Jay Bobo & Darylynn Ross -- App Sec Is Dead. Product Security Is the Future. episode artwork

EPISODE · Jan 9, 2024 · 52 MIN

Jay Bobo & Darylynn Ross -- App Sec Is Dead. Product Security Is the Future.

from The Application Security Podcast · host Chris Romeo

Is application security dead, or does it need to grow into something larger? CoverMyMeds security leaders Jay Bobo and Darylynn Ross challenge the traditional AppSec model and argue for product security that follows business risk across the whole product. They compare centralized security teams with security specialists embedded in engineering, explain where threat modeling and automated testing belong, and discuss how to give developers useful SAST findings without drowning them in tool output. The conversation then turns to communication: executives need risk, impact, and business context rather than raw vulnerability details. Jay and Darylynn also question the industry’s reflexive reliance on penetration testing and share practical advice for aligning security work with product outcomes, engineering workflows, and the people responsible for shipping software.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Darylynn Ross and Jay Bobo:→ Darylynn Ross on LinkedIn→ Jay Bobo on LinkedIn→ CoverMyMedsMentioned in this episode:→ How to Measure Anything in Cybersecurity Risk, 2nd Edition→ Kristin Hannah→ CoverMyMeds→ GitHub DependabotFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Is AppSec dead? Meet Darylynn Ross and Jay Bobo03:11 Jay’s path from development into security04:23 Why traditional AppSec needs to become product security09:21 Embedding security expertise inside development teams20:24 Product security compared with application security23:46 Threat modeling and risk at the product level26:49 Giving developers useful SAST results34:46 Aligning security work with business value36:44 Communicating vulnerabilities across the organization40:18 Turning technical findings into executive risk43:07 Controversial opinions about AppSec44:53 Questioning the industry’s reliance on penetration tests47:07 Book recommendations49:27 Key takeaways from Darylynn and Jay

Episode metadata supplied by the publisher feed · Published Jan 9, 2024

Embed this episode

Is application security dead, or does it need to grow into something larger? CoverMyMeds security leaders Jay Bobo and Darylynn Ross challenge the traditional AppSec model and argue for product security that follows business risk across the whole product. They compare centralized security teams with security specialists embedded in engineering, explain where threat modeling and automated testing belong, and discuss how to give developers useful SAST findings without drowning them in tool outp...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Jay Bobo & Darylynn Ross -- App Sec Is Dead. Product Security Is the Future.

0:00 52:25

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 52 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on January 9, 2024.

Is there a transcript available for this episode?

Yes, a full transcript is available for this episode. You can read the complete transcript on the episode page.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!