Podcast thumbnail for Seeding AppSec

Seeding AppSec

Claim This Podcast

by Arnica IO

5.0(3 reviews)
6 episodes
Updated Daily
Accepts GuestsHas Sponsors

Podcast Overview

Tune into "Seeding AppSec" for an insightful exploration into the dynamic world of application security. This episode spotlights the freshest trends and offers firsthand insights from global AppSec leaders. What You'll Learn: The forefront of application security trends and their significance. Expert takes on tackling current AppSec challenges. An introduction to Arnica's innovative security solutions, enhancing risk identification and management without hindering development speed. As cyber threats magnify, grasping AppSec becomes imperative for businesses, developers, and users.

Language

🇺🇲

Publishing Since

8/8/2023

1 verified contact email on file for Seeding AppSec

Pitch yourself as a guest, propose sponsorships, or reach out directly to the host.

Recent Episodes

Episode thumbnail for Lessons Learned from Securing Security Products

October 2, 2023

Lessons Learned from Securing Security Products

<p><a href="https://www.linkedin.com/in/ACoAAAAArJwB8cI_u85lsBnQwH8hg3Ob2UJblZ4">Lenny Zeltser</a> is as brilliant as he is prolific – a true thought leader in <a href="https://www.linkedin.com/feed/hashtag/?keywords=security&highlightedUpdateUrns=urn%3Ali%3Aactivity%3A7108570524615659520">#security</a> and <a href="https://www.linkedin.com/feed/hashtag/?keywords=applicationsecurity&highlightedUpdateUrns=urn%3Ali%3Aactivity%3A7108570524615659520">#applicationsecurity</a> in particular. Lenny, holds a rare post as the <a href="https://www.linkedin.com/feed/hashtag/?keywords=ciso&highlightedUpdateUrns=urn%3Ali%3Aactivity%3A7108570524615659520">#CISO</a> of a serious and successful security business, Axonius. He builds security programs from within a security company! </p> <p><br></p> <p>On this episode of Seeding AppSec, we discuss with Lenny what lessons he has learned from this unique perspective. With your hosts: <a href="https://www.linkedin.com/in/ACoAAARNj9cBAhBMRD657nLzGL8yaqI9R4ev9o0">Nir Valtman</a> (CEO of Arnica) &amp; <a href="https://www.linkedin.com/in/ACoAAAaZxmoBWMy19FTMCCtm8GqwwbX1WB45coY">Simon A. Wenet</a> (Head of Growth at Arnica)</p> <p><br></p> <p>What we cover in this episode:</p> <p><strong>[00:00 - 10:25] - Security: An Interdisciplinary Pursuit</strong></p> <ul> <li><p>Lenny recalls his early career experiences with firewalls, networking, and intrusion detection. He was drawn to security as an intersection of multiple disciplines. </p> </li> <li><p>Lenny discusses his transition from enterprise security consulting to building security services for small businesses. It required a different cost and customer focus.</p> </li> </ul> <p><strong>[10:26 - 21:28] - The Duality of Product Management</strong></p> <ul> <li><p> As a product manager, Lenny focused more on business objectives like revenue and customer needs rather than strictly security best practices.  </p> </li> <li><p>Lenny emphasizes aligning security program efforts to overall company goals, while carefully prioritizing deficiencies.</p> </li> </ul> <p><strong>[21:29 - 39:22] - Bridging the Security &amp; Product Divide</strong></p> <ul> <li><p>Having security experience helps Lenny empathize with product teams when providing feedback from an internal user perspective.</p> </li> <li><p>Building a security program at a security company raises customer expectations for credibility. But it also provides leverage to get stakeholder buy-in.</p> </li> <li><p>Lenny stresses adding context to scanner findings to properly prioritize vulnerabilities over just risks.</p> </li> <li><p>Catching issues earlier before tickets are needed demonstrates shifting security left to development teams.</p> </li> </ul> <p><strong> [39:23-42:05] - Lightning Round &amp; Closing Thoughts.</strong></p> <ul> <li><p>Lenny shares fun facts about how he takes his coffee, advice to young security professionals, and tells us more about his blog and company.</p> </li> </ul> <p>Connect with Lenny!</p> <p>LinkedIn:<a href="https://www.linkedin.com/in/cassiogoldschmidt/"> </a><a href="https://www.linkedin.com/in/lennyzeltser/">https://www.linkedin.com/in/lennyzeltser/</a></p> <p>Blog: https://zeltser.com/</p> <p>Check out Axonius’s services at:<a href="https://www.servicetitan.com/"> </a><a href="https://www.axonius.com/">https://www.axonius.com/</a></p> <p><br></p> <p>We hope you enjoyed this edition of Seeding AppSec! Check out the latest trends in application security discussed with our esteemed guests from around the globe. Don&#39;t miss any future episodes; subscribe to Seeding AppSec on<a href="https://www.spotify.com/"> Spotify</a>,<a href="https://www.youtube.com/"> YouTube</a>,<a href="https://podcasts.google.com/feed/aHR0cHM6Ly9hbmNob3IuZm0vcy9lNjBmMjY5OC9wb2RjYXN0L3Jzcw"> Google Podcasts,</a> or<a href="https://www.apple.com/podcasts/"> Apple Podcasts</a>.</p> <p> </p> <p>This podcast is proudly brought to you by<a href="https://www.arnica.io/"> Arnica</a>, a revolutionary application security solution reshaping how AppSec teams tackle risk identification and mitigation. Explore Arnica.io for detailed information about their cutting-edge security solution, featuring real-time pipelineless risk identification and git posture management. Protect your developers, code, and products without compromising development velocity.</p> <p> </p> <p>Stay connected and informed by following<a href="https://www.arnica.io/"> Arnica.io</a> on<a href="https://www.linkedin.com/company/arnica-io/"> LinkedIn</a> and<a href="https://twitter.com/ArnicaIO"> Twitter</a> for the latest updates and insights on application security.</p> <p> </p> <p>Thank you for joining us on this enlightening journey into the world of Application Security! Remember to prioritize security and continue seeding AppSec in your organizations. Until next time, stay secure and keep innovating!</p> <p><br></p> <p><strong>Key Quotes</strong></p> <p>&quot;If you don&#39;t know how to manage your own security, then how can you help us manage ours with your solutions?&quot; - Lenny Zeltser</p> <p>&quot;If you are able to catch a new capability that&#39;s not even incorporated into the code branch and stop it early, the developer is much more likely to react positively and quickly and to actually act on the information.&quot; - Lenny Zeltser</p>

Episode thumbnail for Empowering Developers to Impact Security (Positively)

September 6, 2023

Empowering Developers to Impact Security (Positively)

<p>In our world of coding, how we think and act might be our best shield in the mix of tech and safety. It&#39;s not just the lines of code that matter, but the heart behind them. As tech keeps changing, our choices and teamwork become our guiding light, shaping a safer digital space.</p> <p><br></p> <p>In today’s episode of the Seeding AppSec, we explore the compelling parallels between software development and security with Cassio Goldschmidt. Cassio unveils the duality of backlog management and how often, in the rush of prioritization, numerous tickets find themselves lost in the shadows. But beyond tools, tactics, and processes, he delves deep into the critical role culture plays. He dives into why fostering a culture of security transcends mere compliance and becomes the bedrock for genuine progress and empowerment. And as we wrap, Cassio offers golden nuggets of advice for aspiring security professionals and shares a personal recommendation that promises serenity amidst chaos.</p> <p><br></p> <p>Whether you&#39;re a developer, a security enthusiast, or just curious about the nexus between the two, this episode promises insights that will both enlighten and entertain.</p> <p><br></p> <p><br></p> <p><strong>What we cover on the episode:</strong></p> <p><br></p> <p><strong>[00:00 - 21:18] Empowering Developers and Shifting Left</strong></p> <ul> <li>Empowering developers is crucial for secure coding and design, fostering innovation and ownership.</li> <li>Shifting left in security involves early detection and prevention of vulnerabilities, reducing future complexities and embarrassment.</li> <li>Trustworthy automation tools are vital for effective garbage-in, garbage-out prevention in the development process.</li> <li>Ensuring Git posture is essential, including verifying code reviewers&#39; identities and detecting unusual comment styles to enhance security.</li> </ul> <p><strong> </strong></p> <p><strong>[21:19 - 37:10] Security Beyond Developers</strong></p> <ul> <li>Security isn&#39;t just about developers; it also involves aspects like branching strategy, pull request reviews, and status checks.</li> <li>Address vulnerabilities early during development, as fixing them in a backlog can lead to neglect and increased risk.</li> <li>Aligning incentives between security and development is crucial for better security outcomes and involves education, automation, and empathy.</li> <li>Cultivating a culture of security is essential, fostering awareness and collaboration between security and development teams.</li> </ul> <p><br></p> <p>Connect with Cassio!</p> <p>LinkedIn: <a href="https://www.linkedin.com/in/cassiogoldschmidt/" target="_blank">https://www.linkedin.com/in/cassiogoldschmidt/</a></p> <p>Check out ServiceTitan’s services at: <a href="https://www.servicetitan.com/" target="_blank">https://www.servicetitan.com/</a></p> <p><br></p> <p>We hope you enjoyed this edition of Seeding AppSec! Check out the latest trends in application security discussed with our esteemed guests from around the globe. Don&#39;t miss any future episodes; subscribe to Seeding AppSec on <a href="https://www.spotify.com/" target="_blank">Spotify</a>, <a href="https://www.youtube.com/" target="_blank">YouTube</a>, <a href="https://podcasts.google.com/feed/aHR0cHM6Ly9hbmNob3IuZm0vcy9lNjBmMjY5OC9wb2RjYXN0L3Jzcw" target="_blank">Google Podcasts,</a> or <a href="https://www.apple.com/podcasts/" target="_blank">Apple Podcasts</a>.</p> <p> </p> <p>This podcast is proudly brought to you by <a href="https://www.arnica.io/" target="_blank">Arnica</a>, a revolutionary application security solution reshaping how AppSec teams tackle risk identification and mitigation. Explore Arnica.io for detailed information about their cutting-edge security solution, featuring real-time pipelineless risk identification and git posture management. Protect your developers, code, and products without compromising development velocity.</p> <p> </p> <p>Stay connected and informed by following <a href="https://www.arnica.io/" target="_blank">Arnica.io</a> on <a href="https://www.linkedin.com/company/arnica-io/" target="_blank">LinkedIn</a> and <a href="https://twitter.com/ArnicaIO" target="_blank">Twitter</a> for the latest updates and insights on application security.</p> <p> </p> <p>Thank you for joining us on this enlightening journey into the world of Application Security! Remember to prioritize security and continue seeding AppSec in your organizations. Until next time, stay secure and keep innovating!</p> <p><strong> </strong></p> <p><strong>Key Quotes</strong></p> <p> </p> <p><strong>&quot;Empowering People is always a good idea. If people trust that you know your stuff, that you are not throwing things over the fence for them, they will come and ask your opinion, and they will ask, how to best create or develop solutions.&quot; </strong>– Cassio Goldschmidt</p> <p> </p> <p><strong>&quot;Creating a culture of security goes way beyond just development, but really the entire company. And you really start creating awareness.&quot; </strong>- Cassio Goldschmidt</p>

Episode thumbnail for Finding, Evaluating & Implementing Innovation in AppSec

August 28, 2023

Finding, Evaluating & Implementing Innovation in AppSec

<p>The evolution of Application Security stands as a testament to our relentless pursuit of cybersecurity. From its inception, rooted in basic coding blunders, to the intricate labyrinth of challenges we navigate today, the journey of AppSec is nothing short of captivating. Today, we&#39;re thrilled to host Teja Myneedu. With over two decades in the industry, Teja provides a riveting account of the transformation of Application Security from its early phases to the present. Through his expert perspective, we explore the rise and sophistication of AppSec, delving into threat modeling and the nuances of contemporary cyber threats. Teja not only chronicles the evolution but also underscores the socio-economic impacts on security trends, shares stories from landmark breaches, and imparts crucial lessons learned along the way.</p> <p> </p> <p>With a blend of invaluable insights and forward-thinking, this episode promises a deep dive into the past, present, and anticipated trajectory of AppSec.</p> <p> </p> <p><strong>What we cover on the episode:</strong></p> <p> </p> <p><strong>[00:00 - 25:01] AppSec Innovation: Navigating Solutions and Philosophies</strong></p> <ul> <li>Teja emphasizes seeking solutions that stretch beyond conventional approaches, inspiring innovative problem-solving within AppSec.</li> <li>When adopting a new solution, focus on evangelizing the innovative philosophy internally first. Show how the solution improves existing practices and provides empirical metrics, making it easier to measure and communicate progress.</li> </ul> <p>·      Teja&#39;s approach involves internally promoting innovative philosophies, fostering dialogue, and demonstrating solutions&#39; potential to elevate AppSec practices.</p> <p><strong> </strong></p> <p><strong>[25:02 - 43:25] Shifting Security Left: Prioritizing Prevention, Empathy, and Innovation</strong></p> <p>·      Focus on shifting security left in the development process to prevent vulnerabilities, not just finding and fixing them later.</p> <p>·      Emphasize developer empathy, provide real-time help, and prioritize problems within the context of an organization.</p> <p>Innovative security solutions prioritize user experience, collaboration, and contextual understanding, moving beyond narrow issue-focused tools.</p> <p> </p> <p>Connect with Teja!</p> <p>LinkedIn: <a href="https://www.linkedin.com/in/myneedu/" target="_blank">https://www.linkedin.com/in/myneedu/</a></p> <p>Check out his website at: <a href="https://teja-myneedu.com/about" target="_blank">https://teja-myneedu.com/about</a></p> <p><br></p> <p>We hope you enjoyed this edition of Seeding AppSec! Check out the latest trends in application security discussed with our esteemed guests from around the globe. Don&#39;t miss any future episodes; subscribe to Seeding AppSec on <a href="https://www.spotify.com/" target="_blank">Spotify</a>, <a href="https://www.youtube.com/" target="_blank">YouTube</a>, <a href="https://podcasts.google.com/feed/aHR0cHM6Ly9hbmNob3IuZm0vcy9lNjBmMjY5OC9wb2RjYXN0L3Jzcw" target="_blank">Google Podcasts,</a> or <a href="https://www.apple.com/podcasts/" target="_blank">Apple Podcasts</a>.</p> <p> </p> <p>This podcast is proudly brought to you by <a href="https://www.arnica.io/" target="_blank">Arnica</a>, a revolutionary application security solution reshaping how AppSec teams tackle risk identification and mitigation. Explore Arnica.io for detailed information about their cutting-edge security solution, featuring real-time pipelineless risk identification and git posture management. Protect your developers, code, and products without compromising development velocity.</p> <p> </p> <p>Stay connected and informed by following <a href="https://www.arnica.io/" target="_blank">Arnica.io</a> on <a href="https://www.linkedin.com/company/arnica-io/" target="_blank">LinkedIn</a> and <a href="https://twitter.com/ArnicaIO" target="_blank">Twitter</a> for the latest updates and insights on application security.</p> <p> </p> <p>Thank you for joining us on this enlightening journey into the world of Application Security! Remember to prioritize security and continue seeding AppSec in your organizations. Until next time, stay secure and keep innovating!</p> <p><strong> </strong></p> <p><strong>Key Quotes</strong></p> <p> </p> <p><strong>&quot;True developer empathy is realizing... How can we actually make it so that it&#39;s not a problem in the first place?&quot;</strong> – Teja Myneedu.</p> <p> </p> <p><strong>&quot;I fundamentally believe in buying over building if I can. If there is a problem worth solving, there&#39;s a business that&#39;s being built around it. And it&#39;s a matter of finding that business, but if that version of the problem isn&#39;t big enough to be solved, I try to build solutions around it.”</strong> – Teja Myneedu.</p>

6 total episodes available

Deep-dive analytics for Seeding AppSec

Frequently asked questions

Have a different question and can't find the answer you're looking for? Reach out to our support team by sending us an email and we'll get back to you as soon as we can.

What is Seeding AppSec?

Tune into "Seeding AppSec" for an insightful exploration into the dynamic world of application security. This episode spotlights the freshest trends and offers firsthand insights from global AppSec leaders.

What You'll Learn: The forefront of application security trends and their significance. Expert takes on tackling current AppSec challenges. An introduction to Arnica's innovative security solutions, enhancing risk identification and management without hindering development speed.

As cyber threats magnify, grasping AppSec becomes imperative for businesses, developers, and users.

How often does this podcast release new episodes?

This podcast updates daily.

Where can I listen to this podcast?

This podcast is available on 4 platforms including Apple Podcasts, Spotify, and more. You can also use the RSS feed directly.

Does this podcast accept guests?

Yes, this podcast regularly features guests.

Legal Disclaimer

Pod Engine is not affiliated with, endorsed by, or officially connected with any of the podcasts displayed on this platform. We operate independently as a podcast discovery and analytics service.

All podcast artwork, thumbnails, and content displayed on this page are the property of their respective owners and are protected by applicable copyright laws. This includes, but is not limited to, podcast cover art, episode artwork, show descriptions, episode titles, transcripts, audio snippets, and any other content originating from the podcast creators or their licensors.

We display this content under fair use principles and/or implied license for the purpose of podcast discovery, information, and commentary. We make no claim of ownership over any podcast content, artwork, or related materials shown on this platform. All trademarks, service marks, and trade names are the property of their respective owners.

While we strive to ensure all content usage is properly authorized, if you are a rights holder and believe your content is being used inappropriately or without proper authorization, please contact us immediately at hey@podengine.ai for prompt review and appropriate action, which may include content removal or proper attribution.

By accessing and using this platform, you acknowledge and agree to respect all applicable copyright laws and intellectual property rights of content owners. Any unauthorized reproduction, distribution, or commercial use of the content displayed on this platform is strictly prohibited.