Jon Mccoy and Jonathan Marcil -- Agile #AppSec episode artwork

EPISODE · Aug 29, 2017 · 44 MIN

Jon Mccoy and Jonathan Marcil -- Agile #AppSec

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Agile delivery promises fast feedback, but where does application security fit when teams are already moving continuously? Jon McCoy and Jonathan Marcil join Chris and Robert to separate Agile principles from inconsistent enterprise interpretations and identify practical starting points. They discuss dedicated AppSec leadership, security-minded developers, continuous integration, static analysis, shared knowledge, and reusable components. The guests challenge the idea of a late security sprint and examine the real cost of building defenses early. They also explain how responsibility can be distributed without asking every developer to become a cryptography specialist. The episode closes with learning recommendations, community participation, and the principle that a mature AppSec program should help teams avoid repeating the same security mistakes.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Jon McCoy and Jonathan Marcil:→ Jon McCoy on X→ Jonathan Marcil on XMentioned in this episode:→ Agile Manifesto→ OWASP Top 10→ OWASP MontrealFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Agile application security01:54 Security origin stories05:41 Development experience and security work08:52 The advantages of fast feedback10:11 What organizations mean by Agile13:24 Where security fits16:44 Starting an Agile AppSec program20:02 Continuous integration and static analysis23:02 Building a security knowledge base27:54 Why a late security sprint fails28:05 The real cost of building security early32:44 Reusable controls and specialized responsibility35:33 Additional first-year priorities37:34 Learning through local communities43:18 Avoiding the same mistakes over time

Episode metadata supplied by the publisher feed · Published Aug 29, 2017

Embed this episode

Agile delivery promises fast feedback, but where does application security fit when teams are already moving continuously? Jon McCoy and Jonathan Marcil join Chris and Robert to separate Agile principles from inconsistent enterprise interpretations and identify practical starting points. They discuss dedicated AppSec leadership, security-minded developers, continuous integration, static analysis, shared knowledge, and reusable components. The guests challenge the idea of a late security sprin...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Jon Mccoy and Jonathan Marcil -- Agile #AppSec

0:00 44:33

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 44 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on August 29, 2017.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!