Akansha Shukla - Modern AppSec: Securing APIs with Threat Modeling and DevSecOps episode artwork

EPISODE · Sep 2, 2025 · 35 MIN

Akansha Shukla - Modern AppSec: Securing APIs with Threat Modeling and DevSecOps

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

APIs power modern applications, yet many AppSec programs still cannot reliably inventory them, model their threats, or enforce authorization. Akansha Shukla draws on more than a decade in application security and DevSecOps to explain why API security remains immature and what practitioners can do about it. She and the hosts examine the OWASP API Security Top 10, broken object-level authorization, API-specific threat modeling, and the role of posture management. The conversation also asks why foundational controls such as input validation remain difficult despite strong framework support, and whether declarations that shift left is dead reflect reality or marketing. Akansha closes with practical guidance for building developer understanding, integrating security throughout delivery, and treating APIs as first-class elements of architecture rather than invisible plumbing.The Application Security Podcast is brought to you by Security Journey.About Security JourneyWe provide diverse training content and easy-to-digest lessons to meet individual learner needs. Learners report improving their knowledge as much as 85% on AppSec topics.→ Learn more about Security JourneyConnect with Akansha Shukla:→ Akansha Shukla on LinkedIn→ Women4Cyber Mentorship ProgrammeMentioned in this episode:→ OWASP API Security Top 10→ Burp Suite Professional→ Women4Cyber Mentorship Programme→ OAuth 2.0Follow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Akansha Shukla03:11 Moving from engineering into security06:13 Why development knowledge matters09:09 Using the OWASP API Security Top 1011:55 Authorization and API guardrails14:46 Threat modeling APIs17:26 Why teams skip API threat models18:49 Is the barrier knowledge or process?21:15 The role of API security posture management22:25 Why API inventory is still difficult24:41 Framework support versus real adoption27:43 Did security make the paved road too hard?28:14 Why input validation remains unsolved29:39 Is shift left dead?33:04 Akansha's key takeaway34:55 Closing thoughts

Episode metadata supplied by the publisher feed · Published Sep 2, 2025

Embed this episode

APIs power modern applications, yet many AppSec programs still cannot reliably inventory them, model their threats, or enforce authorization. Akansha Shukla draws on more than a decade in application security and DevSecOps to explain why API security remains immature and what practitioners can do about it. She and the hosts examine the OWASP API Security Top 10, broken object-level authorization, API-specific threat modeling, and the role of posture management. The conversation also asks why ...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Akansha Shukla - Modern AppSec: Securing APIs with Threat Modeling and DevSecOps

0:00 35:35

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 35 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on September 2, 2025.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!