ensure all content usage is properly authorized, if you are a rights holder and believe your content is being used inappropriately or without proper authorization, please contact us immediately at hey@podengine.ai for prompt review and appropriate action, which may include content removal or proper attribution.
By accessing and using this platform, you acknowledge and agree to respect all applicable copyright laws and intellectual property rights of content owners. Any unauthorized reproduction, distribution, or commercial use of the content displayed on this platform is strictly prohibited.