Marc French — The AppSec CISO episode artwork

EPISODE · Nov 10, 2019 · 43 MIN

Marc French — The AppSec CISO

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Is becoming a CISO the next technical promotion, or a fundamentally different job? Marc French joins Chris and Robert to discuss the role through the eyes of an application security leader. Drawing on experience running both product and security functions, he explains how delivery commitments change the way risk decisions look. The conversation examines the CISO's communication-heavy day, reporting relationships, alternative career paths, and the growing importance of application and product security as infrastructure becomes code. Marc offers practical advice for people pursuing leadership: understand the business, gain experience outside a narrow security role, and find mentors who will challenge your assumptions. He also discusses programming skills, developing future AppSec talent, and why a title alone is not a useful career plan.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Marc French:→ LinkedInMentioned in this episode:→ Boston Application Security ConferenceFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Introduction02:09 How Marc's AppSec CISO perspective developed05:30 Running application security inside product management08:59 Balancing vulnerabilities and business commitments10:37 Learning outside a security role12:36 What a CISO actually does14:24 Reporting relationships and the org chart16:15 The limits of a purely technical career plan18:26 Leadership paths beyond the CISO title21:03 Breaches and leadership expectations22:16 Where application security fits25:02 Advice for aspiring CISOs29:51 The rise of product security leadership32:20 Advice for students entering security35:32 Why programming skills matter41:21 Finding a mentor

Episode metadata supplied by the publisher feed · Published Nov 10, 2019

Embed this episode

Is becoming a CISO the next technical promotion, or a fundamentally different job? Marc French joins Chris and Robert to discuss the role through the eyes of an application security leader. Drawing on experience running both product and security functions, he explains how delivery commitments change the way risk decisions look. The conversation examines the CISO's communication-heavy day, reporting relationships, alternative career paths, and the growing importance of application and product ...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Marc French — The AppSec CISO

0:00 43:48

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 43 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on November 10, 2019.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!