EPISODE · Jul 25, 2022 · 33 MIN
Hillel Solow -- How to do AppSec without a security team
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
How can a startup build meaningful AppSec when it cannot hire a dedicated security specialist? Hillel Solow, a longtime security product builder and former ProtectOnce chairman, joins Chris and Robert to frame an application security program around what matters most: protecting availability, confidentiality, and integrity without crippling the product. They break the work into before, during, and after deployment; compare the constraints facing startups, midsize companies, and large enterprises; and explain why tools only help when developers understand their purpose. Hillel also argues that small companies need an incident plan, basic security architecture, and shared ownership early—not after the first enterprise security questionnaire arrives. The practical takeaway is simple: use what already exists, prioritize by risk, and make security part of everyone’s job.You are now listening to the Application Security Podcast, brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Hillel Solow:→ Hillel Solow on LinkedInMentioned in this episode:→ OWASP DevSecOps Guideline→ AICPA SOC for Service Organizations overviewFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Hillel Solow: AppSec Without a Security Team03:03 From junior developer to security engineering05:44 The building blocks of an AppSec program10:28 Defense in depth across the application lifecycle12:48 Why security tools need developer education13:31 AppSec at startup, midsize, and enterprise scale18:09 Advice for companies without a security specialist23:41 A one-page incident response plan beats panic27:01 Why small companies are still attractive targets29:49 Making security everyone’s responsibility30:33 Hillel’s practical call to action
Embed this episode
What this episode covers
How can a startup build meaningful AppSec when it cannot hire a dedicated security specialist? Hillel Solow, a longtime security product builder and former ProtectOnce chairman, joins Chris and Robert to frame an application security program around what matters most: protecting availability, confidentiality, and integrity without crippling the product. They break the work into before, during, and after deployment; compare the constraints facing startups, midsize companies, and large enterpris...
Ready to play
Hillel Solow -- How to do AppSec without a security team
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.