Brad Geesaman - Redefining AppSec with AI: Shrinking Toil, Expanding Impact - How LLMs are able to reduce toil in triage-heavy AppSec workflows episode artwork

EPISODE · Oct 28, 2025 · 42 MIN

Brad Geesaman - Redefining AppSec with AI: Shrinking Toil, Expanding Impact - How LLMs are able to reduce toil in triage-heavy AppSec workflows

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

AppSec teams are drowning in repetitive triage while the work that requires judgment keeps piling up. Brad Geesaman, Principal Security Engineer at Ghost Security, explains how large language models can shrink that toil without handing security decisions to an unreliable black box. He walks through using LLMs for classification, evidence gathering, and contextual analysis, with humans retaining final authority. Brad and Chris examine prompt engineering, trust, market disruption, and the limits of incumbent tools built around producing ever-larger finding queues. They also explore AI-assisted remediation, code drift, and the changing day-to-day work of AppSec engineers. The result is a pragmatic model for gaining leverage from AI while preserving the expertise, accountability, and skepticism that effective security still demands.The Application Security Podcast is brought to you by Security Journey.About Security JourneyWe provide application security training for not just your developers, but for all roles in your SDLC.→ Learn more about Security JourneyConnect with Brad Geesaman:→ Brad Geesaman on LinkedIn→ Ghost Security ReaperMentioned in this episode:→ Ghost Security→ Reaper→ Security Compass→ OWASP ZAP→ Burp Suite Professional→ SQL Slammer→ Code Red→ Nimda→ Exodus Communications→ NetWitnessFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Brad Geesaman03:01 What toil means in AppSec05:20 Why triage drains security teams06:13 Where AI can create leverage09:29 Does an LLM need custom training?11:51 Prompt engineering for useful results13:33 Humans remain at the center15:23 Trusting probabilistic systems19:30 A seismic shift in AppSec tooling20:18 Escaping the pile of findings24:00 How incumbent vendors are responding25:46 Why platform shifts leave openings28:31 The AppSec engineer's changing day33:04 Moving from triage to code changes35:36 AI-generated code and application drift38:49 What Brad hopes comes next41:51 Closing thoughts

Episode metadata supplied by the publisher feed · Published Oct 28, 2025

Embed this episode

AppSec teams are drowning in repetitive triage while the work that requires judgment keeps piling up. Brad Geesaman, Principal Security Engineer at Ghost Security, explains how large language models can shrink that toil without handing security decisions to an unreliable black box. He walks through using LLMs for classification, evidence gathering, and contextual analysis, with humans retaining final authority. Brad and Chris examine prompt engineering, trust, market disruption, and the limit...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Brad Geesaman - Redefining AppSec with AI: Shrinking Toil, Expanding Impact - How LLMs are able to reduce toil in triage-heavy AppSec workflows

0:00 42:19

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 42 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on October 28, 2025.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!