EPISODE · Jan 9, 2024 · 52 MIN
Jay Bobo & Darylynn Ross -- App Sec Is Dead. Product Security Is the Future.
from The Application Security Podcast · host Chris Romeo
Is application security dead, or does it need to grow into something larger? CoverMyMeds security leaders Jay Bobo and Darylynn Ross challenge the traditional AppSec model and argue for product security that follows business risk across the whole product. They compare centralized security teams with security specialists embedded in engineering, explain where threat modeling and automated testing belong, and discuss how to give developers useful SAST findings without drowning them in tool output. The conversation then turns to communication: executives need risk, impact, and business context rather than raw vulnerability details. Jay and Darylynn also question the industry’s reflexive reliance on penetration testing and share practical advice for aligning security work with product outcomes, engineering workflows, and the people responsible for shipping software.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Darylynn Ross and Jay Bobo:→ Darylynn Ross on LinkedIn→ Jay Bobo on LinkedIn→ CoverMyMedsMentioned in this episode:→ How to Measure Anything in Cybersecurity Risk, 2nd Edition→ Kristin Hannah→ CoverMyMeds→ GitHub DependabotFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Is AppSec dead? Meet Darylynn Ross and Jay Bobo03:11 Jay’s path from development into security04:23 Why traditional AppSec needs to become product security09:21 Embedding security expertise inside development teams20:24 Product security compared with application security23:46 Threat modeling and risk at the product level26:49 Giving developers useful SAST results34:46 Aligning security work with business value36:44 Communicating vulnerabilities across the organization40:18 Turning technical findings into executive risk43:07 Controversial opinions about AppSec44:53 Questioning the industry’s reliance on penetration tests47:07 Book recommendations49:27 Key takeaways from Darylynn and Jay
Embed this episode
What this episode covers
Is application security dead, or does it need to grow into something larger? CoverMyMeds security leaders Jay Bobo and Darylynn Ross challenge the traditional AppSec model and argue for product security that follows business risk across the whole product. They compare centralized security teams with security specialists embedded in engineering, explain where threat modeling and automated testing belong, and discuss how to give developers useful SAST findings without drowning them in tool outp...
Ready to play
Jay Bobo & Darylynn Ross -- App Sec Is Dead. Product Security Is the Future.
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.