Hillel Solow -- How to do AppSec without a security team episode artwork

EPISODE · Jul 25, 2022 · 33 MIN

Hillel Solow -- How to do AppSec without a security team

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

How can a startup build meaningful AppSec when it cannot hire a dedicated security specialist? Hillel Solow, a longtime security product builder and former ProtectOnce chairman, joins Chris and Robert to frame an application security program around what matters most: protecting availability, confidentiality, and integrity without crippling the product. They break the work into before, during, and after deployment; compare the constraints facing startups, midsize companies, and large enterprises; and explain why tools only help when developers understand their purpose. Hillel also argues that small companies need an incident plan, basic security architecture, and shared ownership early—not after the first enterprise security questionnaire arrives. The practical takeaway is simple: use what already exists, prioritize by risk, and make security part of everyone’s job.You are now listening to the Application Security Podcast, brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Hillel Solow:→ Hillel Solow on LinkedInMentioned in this episode:→ OWASP DevSecOps Guideline→ AICPA SOC for Service Organizations overviewFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Hillel Solow: AppSec Without a Security Team03:03 From junior developer to security engineering05:44 The building blocks of an AppSec program10:28 Defense in depth across the application lifecycle12:48 Why security tools need developer education13:31 AppSec at startup, midsize, and enterprise scale18:09 Advice for companies without a security specialist23:41 A one-page incident response plan beats panic27:01 Why small companies are still attractive targets29:49 Making security everyone’s responsibility30:33 Hillel’s practical call to action

Episode metadata supplied by the publisher feed · Published Jul 25, 2022

Embed this episode

How can a startup build meaningful AppSec when it cannot hire a dedicated security specialist? Hillel Solow, a longtime security product builder and former ProtectOnce chairman, joins Chris and Robert to frame an application security program around what matters most: protecting availability, confidentiality, and integrity without crippling the product. They break the work into before, during, and after deployment; compare the constraints facing startups, midsize companies, and large enterpris...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Hillel Solow -- How to do AppSec without a security team

0:00 33:52

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 33 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on July 25, 2022.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!