EPISODE · Sep 2, 2025 · 35 MIN
Akansha Shukla - Modern AppSec: Securing APIs with Threat Modeling and DevSecOps
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
APIs power modern applications, yet many AppSec programs still cannot reliably inventory them, model their threats, or enforce authorization. Akansha Shukla draws on more than a decade in application security and DevSecOps to explain why API security remains immature and what practitioners can do about it. She and the hosts examine the OWASP API Security Top 10, broken object-level authorization, API-specific threat modeling, and the role of posture management. The conversation also asks why foundational controls such as input validation remain difficult despite strong framework support, and whether declarations that shift left is dead reflect reality or marketing. Akansha closes with practical guidance for building developer understanding, integrating security throughout delivery, and treating APIs as first-class elements of architecture rather than invisible plumbing.The Application Security Podcast is brought to you by Security Journey.About Security JourneyWe provide diverse training content and easy-to-digest lessons to meet individual learner needs. Learners report improving their knowledge as much as 85% on AppSec topics.→ Learn more about Security JourneyConnect with Akansha Shukla:→ Akansha Shukla on LinkedIn→ Women4Cyber Mentorship ProgrammeMentioned in this episode:→ OWASP API Security Top 10→ Burp Suite Professional→ Women4Cyber Mentorship Programme→ OAuth 2.0Follow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Akansha Shukla03:11 Moving from engineering into security06:13 Why development knowledge matters09:09 Using the OWASP API Security Top 1011:55 Authorization and API guardrails14:46 Threat modeling APIs17:26 Why teams skip API threat models18:49 Is the barrier knowledge or process?21:15 The role of API security posture management22:25 Why API inventory is still difficult24:41 Framework support versus real adoption27:43 Did security make the paved road too hard?28:14 Why input validation remains unsolved29:39 Is shift left dead?33:04 Akansha's key takeaway34:55 Closing thoughts
Embed this episode
What this episode covers
APIs power modern applications, yet many AppSec programs still cannot reliably inventory them, model their threats, or enforce authorization. Akansha Shukla draws on more than a decade in application security and DevSecOps to explain why API security remains immature and what practitioners can do about it. She and the hosts examine the OWASP API Security Top 10, broken object-level authorization, API-specific threat modeling, and the role of posture management. The conversation also asks why ...
Ready to play
Akansha Shukla - Modern AppSec: Securing APIs with Threat Modeling and DevSecOps
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.