
Advertise on podcast: The Elephant in AppSec
This podcast has
90 episodes
Language
EnglishPublisher
The Elephant in AppSecExplicit
No
Date created
2024/10/28
Latest episode
2026/09/06
Average duration
39 min.
Release period
25 days
Description
Time to discuss AppSec issues no one talks about.
Unlock The Elephant in AppSec podcast Email contact info,
Listeners & Audience details
Email contact information
Direct podcast contact details

Listeners
Audience numbers & engagement insights

Audience details
Podcast Insights

Podcast episodes
Check latest episodes from The Elephant in AppSec podcast
Don't just model the attack, model the recovery with Petra Vukmirovic
2026/09/06
My guest today is Petra Vukmirovic, Head of Information Security and IT at Numan, and she also works with DevArmor on automating threat modeling and security design reviews.
Outside of that she started the OWASP Threat Model Library, an open collection of real threat models the community can learn from.
What makes her path unusual is that she didn't come to AppSec through development, she came through emergency medicine, where she worked as a doctor.
In this episode, we talked about what transfers from the ER to incident response, which is mostly the protocols: risk scores, runbooks, decision trees you can follow when things are on fire. She also thinks threat modeling stops too early. Most teams model protective controls and stop, when recovery deserves the same attention.
We also got into automating threat models with LLMs, catching drift between the model and the code, and where design reviews end and threat modeling begins.
And much more!
This podcast is brought to you by
Escape: https://escape.tech — Offensive security for the teams that are 100x outnumbered, combining Attack Surface Management, business-logic-aware DAST and AI pentesting solutions.
The Docker mistakes everyone's still making and how to fix them with Advait Patel
2026/08/04
Today I'm joined by Advait Patel, Senior Site Reliability Engineer and the creator of DockSec, an open-source, AI-powered Docker security scanner that's now an official OWASP Incubator project.
In this episode, we get into:
Why dumping 200 container findings into a Jira ticket is the fastest way to get developers to fix nothing and how DockSec cuts that down to the 5 that actually matter
The AI support agent that got hijacked by a single malicious ticket and emailed customer data straight to an attacker
Why you should treat AI as an assistant on a leash, not an engineer with root access
the Docker mistakes Advait sees everywhere (stale base images, root by default, and secrets baked right into the image)
…and much more!
Get ready, Advait doesn't hold back his opinions. Let's dive right in!
Connect with Advait: https://www.linkedin.com/in/advaitpatel93/
Connect with Alexandra: https://www.linkedin.com/in/alexandra-charikova/
This podcast is brought to you by
Escape: https://escape.tech — Offensive security for the teams that are 100x outnumbered, combining ASM business-logic-aware DAST, and AI-powered pentesting solutions.
Mentioned
DockSec on GitHub (now the OWASP org repo): https://github.com/OWASP/DockSec
OWASP project page: https://owasp.org/www-project-docksec/
Open Policy Agent (his "open policy" reference): https://www.openpolicyagent.org/
OWASP Top 10 for LLM Applications: https://genai.owasp.org/
Why Security Loses Influence in High-Growth Companies (And What to Do About It) with Kavia Venkatesh
2026/05/20
Today, I'm joined by Kavia Venkatesh, Director of Product Security at a large healthcare organization. She didn't take the traditional path into cybersecurity — she came from biotech. But that outsider lens turned out to be her edge.
With over 10 years of experience leading cybersecurity strategy for hyper-scale ecosystems, she's built many security programs from the ground up, navigating 9 acquisitions in 18 months at a large tech org, and along the way developed a rare ability to translate risk into language that executives actually act on.
Kavia is also a frequent speaker at premier global conferences, including DEF CON, BSides San Francisco, and Nullcon.
In this episode, we talked about what most security teams get completely wrong during integrations, what she'd change about how security teams show up in organizations and the "breachability mindset" that changes how you approach risk.
And much more!
Get ready, Kavia doesn't hold back her opinions. Let's dive right in!
This podcast is brought to you by Escape: https://escape.tech — Offensive security for the teams that are 100x outnumbered, combining Attack Surface Management, business-logic-aware DAST and AI pentesting solutions.
Connect with Kavia: https://www.linkedin.com/in/kaviavenkatesh/
The Lethal Trifecta or why your AI agent knows too much - Jason Fernandes
2026/05/11
Today, I’m joined by Jason Fernandes, VP of security and privacy at Mercari, the Japanese-born global marketplace now spanning e-commerce, FinTech, and crypto. It is this rare combination that puts him at the intersection of some of the strictest regulatory environments in tech.
He oversees everything from product and platform security to threat detection, privacy, and, since last year, AI security and AI governance.
In this episode, we also talked about the challenges of AI governance, the lethal trifecta for AI agents, the confused deputy problem, and how to justify AI security investments to the leadership and working with FinOps teams. And much more!
Dive right in!
This podcast is brought to you by
Escape: https://escape.tech — Offensive security for the teams that are 100x outnumbered, combining Attack Surface Management, business-logic-aware DAST and AI pentesting solutions.
Mentioned
FACADE (Google's internal fraud detection model) https://arxiv.org/abs/2412.06700
Meta Practical AI Agent Security (Rule of Two) https://ai.meta.com/blog/practical-ai-agent-security/
Simon Willison The Lethal Trifecta https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/
Hiroki's AI Security blog (Mercari) https://hi120ki.github.io/blog/posts/20260103/
Anthropic Project Vend https://www.anthropic.com/research/project-vend-2
25 years of the same problem in Application Security - Sam Stepanyan
2026/04/22
Today, I’m joined by Sam Stepanyan, an OWASP Global Board member and an OWASP London Chapter Leader. Sam is an Independent Application Security Consultant and Security Architect with over 20 years of experience in the IT industry.
Sam has worked for various financial services institutions in the City of London specialising in Application Security consulting, Secure Software Development Lifecycle (SDLC), developer training, source code reviews and vulnerability management.
He is also a Subject Matter Expert in Web Application Firewalls (WAF) and SIEM systems.
In this episode, we explore why, despite OWASP being around for over 25 years, many developers are still unaware of it—and why shifting focus toward developer conferences might be key to spreading security knowledge more effectively.
We also discuss the impact of AI on modern security practices, the growing role of automated penetration testing tools, and how even small changes—like adding the word “secure” to a vibe coding prompt—can help nudge developers toward more security-conscious decisions.
Dive right in!
This podcast is brought to you by
Escape: https://escape.tech — Offensive security for the teams that are 100x outnumbered, combining Attack Surface Management, business-logic-aware DAST and AI pentesting solutions.
Should security belong in every AI strategy meeting? with Amol Deshpande
2025/12/29
Today, I’m joined by Amol Deshpande, a seasoned security engineer currently at Stripe, where he focuses on building secure systems at massive scale. With a background spanning product security and penetration testing at companies like Salesforce, Splunk, and Early Warning, Amol brings deep hands-on experience in securing complex, real-world platforms.
He’s also been a HackMIT judge and a long-time CTF competitor at DEF CON, giving him a very practical view of modern security challenges.
In this episode, we cover whether security must now belong in every AI strategy meeting, and how to embed it into AI development from the outset.
We also touch on how privacy concerns will only grow as agents are trained on sensitive data and why human oversight is essential for critical AI operations.
Dive right in!
What Mindset Shift Developers Need to Break Into Security? with Aleksandra Kornecka
2025/12/24
Today, I’m joined by Aleksandra Kornecka, a security engineer with a global mindset. She recently transitioned from Senior AppSec Engineer to Cloud Infrastructure Security Engineer, and has a background in software testing and cognitive science — a combination that gives her a unique take on both the technical and human sides of security.As a member of the OWASP Security Champions Guide and the project's Artifact stream, Aleksandra also put efforts to collect templates, documents, and other artifacts useful to build the security champions program.In this episode, we dive into the mindset shift developers need to successfully break into security and why security champions are critical for scaling security awareness across organizations.We also explore how curiosity fuels a lasting passion for security, and unpack why Zero Trust is often misunderstood and overhyped.Dive right in!
Is the AI–API interaction the biggest security blind spot? with Gowtham Sundar
2025/12/20
Today, I’m joined by Gowtham Sundar, a Senior Lead Engineer - 3A Security (AI and API included as you can guess) at SPH Media and a seasoned AppSec leader with over a decade of experience across enterprise security, penetration testing, and secure product development.
In this episode, Gowtham brings a real practitioner’s point of view on what it actually takes to secure AI systems. We dive into why APIs are at the heart of AI, why securing them is non-negotiable, and why automated API discovery is becoming critical for governance as systems scale.
We also talk about how AI security is evolving at lightning speed, sometimes changing week by week, and what that means for security teams trying to keep up.And with that, get ready to hear Gowtham’s opinions.
Dive right in!
What best drives the adoption of secure software practices? with Enrique Larios Vargas
2025/12/11
Today, I’m joined by Enrique Larios Vargas, a Security and Learning Specialist at Adyen.
Enrique has over eight years of experience designing impactful learning and enablement programs across fintech, engineering, and security. He’s also been a university lecturer in software engineering in Peru, the Netherlands, and Canada.
Bringing together technical expertise and behavioral science, Enrique is passionate about helping developers move beyond compliance and build a meaningful, human-centered security culture.
In this episode, we dive into his research paper, “DASP: A Framework for Driving the Adoption of Software Security Practices,” co-authored with five others (all listed in the description). The paper explores how behavioral models like COM-B can drive secure development practices.
We also get into incentives and Enrique’s controversial take on why we shouldn’t call security champions “champions” anymore. He’ll even be put to the test on this topic at the upcoming Elephant in AppSec conference, where he’ll debate it with other panelists.
Dive right in!
Why AppSec Needs More Than Just a Checkbox ⎢ Marcos Vinicius Cassel
2025/12/03
Today, I’m joined by Marcos Vinicius Cassel, Application Security Manager at PowerSchool.
With over a decade of experience in the information security space, as a CISSP, ISO 27001 Lead Auditor, and a passionate technologist, Marcos has led security initiatives across multiple industries.
He also previously led the OWASP Porto Alegre Chapter, and fun fact: we first met while volunteering together at BSides SF!
In this episode, we dive into the real value of certifications in application security, how they can provide structure and credibility, but shouldn’t define a professional’s entire skill set.
We also unpack the balance between compliance and risk management and between privacy and innovation, and why strong communication between security and engineering teams is more essential than ever.
And with that, get ready to hear Marcos’ opinions.
Dive right in!
The Supply Chain Crisis We Created: How AI, Extensions, and Dependencies Became the New Attack Surface with Aamiruddin Syed
2025/11/26
Today, I’m joined by Aamiruddin Syed, Senior Product Security Engineer at AGCO Corporation.
Aamiruddin is the author of “Supply Chain Software Security book focusing on AI, IoT, and AppSec” and a recognized advocate for secure development. He’s a frequent speaker at major conferences, including RSA, DEFCON, and Black Hat.
Fun facts: he was once ranked in the top 1% of all TryHackMe penetration testers, and a memorable milestone in his career was delivering a Cybersecurity Awareness talk to officer trainees of the Indian Army.
He’s also a fellow podcaster, co-hosting the CyberGPT Pulse Podcast.
In this episode, we dive into the complexities of software supply chain security, especially the risks introduced by third-party extensions, and how generative AI can strengthen defenses across the supply chain.
We also explore the challenges of data quality when training AI models and discuss why strong governance is essential for secure developer practices.
Dive right in!
Why AppSec Is breaking: Vibe Coding, DevSecOps backlogs & the new OWASP Top 10 (with Tanya Janca)
2025/11/13
Today, I’m joined once again by Tanya Janca for her second appearance on the podcast. Her first episode was a hit, so we figured: why not record another? And the timing couldn’t be better, as Tanya has just embarked on a brand-new chapter in her career this year. In our first conversation, I highlighted many of Tanya’s accomplishments, and she’s only added to the list since then. Most notably, she’s been deeply involved in shaping key components of the newly released OWASP Top 10.In this episode, we dive into the initiatives she’s focusing on in her new solo journey, why she decided to join the OWASP Top 10 team, her mission to create a developer-focused awareness document, and even the unexpected difficulty of naming vulnerabilities for the final list.We also chat about her take on why DevSecOps has started to lose some of its shine. Something she’ll be discussing further at the upcoming Elephant in AppSec conference.Dive right in!
Secure by Design: Who’s Really Responsible? with Abhijeth Dugginapeddi
2025/11/04
Today on the show, I’m joined by Abhijeth Dugginapeddi, Director of Offensive Security at Palo Alto Networks. Before this, he built and led product and cloud security at BigCommerce, and worked on application security at Commonwealth Bank and Adobe.Abhijeth is deeply passionate about giving back to the community. He’s taught advanced web application security at UNSW, mentored through multiple outreach programs, and recently launched his first LinkedIn Learning course, “Practical Secure by Design”. He’s also been recognised in the Hall of Fame at companies like Google, Yahoo, and others for uncovering serious vulnerabilities across their platforms.In this episode, we get into the idea and the principles of secure by design, who should own it, and why security culture matters so much. We also talk about IPO readiness from a security perspective, and the real-world challenges startups face when trying to build security in.Dive right in!
The Pressure of Security Leadership: What SLAs Actually Work? with Terry O'Daniel
2025/10/19
Today, I’m excited to be joined by Terry O’Daniel, former global head of security at Amplitude, Instacart, and Netflix, and a trusted advisor in the security space. Terry thrives in high-growth environments and loves tackling complex challenges.
With a strong background in engineering and security, he builds teams that focus on solving security problems at scale through automation and instrumentation.
Terry is also a frequent public speaker and passionate advocate for product security. And recently, he joined Harvard as the Head TA for Security Lifecycle Threats.
In this episode, we break down how SLAs enforce real accountability, why security leaders are constantly under pressure, and why ignoring identity and data structures is a recipe for failure.
We also discuss how operating under pressure can surprisingly lead to better decision-making and what the future of product security will look like.
Dive right in!
Can We Make AI Agents Smarter Than Security Teams? with Anshuman Bhartiya
2025/09/25
Today, I’m excited to welcome Anshuman Bhartiya, an AppSec tech lead at Lyft. Before that, he worked as a security engineer at companies like Thirty Madison, Intuit, and Atlassian.
Anshuman is also a fellow podcaster and co-host of the Boring AppSec podcast, alongside one of my previous guests, Sandesh Mysore Anand.
Recently, he’s been experimenting extensively with building AI agents for both offensive and defensive security, and he’s documenting his findings at anshumanbhartiya.com(link in the description).
In this episode, we dive into the challenges of building effective AI agents, the impact of AI on security practices, and the importance of understanding AI outputs and avoiding confirmation bias.
We also touch on the ongoing debate of build versus buy solutions and explore where the future of AI in security might be headed.
Dive right in!
Podcast reviews
Read The Elephant in AppSec podcast reviews
Podcast sponsorship advertising
Start advertising on The Elephant in AppSec relevant audience podcasts
You may also like to advertise on these Podcasts

51088171
Middle Children
Jessie Jolles and Chris Burns

4.9264932000
Morning Wire
The Daily Wire

4.689251199
Get Sleepy: Sleep meditation and stories
Slumber Studios

4.79026375
Life is Short with Justin Long
Audible

4.714083346
Bad Friends
Bobby Lee & Andrew Santino

4.7124668
10 to Life
Annie Elise

4.76746460
Criminology
Emash Digital & Mike Ferguson, Mike Morford

4.87488968
The Dr. John Delony Show
Ramsey Network

4.8224671785
The Andrew Klavan Show
The Daily Wire

4.959721991
Legal AF by MeidasTouch
MeidasTouch Network