EPISODE · Jul 28, 2026 · 49 MIN
Isaac Evans - AppSec in the Age of AI
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
AI is moving AppSec's control point out of CI and directly into the coding agent—but what happens when the model writing the code is also expected to secure it? Semgrep co-founder and CEO Isaac Evans explains why deep background analysis and real-time agent plugins may replace universal rule sets with organization-specific security controls. He and Chris explore how security engineering roles will change, why independent verification still matters, and where business-logic flaws may become the next major battleground. The conversation also covers vibe coding at enterprise scale, the limits of reasoning about model behavior, open source in an agent-built world, and why Isaac sees more opportunity than threat even as AI creates a fresh wave of vulnerabilities and cleanup work.Connect with Isaac Evans:→ Isaac Evans on LinkedIn→ SemgrepMentioned in this episode:→ Semgrep→ DeepSeek→ Cursor→ OpenAI Codex→ Claude Code→ Boston Dynamics→ DARPA Robotics Challenge→ Reflections on Trusting Trust→ uutils/coreutils→ RustFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Isaac Evans01:11 From cryptography to the DARPA Robotics Challenge03:43 Founding Semgrep04:05 How AI is reshaping AppSec06:15 Attackers, defenders, and model choice08:02 Regenerating code until it clears the security bar10:30 Organization-specific rules beat universal rules14:18 The changing role of the security engineer17:53 Career advice for security practitioners19:47 Will foundation models absorb security vendors?24:18 Getting secure changes across an enterprise26:40 Trusting Trust becomes the easy problem27:41 How much should we trust agent-generated code?29:38 Independent verification and competing models34:50 Business logic flaws after SQL injection36:56 Protecting the new wave of citizen developers39:40 Vibe coding and disposable software42:05 Open source in an agent-built world44:10 Can the exponential pace continue?44:41 Key takeaways and calls to action
Embed this episode
What this episode covers
AI is moving AppSec's control point out of CI and directly into the coding agent—but what happens when the model writing the code is also expected to secure it? Semgrep co-founder and CEO Isaac Evans explains why deep background analysis and real-time agent plugins may replace universal rule sets with organization-specific security controls. He and Chris explore how security engineering roles will change, why independent verification still matters, and where business-logic flaws may become th...
Ready to play
Isaac Evans - AppSec in the Age of AI
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.